If you have a screen that looks like this, you’ve probably been in contact with someone with a Middle Eastern accent.
The ransomeware style service they provide leaves you with a Windows 95 login screen that you can’t get past with any password you know. This is so they can call back later to “fix” what they did in the first place for an exorbitant sum of money.
Rule #1. Microsoft will never call you, unless you are advertising with them or you work for them. They will also not take over a browser to inform you that your computer is infected.
Rule #2. The FBI or IRS will never call you, unless you work for the FBI or IRS. Do your parents a favor and tell them that.
So, in order to fix this a series of steps must be taken.
1. Boot into a live OS of some kind either linux or minixp, or pull the harddrive and set it up in an external case to view the files.
2. Move to the directory \Windows\System32\Config\RegBack on the drive in question.
3. Copy all files in this directory and then paste/ overwrite them in the \Windows\System32\Config Directory.
NOTE: If there are no files in the folder named RegBack, the system cannot be recovered using this method.
This will overwrite any changes made to the registry and restore it to the backed up good copy.
Boot the system as normal. Your access will be restored.