Detecting Back Orifice and Netbus on Windows 95/98

6

You might be seeing strange activity on your system. If you are running Windows 95 or 98, the culprit is likely Back Orifice or Netbus. These are not viruses. They are Trojan horse programs. Their sole purpose is to let someone else access your machine over the internet. And usually, they do it for malicious reasons.

The mechanics are simple but dangerous. To let anyone use Back Orifice on your computer, they need you to install the server side of the application. This never happens on its own. The attacker has to trick you. They send you an executable file. Maybe it arrives in an email attachment. Maybe it’s a download from a sketchy website. You have to run it.

That is the “Trojan” part. It masquerades as something useful. It does not propagate itself like a traditional virus. You have to consciously or unconsciously execute the EXE file to install the server. Once you run that file, the server is installed. It sets up shop. It starts automatically every time you turn on the computer.

Once the server is installed, an attacker can run the client program and control your computer remotely. They can run programs. They can erase files. This is obviously a bad thing.

The danger lies in the remote control. With the server active, an “evil-doer” uses the BO client program to take the wheel. They can do nearly anything. Access files. Delete data. Install more malware. There is no good reason for this to happen.

Fortunately, Back Orifice is easy to detect. You can find it manually. You can also use software to spot it. If you suspect you have been hacked, check your startup programs. Look for suspicious processes. Don’t ignore the signs.

Why These Programs Matter Today

These tools were designed for a different era of the web. But they laid the groundwork for modern remote administration tools (RATs). The concept remains the same. Trick the user. Install a backdoor. Take control.

If you are still on legacy systems, the risk is high. Modern security practices didn’t exist then. There were no firewalls by default. No antivirus scans on startup. Just trust. And that trust was exploited.

Related Resources

For a deeper dive into these threats, check out the following:

  • How Computer Viruses Work
  • How Web Servers Work
  • Symantec: Information on Back Orifice and NetBus
  • Trojan horses: Back Orifice & Netbus
  • CNET News.com: Windows “back door” raises flags