Hacked by AGTA BAckup malware and can't fix it

Duncan R. Olney 0 Reputation points
2026-09-27T04:15:28.2633333+00:00

I was hacked, and my computer has AGTA Backup malware. I cannot get into the BIOS to boot into Safe Mode, and my power button only shows the Lock option. I have tried to boot with a Recovery Disk, but it didn't help

Windows for home | Windows 11 | Security and privacy
0 comments No comments

2 answers

Sort by: Newest
  1. Thomas4-N 22,380 Reputation points Microsoft External Staff Moderator
    2026-10-01T07:20:33.15+00:00

    Hello Duncan R. Olney,

    I’m sorry you’re dealing with this. To narrow down what’s blocking recovery, what happens when you try to start the PC from the recovery disk? Does it open a recovery screen, show an error, or start Windows as usual?

    Also, where did the “AGTA Backup” identification come from, such as a security alert or a file you found? That will help distinguish the boot problem from the suspected malware before suggesting another fix.

    Was this answer helpful?


  2. Abinesh Magudeeswaran 230 Reputation points Student Ambassador
    2026-09-27T04:51:45.7033333+00:00

    Hi Duncan,

    If the computer has been compromised by AGTA ransomware/malware and you cannot boot into Windows Recovery or Safe Mode, I would avoid trying to remove the malware manually while the system is running.

    I recommend these steps:

    Disconnect the affected PC from the network

    Disconnect Ethernet.

      Turn off Wi-Fi if possible.
      
         Do not connect external drives that contain important files.
         
         **Protect your other accounts/devices**
         
            From a known-clean device, change important passwords, especially your Microsoft account, email, banking, and other sensitive accounts.
            
               Enable MFA where available.
               
                  If this is a work/school device, contact your IT/security team immediately.
                  
                  **Try Windows Recovery from installation media** If the existing recovery environment is not working, create official Windows installation media on another clean computer and boot the affected PC from it. From the Windows Setup screen, select **Repair your computer** rather than installing Windows immediately.
                  
                  **Do not format or reinstall Windows yet if the encrypted files are important.** If AGTA has encrypted your files, reinstalling Windows will not decrypt them. Preserve the affected drive and consider obtaining professional incident-response/data-recovery assistance if the files are critical.
                  
                  **If you have a known-good backup**, restoring from that backup after completely removing/rebuilding the compromised system is generally safer than trusting the infected installation.
                  
    

    Also, the inability to access BIOS/UEFI is a separate issue from Windows Safe Mode. Safe Mode is a Windows boot option; BIOS/UEFI is firmware-level, so the correct key and procedure depend on the computer manufacturer/model.

    If you can provide the PC manufacturer/model and the exact AGTA ransom-note text or filename extension added to the encrypted files, we can narrow down the recovery options without risking further damage to the data.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.