We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:WinNT/Wador.A
Aliases: Trojan.Mebromi (Symantec) Win-Trojan/Mybios.5632 (AhnLab) Trojan.Bootkit.1 (Dr.Web) Rootkit.Win32.Mybios.a (Kaspersky) Troj/MyBios-C (Sophos)
Summary
Trojan:WinNT/Wador.A is malware installed as a Windows NT driver that writes code to certain versions of BIOS.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
If you suspect that your system has been affected with this malware, you may need to write a known-good copy of the Master Boot Record back to the disk to prevent the malware's driver from being loaded on the next reboot. This can be accomplished by using the Windows Recovery Console.
Please see the following articles for further details on using the Windows Recovery Console:
- Description of the Windows XP Recovery Console (Use the 'fixmbr' command)
- How to use the Bootrec.exe tool in the Windows Recovery Environment to troubleshoot and repair startup issues in Windows Vista (Use the /FixMbr option)
When the MBR has been successfully restored, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.
Furthermore, this threat may affect Award BIOS. If you think you need to update your BIOS, check the information that came with your computer or go to the computer manufacturer’s website. You may also refer BIOS: frequently asked questions (http://windows.microsoft.com/en-US/windows7/BIOS-frequently-asked-questions) for more information.