Ransomware : Your Crippling IT Nightmare
Crypto-Ransomware  Recovery ConsultantsRansomware has become an escalating cyber pandemic that presents an existential danger for businesses poorly prepared for an assault. Versions of ransomware like the Dharma, CryptoWall, Locky, NotPetya and MongoLock cryptoworms have been around for a long time and continue to inflict havoc. More recent strains of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, along with frequent as yet unnamed malware, not only encrypt on-line data but also infect any accessible system protection mechanisms. Information synchronized to the cloud can also be rendered useless. In a poorly architected environment, this can render automatic recovery hopeless and basically sets the datacenter back to square one.

Getting back on-line applications and data after a ransomware outage becomes a race against the clock as the targeted business struggles to contain, remove the crypto-ransomware, and restore enterprise-critical activity. Since ransomware needs time to replicate across a targeted network, attacks are often launched on weekends and holidays, when successful attacks tend to take longer to identify. This multiplies the difficulty of quickly mobilizing and orchestrating an experienced response team.

Progent provides an assortment of support services for protecting West Palm Beach businesses from crypto-ransomware events. These include user training to become familiar with and avoid phishing exploits, ProSight Active Security Monitoring for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based cyberthreat protection to discover and suppress day-zero modern malware attacks. Progent in addition can provide the services of veteran ransomware recovery professionals with the track record and commitment to re-deploy a breached network as urgently as possible.

Progent's Ransomware Restoration Services
Following a ransomware attack, paying the ransom in cryptocurrency does not ensure that distant criminals will respond with the codes to decrypt any or all of your data. Kaspersky Labs determined that 17% of ransomware victims never restored their information after having sent off the ransom, resulting in additional losses. The risk is also costly. Ryuk ransoms are typically several hundred thousand dollars. For larger enterprises, the ransom demand can be in the millions of dollars. The fallback is to setup from scratch the vital parts of your IT environment. Absent the availability of essential data backups, this calls for a wide complement of IT skills, well-coordinated project management, and the ability to work 24x7 until the job is finished.

For two decades, Progent has offered expert Information Technology services for companies across the U.S. and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have attained advanced certifications in leading technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security consultants have earned internationally-recognized certifications including CISA, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has experience with accounting and ERP application software. This breadth of experience provides Progent the capability to rapidly identify important systems and re-organize the remaining pieces of your computer network system following a crypto-ransomware event and assemble them into an operational network.

Progent's security team of experts has top notch project management systems to orchestrate the complicated recovery process. Progent knows the importance of acting swiftly and together with a customer's management and IT resources to prioritize tasks and to put critical systems back online as soon as possible.

Case Study: A Successful Crypto-Ransomware Virus Response
A customer hired Progent after their company was crashed by Ryuk ransomware. Ryuk is believed to have been developed by North Korean state sponsored criminal gangs, suspected of using strategies exposed from America's National Security Agency. Ryuk goes after specific organizations with little tolerance for operational disruption and is among the most profitable versions of crypto-ransomware. Well Known organizations include Data Resolution, a California-based info warehousing and cloud computing company, and the Chicago Tribune. Progent's client is a small manufacturing business located in the Chicago metro area and has about 500 employees. The Ryuk attack had paralyzed all business operations and manufacturing capabilities. Most of the client's backups had been directly accessible at the beginning of the intrusion and were destroyed. The client considered paying the ransom demand (in excess of $200K) and praying for good luck, but in the end reached out to Progent.


"I can't say enough in regards to the help Progent provided us during the most stressful time of (our) company's life. We most likely would have paid the cybercriminals if it wasn't for the confidence the Progent experts gave us. That you were able to get our messaging and important servers back into operation sooner than five days was earth shattering. Each person I talked with or communicated with at Progent was laser focused on getting us restored and was working at all hours to bail us out."

Progent worked together with the customer to rapidly determine and prioritize the key applications that had to be recovered in order to continue company functions:

  • Active Directory
  • Microsoft Exchange Email
  • Accounting/MRP
To start, Progent adhered to Anti-virus penetration response industry best practices by stopping the spread and clearing up compromised systems. Progent then started the task of rebuilding Microsoft AD, the core of enterprise environments built upon Microsoft Windows Server technology. Microsoft Exchange Server messaging will not function without AD, and the customer's financials and MRP system utilized SQL Server, which needs Active Directory services for security authorization to the information.

In less than 2 days, Progent was able to re-build Active Directory services to its pre-attack state. Progent then charged ahead with reinstallations and storage recovery of key systems. All Exchange ties and attributes were usable, which greatly helped the rebuild of Exchange. Progent was able to collect local OST data files (Outlook Email Offline Folder Files) on team workstations in order to recover email data. A not too old off-line backup of the businesses financials/ERP software made them able to recover these required programs back available to users. Although significant work was left to recover totally from the Ryuk event, the most important services were restored rapidly:


"For the most part, the manufacturing operation ran fairly normal throughout and we made all customer sales."

During the following month important milestones in the recovery process were completed through close cooperation between Progent engineers and the customer:

  • In-house web sites were returned to operation with no loss of information.
  • The MailStore Microsoft Exchange Server exceeding 4 million archived messages was brought online and available for users.
  • CRM/Product Ordering/Invoicing/AP/AR/Inventory Control capabilities were fully restored.
  • A new Palo Alto 850 security appliance was brought on-line.
  • 90% of the user desktops and notebooks were back into operation.

"A lot of what happened those first few days is nearly entirely a haze for me, but our team will not forget the commitment all of your team put in to help get our company back. I have been working with Progent for the past 10 years, maybe more, and every time Progent has shined and delivered as promised. This time was a life saver."

Conclusion
A possible business extinction catastrophe was evaded with dedicated professionals, a wide spectrum of knowledge, and close teamwork. Although in retrospect the crypto-ransomware virus attack described here could have been identified and stopped with advanced cyber security technology and ISO/IEC 27001 best practices, user and IT administrator training, and appropriate incident response procedures for data protection and proper patching controls, the reality remains that government-sponsored cybercriminals from China, North Korea and elsewhere are tireless and are an ongoing threat. If you do get hit by a ransomware incursion, remember that Progent's roster of professionals has extensive experience in ransomware virus defense, remediation, and data disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen and Tony (along with others that were involved), thanks very much for making it so I could get some sleep after we got through the initial push. Everyone did an fabulous job, and if any of your team is around the Chicago area, a great meal is my treat!"

Download the Crypto-Ransomware Remediation Case Study Datasheet
To review or download a PDF version of this ransomware incident report, click:
Progent's Crypto-Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting in West Palm Beach
For ransomware cleanup expertise in the West Palm Beach metro area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.