BackOrifice Trojan
Backorifice (BO) - Remote Administration Sniffer
    Review date: 01.01.2011

A Trojan horse is not really a virus. The Back Orifice is an intruder tool that consists of two pieces, a client application and a server application. Here, you'll find some explanations on how a Trojan horse (BO) intrudes a system and how it protects itself from being detected including detailed information on default backdoor ports.

First of all, Backorifice or BO is not a virus. This is a free Win32 based Trojan program. Do not download or upload software unless you have opted to do so. This trojan can affect Windows 95 and Windows 98 system. It does not work on Windows NT.

Note: According to the lastest security reports, this malware is not able to break through a firewall. Detection - Backdoor Rootkit for Windows Hosts
Using nmap and doing a UDP scan for port 31337 against our hosts is the only way that you can really detect BackOrifice's presence on our network. It's a risk to keep the BO server in your computer.

Designed to work on Windows 95 and 98 machines, this remote administration tool allows the user to remotely control the operating system, including:

  • View the contents of any file on the computer
  • Execute any program
  • System
  • Passwords
  • Network
  • File system
  • Registry
  • Processes


In addition to that, this backdoor has the ability to transfer files, delete, create and modify files on your hard drive. Ability to list cached and screen saver passwords and capture a screenshot.

Besides, Back Orifice trojan needs to be executed by the user for it to be installed. Best of all, once executed and downloaded by the user it will install itself in such a way that it will be active all the time.

Back Orifice adds an entry to the Windows Registry to achieve this. Besides, the client application, running on one machine, may be used to monitor and control online a second machine.


The presence of Back Orifice (BO) installed in the computer will not be evident to the affected user. The size of this trojan file is 124,928 bytes. It can also be slightly more than this size.Troj/NeoBO-A is a Trojan for the Windows platform.



BackOrifice's Features List:
  • Enables to restart the computer.
  • Executes any program.
  • Forces the computer to lock up or freeze.
  • Session logging
  • Multiple server connections at once
  • Process control, start, stop, list
  • Graphical remote registry editing
  • Access console programs
  • Network redirection of TCP/IP connections

Latest version known:
  • backdoor.win32.bo.a
  • Backdoor IRCNite pl
  • Back Orifice 1.20
  • Back Orifice 1.3
  • Back Orifice 1.41
  • Back Orifice 2000 1.0 International

Back Orifice Screenshot: Designed with a client-server architecture.

Actions are performed on the server by sending commands from the client to a specific ip address.

In the event you do inadvertently install a Trojan horse and if the server machine is not on a static address, it can be located by using the sweep or sweeplist commands from the text client, or from the gui client using the "Ping..." dialog or by putting a target ip of "1.2.3.*". If sweeping a list of subnets, when a server machine responds the client will look in the same directory as subnet list and will display the first line of the first file it finds with the filename of the subnet.

Overall, communication packets used by Back Orifice are encrypted with a user definable key, so only the intended client can control the server.



BO2K Configuration Wizard
Br> Back Orifice Win32 GUI Client 1.20 Patched

Three basic steps to removing Back Orifice:

  • Remove its Registry entry
  • Shut down and restart your system
  • Then delete the actual program.



NOTE: This information is supplied for educational purposes only. The best defense against BO Trojan is to follow safe computing practices.
What is Backorifice or BO Trojan and Zeus?
  • This malware poses the greatest danger to users’ PCs. Also known as Kneber, Zbot, Gorhax, PRG, Wsnpoem, Zeus is a trojan horse. It is one of the nastiest password stealing trojans in the world.

    The main route main route of infection is via spam and attachment. Moreover, Zeus can be difficult to detect even with up-to-date antivirus software.
  • BO Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user's knowledge. Update and download your antivirus databases and perform a full scan of the computer.

    Most today's anti-virus programs will guard against Trojan horses and remove them should they be installed.

    Find here the answers to the most commonly asked questions about trojan horse. Learn how to identify Internet threats and protect yourself online.
Backorifice - Can you spot the trojans?
  1. Functions of this trojan
  2. Overview of BOserve and BOclient
  3. Information on Back Orifice and Netbus
  4. What is Back Orifice?
  5. Back Orifice, NetBus, and Others
  6. Backdoor.Bionet.40a
  7. Backdoor Malware - how hackers use it
  8. Backdoor Trojan
  9. How to remove Back Orifice 2000
Related to Site Reviews
  • Top Firewall Software - Learn about the latest technologies. Besides, we rank the best personal firewall
  • Top 10 Antivirus Software - To read our top-ranked antivirus programs review and see how they work by
  • Free Registry Repair - How to fix the Windows registry and system file errors? Read insightful software
  • Top 10 Antispam - Latest news about new anti-spam products, protection, evaluations, tips and tricks
  • Free Spyware Remover - Looking for anti-spyware that really works? Here's you'll find reviews of the best
  • Subseven Trojan Review - To fight this problem, a spyware removal tool as is a firewall are helpful
2011 Internet Security - Sponsored Sites

Bsecure Internet Filter - is best because we address the latest threats with patented, cloud based technology. On top of that, the software also comes with a pop-up blocker, a firewall and controls for other Internet applications

Free Spyware Remover - Most computers that are connected to the internet today are infected by some sort of adware and spyware. You may have invested in the best security tools, but still it is advisable to use...

Web Blocking Internet Filter - The Safe Eyes Parental Control Software is the ideal online protection for you. It warns when kids post private information online. It allows you to control what applications each user can access on your PC. Besides, this top performer among internet

Security Scanner for Home Users - Infiltrator can audit each scanned computer for improper registry settings, suspicious open ports, vulnerable services, scripting exploits, weak password policies, and improper user configurations The program can be

GFI Software - Leading developer of network security, content security and messaging software. Its product range includes email content exploit checking and anti-virus software; security scanning and patch management tools.

WS FTP Pro - Secure File Transfer - offers industry-leading security and customization capabilities. It delivers the highest level of encryption and a range of features that enhances productivity and communication. Support for Microsoft IIS and Apache Web servers.