Ransomware : Your Worst IT Nightmare
Crypto-Ransomware  Remediation ConsultantsRansomware has become a too-frequent cyberplague that poses an existential danger for businesses poorly prepared for an assault. Different iterations of ransomware like the Reveton, Fusob, Bad Rabbit, NotPetya and MongoLock cryptoworms have been out in the wild for many years and continue to inflict damage. Newer versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Egregor, plus frequent as yet unnamed newcomers, not only encrypt online information but also infect all accessible system protection mechanisms. Data synched to off-premises disaster recovery sites can also be ransomed. In a poorly designed data protection solution, it can make any recovery impossible and effectively sets the network back to square one.

Getting back online programs and information after a ransomware outage becomes a race against the clock as the targeted business fights to contain the damage, eradicate the crypto-ransomware, and resume business-critical activity. Since crypto-ransomware requires time to move laterally throughout a targeted network, attacks are often launched at night, when successful penetrations tend to take longer to discover. This multiplies the difficulty of promptly assembling and coordinating a capable response team.

Progent makes available a variety of help services for protecting Guarulhos enterprises from crypto-ransomware events. These include team education to help identify and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response using SentinelOne's behavior-based threat defense to detect and disable day-zero modern malware attacks. Progent in addition can provide the services of expert ransomware recovery consultants with the skills and perseverance to rebuild a breached environment as urgently as possible.

Progent's Ransomware Restoration Support Services
Soon after a ransomware invasion, paying the ransom in cryptocurrency does not ensure that cyber hackers will provide the needed keys to unencrypt any or all of your data. Kaspersky Labs ascertained that seventeen percent of crypto-ransomware victims never recovered their files even after having sent off the ransom, resulting in more losses. The risk is also costly. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom can be in the millions of dollars. The other path is to setup from scratch the mission-critical parts of your Information Technology environment. Absent access to full system backups, this calls for a broad complement of skills, top notch project management, and the willingness to work continuously until the task is completed.

For two decades, Progent has made available professional Information Technology services for businesses throughout the U.S. and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have earned top certifications in foundation technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security specialists have earned internationally-renowned industry certifications including CISA, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has experience in financial systems and ERP application software. This breadth of experience affords Progent the skills to knowledgably ascertain necessary systems and consolidate the surviving components of your network system following a crypto-ransomware attack and assemble them into a functioning network.

Progent's ransomware group utilizes top notch project management applications to orchestrate the complicated restoration process. Progent appreciates the importance of acting quickly and in unison with a customer's management and IT resources to assign priority to tasks and to get essential systems back on line as fast as humanly possible.

Business Case Study: A Successful Crypto-Ransomware Incident Response
A business engaged Progent after their network was taken over by Ryuk ransomware. Ryuk is generally considered to have been created by North Korean government sponsored criminal gangs, suspected of adopting technology leaked from the United States NSA organization. Ryuk attacks specific businesses with limited room for disruption and is one of the most lucrative incarnations of ransomware viruses. Major organizations include Data Resolution, a California-based information warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a single-location manufacturing business located in Chicago and has about 500 workers. The Ryuk intrusion had paralyzed all business operations and manufacturing processes. The majority of the client's system backups had been directly accessible at the beginning of the intrusion and were encrypted. The client considered paying the ransom (exceeding two hundred thousand dollars) and wishfully thinking for good luck, but ultimately brought in Progent.


"I can't say enough about the support Progent gave us throughout the most fearful time of (our) businesses life. We may have had to pay the cybercriminals if it wasn't for the confidence the Progent team afforded us. The fact that you were able to get our e-mail system and essential applications back quicker than five days was something I thought impossible. Every single expert I interacted with or messaged at Progent was urgently focused on getting us operational and was working 24/7 on our behalf."

Progent worked together with the customer to quickly get our arms around and prioritize the most important elements that had to be recovered to make it possible to continue company functions:

  • Windows Active Directory
  • Email
  • Accounting/MRP
To get going, Progent followed Anti-virus penetration response industry best practices by halting the spread and performing virus removal steps. Progent then initiated the task of rebuilding Active Directory, the key technology of enterprise networks built on Microsoft Windows technology. Microsoft Exchange email will not function without Windows AD, and the businesses' financials and MRP system used Microsoft SQL, which requires Active Directory for security authorization to the information.

In less than two days, Progent was able to re-build Active Directory to its pre-attack state. Progent then helped perform rebuilding and storage recovery of needed servers. All Exchange schema and configuration information were usable, which facilitated the rebuild of Exchange. Progent was able to locate local OST files (Outlook Email Offline Folder Files) on team workstations and laptops in order to recover mail messages. A recent offline backup of the businesses accounting systems made them able to recover these essential applications back available to users. Although major work needed to be completed to recover fully from the Ryuk event, critical services were returned to operations quickly:


"For the most part, the production line operation survived unscathed and we produced all customer deliverables."

During the next month key milestones in the restoration process were accomplished in close collaboration between Progent consultants and the customer:

  • In-house web applications were restored without losing any information.
  • The MailStore Server exceeding four million historical messages was brought online and available for users.
  • CRM/Customer Orders/Invoices/Accounts Payable/Accounts Receivables (AR)/Inventory modules were 100 percent functional.
  • A new Palo Alto 850 security appliance was installed and configured.
  • Ninety percent of the user PCs were back into operation.

"So much of what went on in the early hours is mostly a fog for me, but we will not soon forget the dedication each and every one of your team accomplished to help get our business back. I've utilized Progent for the past ten years, maybe more, and each time I needed help Progent has outperformed my expectations and delivered. This situation was a testament to your capabilities."

Conclusion
A likely business disaster was evaded by hard-working experts, a wide spectrum of knowledge, and close collaboration. Although in analyzing the event afterwards the ransomware incident detailed here could have been prevented with up-to-date cyber security technology and NIST Cybersecurity Framework or ISO/IEC 27001 best practices, team education, and well designed security procedures for information backup and keeping systems up to date with security patches, the fact remains that state-sponsored cybercriminals from China, Russia, North Korea and elsewhere are tireless and are not going away. If you do get hit by a ransomware incident, feel confident that Progent's team of experts has proven experience in ransomware virus defense, mitigation, and file disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Jesse, Arnaud, Allen, Tony and Chris (along with others that were helping), thank you for letting me get rested after we made it over the first week. Everyone did an fabulous job, and if anyone that helped is in the Chicago area, a great meal is the least I can do!"

Download the Ransomware Removal Case Study Datasheet
To read or download a PDF version of this ransomware incident report, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Services in Guarulhos
For ransomware recovery consulting in the Guarulhos metro area, phone Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.