Skip to main content

Back Orifice

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • Back Orifice
  • BO
  • CDC-BO
  • BOSERVE
  • BOCLIENT
  • Orifice
  • Hacktool
  • Back_Orifice

Summary

There is no virus by this name. However, there is a toolkit from a hacker group Cult of the Dead Cow by this name.

Removal

Technical Details

This trojan horse allows an intruder to monitor and tamper with Windows 95 and Windows 98 computers over the Internet. There is no easy way for a computer user to know the attack is taking place, and there is no easy way to stop the attack once Back Orifice has installed itself on the computer.

In a typical attack, the intruder sends the Back Orifice trojan horse to his victim as a program attached to email. When the email recipient executes the program attachment, the trojan horse opens connections from the computer to the Internet. This allows the intruder to control the computer. The trojan horse is invisible and will restart itself automatically even if Windows is re-booted.

Back Orifice allows a hacker to view and modify any files on the hacked computer. It can create a log file of the computer users actions. It can take screen shots of the computer screen and send them back to the hacker. Or it can simply crash the computer.

F-Secure Anti-Virus detects and disinfects this trojan as Trojan.Win32.BO.

To manually remove Back Orifice, restart the machine in MS-DOS mode (Start/Shut Down/Restart in MS-DOS mode) and delete the BO server from Windows system directory. Usually this can be done by typing in the DOS prompt:

DEL C:\WINDOWS\SYSTEM\EXE~1

Variant:ALIAS:BOSniffer

This is a trojan which claims to detect Back Orifice, while in fact it is Back Orifice server itself. It is detected as Trojan.Win32.BO.b.

See: Netbus

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.