Hi Duncan,
If the computer has been compromised by AGTA ransomware/malware and you cannot boot into Windows Recovery or Safe Mode, I would avoid trying to remove the malware manually while the system is running.
I recommend these steps:
Disconnect the affected PC from the network
Disconnect Ethernet.
Turn off Wi-Fi if possible.
Do not connect external drives that contain important files.
**Protect your other accounts/devices**
From a known-clean device, change important passwords, especially your Microsoft account, email, banking, and other sensitive accounts.
Enable MFA where available.
If this is a work/school device, contact your IT/security team immediately.
**Try Windows Recovery from installation media** If the existing recovery environment is not working, create official Windows installation media on another clean computer and boot the affected PC from it. From the Windows Setup screen, select **Repair your computer** rather than installing Windows immediately.
**Do not format or reinstall Windows yet if the encrypted files are important.** If AGTA has encrypted your files, reinstalling Windows will not decrypt them. Preserve the affected drive and consider obtaining professional incident-response/data-recovery assistance if the files are critical.
**If you have a known-good backup**, restoring from that backup after completely removing/rebuilding the compromised system is generally safer than trusting the infected installation.
Also, the inability to access BIOS/UEFI is a separate issue from Windows Safe Mode. Safe Mode is a Windows boot option; BIOS/UEFI is firmware-level, so the correct key and procedure depend on the computer manufacturer/model.
If you can provide the PC manufacturer/model and the exact AGTA ransom-note text or filename extension added to the encrypted files, we can narrow down the recovery options without risking further damage to the data.