When searching our Virus Descriptions database for a specific program (e.g., Backdoor:W32/Example.A), you may be directed to this page if the overview below sufficiently describes the program.
Alternatively, you may be directed to this page if no description matching that specific query is currently available. You can submit a sample of the suspect file to our Response Lab for further analysis via:
A backdoor program is a remote administration utility that allows a user access and control a computer, usually remotely over a network or the Internet. A backdoor is usually able to gain control of a system because it exploits undocumented processes in the system's code.
These utilities may be legitimate, and may be used for legitimate reasons by authorized administrators, but they are also frequently used by attackers to gain control of a user's machine without their knowledge or authorization.
A typical backdoor consists of 2 components - the client and its server(s). An attacker will use a client application to communicate with the server components, which are installed on the victim's system. The server components can be delivered to the victim's system in numerous ways - as part of a worm or trojan payload, as an e-mail attachment, as a tantalizingly-named file on peer-to-peer networks, etc.
Once installed, the server component will open a network port and communicate with the client, to indicate that the computer is infected and vulnerable. An attacker can then use the backdoor's client to issue commands to the infected system. Depending on how sophisticated a client is, it can include such features as:
and so on.
A particular type of backdoor is the IRC backdoor, which can be controlled via a specific Internet Relay Chat (IRC) channel under the control of the hacker.
For more information, see Terminology: Backdoor.