The first step is to see if the MBR has an exception, and if there is a red item, the MBR has been tampered with by the virus.
(The PT automatically confirms whether there is malicious code and the MBR code is hidden and then displays red)
The second step is to click on the automatic fix to fix:
It's about 10 seconds to confirm the recovery.
Next, remove the rogue ads and shortcuts left by Ghost Shadows.
(Ordinary deletion method is very cumbersome, the PT can be deleted only in one step)
Click Repair to take about 5 seconds
Finally, delete the Ghost shadow left behind the driver file
It's about 5 seconds,
Finally, the system reboots, and it can be restored to a clean system.
The ghost is actually just an entry-level bootkit, and the variants may be stronger later.
PowerTool can also counter MBR Rootkit that hide MBR code.
If there is no confrontation,
Repairing the MBR under DOS is the most thorough.
Reset:
Fdisk/mbr
FIXMBR (Windows Recovery Console)
Gdisk disk/mbr.