Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Sep 06, 2011 | Updated Sep 15, 2017

Trojan:WinNT/Wador.A

Detected by Microsoft Defender Antivirus

Aliases: Trojan.Mebromi (Symantec) Win-Trojan/Mybios.5632 (AhnLab) Trojan.Bootkit.1 (Dr.Web) Rootkit.Win32.Mybios.a (Kaspersky) Troj/MyBios-C (Sophos)

Summary

Trojan:WinNT/Wador.A is malware installed as a Windows NT driver that writes code to certain versions of BIOS.

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

If you suspect that your system has been affected with this malware, you may need to write a known-good copy of the Master Boot Record back to the disk to prevent the malware's driver from being loaded on the next reboot. This can be accomplished by using the Windows Recovery Console.

Please see the following articles for further details on using the Windows Recovery Console:

When the MBR has been successfully restored, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.

Furthermore, this threat may affect Award BIOS. If you think you need to update your BIOS, check the information that came with your computer or go to the computer manufacturer’s website. You may also refer BIOS: frequently asked questions (http://windows.microsoft.com/en-US/windows7/BIOS-frequently-asked-questions) for more information.

Follow us