Threat Description

Backdoor

Details

Aliases:Backdoor
Category:Malware
Type:Backdoor
Platform:W32

Summary



A remote administration utility that bypasses normal security mechanisms to secretly control a program, computer or network.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



A backdoor program is a remote administration utility that allows a user access and control a computer, usually remotely over a network or the Internet. A backdoor is usually able to gain control of a system because it exploits undocumented processes in the system's code.

These utilities may be legitimate, and may be used for legitimate reasons by authorized administrators, but they are also frequently used by attackers to gain control of a user's machine without their knowledge or authorization.

A typical backdoor consists of 2 components - the client and its server(s). An attacker will use a client application to communicate with the server components, which are installed on the victim's system. The server components can be delivered to the victim's system in numerous ways - as part of a worm or trojan payload, as an e-mail attachment, as a tantalizingly-named file on peer-to-peer networks, etc.

Once installed, the server component will open a network port and communicate with the client, to indicate that the computer is infected and vulnerable. An attacker can then use the backdoor's client to issue commands to the infected system. Depending on how sophisticated a client is, it can include such features as:

  • Sending and receiving files
  • Browsing through the hard drives and network drives
  • Getting system information
  • Taking screenshots
  • Changing the date/time and settings
  • Playing tricks like opening and closing the CD-ROM tray

and so on.

SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More