Ransomware : Your Worst IT Disaster
Ransomware  Recovery ProfessionalsCrypto-Ransomware has become an escalating cyber pandemic that poses an existential danger for businesses of all sizes unprepared for an assault. Different iterations of crypto-ransomware such as Dharma, Fusob, Locky, Syskey and MongoLock cryptoworms have been out in the wild for many years and continue to cause destruction. Newer strains of crypto-ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Nephilim, plus additional unnamed newcomers, not only perform encryption of online critical data but also infiltrate many available system protection. Data synchronized to cloud environments can also be corrupted. In a vulnerable data protection solution, this can make any restore operations useless and effectively sets the network back to zero.

Getting back on-line applications and data after a ransomware intrusion becomes a race against time as the targeted business tries its best to contain, cleanup the ransomware, and restore mission-critical operations. Since ransomware needs time to spread throughout a network, penetrations are frequently sprung on weekends and holidays, when successful attacks may take longer to discover. This compounds the difficulty of rapidly mobilizing and coordinating a knowledgeable mitigation team.

Progent has an assortment of solutions for protecting Appleton organizations from crypto-ransomware events. These include user education to help recognize and avoid phishing scams, ProSight Active Security Monitoring for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based threat defense to identify and extinguish day-zero malware attacks. Progent also offers the assistance of experienced ransomware recovery consultants with the skills and commitment to reconstruct a compromised network as quickly as possible.

Progent's Crypto-Ransomware Restoration Help
After a ransomware penetration, even paying the ransom in cryptocurrency does not guarantee that distant criminals will respond with the needed codes to decrypt any or all of your data. Kaspersky ascertained that 17% of crypto-ransomware victims never restored their files after having sent off the ransom, resulting in more losses. The gamble is also expensive. Ryuk ransoms are commonly several hundred thousand dollars. For larger enterprises, the ransom can reach millions. The fallback is to re-install the vital elements of your IT environment. Without the availability of complete system backups, this calls for a wide complement of skill sets, professional team management, and the willingness to work continuously until the job is finished.

For decades, Progent has offered expert IT services for companies throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes professionals who have earned top certifications in foundation technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security specialists have garnered internationally-recognized industry certifications including CISA, CISSP, CRISC, SANS GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has expertise with financial management and ERP software solutions. This breadth of expertise provides Progent the capability to quickly understand necessary systems and consolidate the remaining parts of your network system after a ransomware event and configure them into an operational network.

Progent's recovery group utilizes state-of-the-art project management systems to coordinate the sophisticated recovery process. Progent understands the urgency of acting quickly and in unison with a customer's management and Information Technology staff to assign priority to tasks and to put essential applications back on line as soon as possible.

Customer Case Study: A Successful Ransomware Attack Recovery
A customer engaged Progent after their network system was brought down by Ryuk ransomware. Ryuk is thought to have been deployed by North Korean government sponsored cybercriminals, suspected of using techniques leaked from America's NSA organization. Ryuk seeks specific companies with little tolerance for disruption and is one of the most lucrative versions of ransomware malware. Headline victims include Data Resolution, a California-based data warehousing and cloud computing company, and the Chicago Tribune. Progent's customer is a small manufacturing company located in the Chicago metro area and has about 500 workers. The Ryuk event had disabled all business operations and manufacturing capabilities. The majority of the client's system backups had been online at the time of the attack and were destroyed. The client was pursuing financing for paying the ransom demand (in excess of $200K) and hoping for good luck, but ultimately brought in Progent.


"I cannot thank you enough in regards to the expertise Progent gave us during the most stressful time of (our) businesses existence. We would have paid the Hackers except for the confidence the Progent team provided us. That you could get our e-mail and important servers back online sooner than 1 week was beyond my wildest dreams. Every single person I got help from or texted at Progent was amazingly focused on getting our system up and was working breakneck pace to bail us out."

Progent worked hand in hand the customer to rapidly determine and prioritize the essential elements that had to be recovered to make it possible to restart departmental operations:

  • Windows Active Directory
  • Microsoft Exchange Server
  • MRP System
To get going, Progent followed AV/Malware Processes penetration response industry best practices by stopping lateral movement and performing virus removal steps. Progent then started the process of bringing back online Microsoft Active Directory, the core of enterprise environments built on Microsoft Windows Server technology. Microsoft Exchange Server messaging will not function without Windows AD, and the customer's accounting and MRP applications used Microsoft SQL Server, which needs Active Directory for authentication to the databases.

Within 2 days, Progent was able to re-build Active Directory to its pre-virus state. Progent then performed reinstallations and storage recovery on needed servers. All Exchange schema and configuration information were usable, which accelerated the restore of Exchange. Progent was able to find intact OST files (Outlook Email Offline Data Files) on team PCs to recover email messages. A recent offline backup of the client's accounting/ERP software made it possible to return these vital applications back online for users. Although a lot of work was left to recover totally from the Ryuk damage, the most important systems were recovered quickly:


"For the most part, the assembly line operation did not miss a beat and we made all customer orders."

Over the next month important milestones in the recovery process were made in tight collaboration between Progent team members and the client:

  • Self-hosted web applications were brought back up with no loss of information.
  • The MailStore Microsoft Exchange Server containing more than four million historical emails was brought on-line and accessible to users.
  • CRM/Product Ordering/Invoicing/AP/Accounts Receivables/Inventory Control capabilities were 100% recovered.
  • A new Palo Alto 850 security appliance was brought on-line.
  • Nearly all of the desktop computers were back into operation.

"A huge amount of what was accomplished that first week is nearly entirely a haze for me, but our team will not soon forget the care all of your team accomplished to help get our company back. I have utilized Progent for at least 10 years, possibly more, and every time Progent has shined and delivered as promised. This time was a Herculean accomplishment."

Conclusion
A probable enterprise-killing disaster was dodged due to dedicated experts, a wide spectrum of knowledge, and tight teamwork. Although in hindsight the ransomware virus attack detailed here should have been shut down with modern security solutions and recognized best practices, staff training, and properly executed incident response procedures for information protection and proper patching controls, the reality is that state-sponsored cyber criminals from Russia, North Korea and elsewhere are relentless and represent an ongoing threat. If you do get hit by a ransomware incursion, feel confident that Progent's roster of experts has proven experience in ransomware virus defense, cleanup, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Chris (and any others that were contributing), thanks very much for letting me get some sleep after we made it through the most critical parts. All of you did an incredible job, and if any of your team is in the Chicago area, a great meal is on me!"

Download the Crypto-Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this case study, click:
Progent's Ryuk Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Services in Appleton
For ransomware recovery expertise in the Appleton metro area, call Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.