Thanks for downloading BoDetect v2.5. BoDetect is designed to detect and remove the Back Orifice and NetBus trojan horses. It will do the following:
BoDetect has been tested on Win95, Win98, and WinNT 4.0 (SP3).
01/29/99 v2.5 Updated to run under WinNT. Added support for NetBus 1.5x, 1.6, and 1.7 detection and removal. Added detection/removal of new 'modified' Back Orifice servers. Revised the user interface to be easier to use. Added several options to the 'Options' panel, including the ability to easily clear and/or view the log file. Upgraded the scanning engine to be faster and more memory efficient. Fixed several small bugs. Added AdminAlert feature. Added new graphics. 10/18/98 v2.01 Modified the installation procedure BoDetect uses to register the scan engine to improve reliability on certain systems that reported trouble. Fixed bug that could prevent options from being saved properly. 10/05/98 v2.0 Removed the installation package I was using. Too many people reported problems using it. Added 'AutoScan' so that BoDetect can automatically scan your system on startup without user interaction, if desired. Added ability to enable/disable event logging. Added 'silent' mode for easier use in automated environments (login scripts etc...). Added 'timed scanning' feature so that BoDetect can scan your system for infection at user defined intervals. Updated the user interface, BoDetect now puts itself in your system tray. Fixed bug in the scanning engine that could affect file renaming under certain circumstances. 09/03/98 v1.5 Added an installation program for easy setup and removal of BoDetect. User Interface has been reworked a little. Fixed a bug that sometimes incorrectly identified the %windows% path. Scanning engine upgraded. Now detects and removes certain leftover BO files and registry keys that can be created from certain configurations of Back Orifice. Also now removes the 'windll.dll' file that BO creates when it is run. 08/22/98 v1.0.2 The scanning engine has been upgraded for better detection. The generated log file has been cleaned up and should be easier to read. Infected files are now moved to an 'Infected Files' directory after disinfection. 08/14/98 v1.0.1 Fixed a bug that might prevent the infected file from being renamed. The process would still be killed and the registry entries removed. This problem only occurs in cases where Back Orifice is installed under its default name of " .exe". Now any infected file that was named " .exe" is renamed to BACKORIFICE.BOD for easy distinction. 08/09/98 v1.0 Initial Release.
BoDetect is easy to use. Simply unzip the zip file into a temporary directory and run 'setup.exe'. Follow the on screen instructions to complete the installation.
When you run BoDetect, the BoDetect icon will appear in your system tray. Right clicking on this icon will bring up a menu. From this menu you can do the following:
- Open: This will bring up the main BoDetect dialog (double clicking the tray icon does the same).
- Exit: Exit BoDetect.
To configure BoDetect, double-click the tray icon to bring up the main window. Next, select the 'Options' tab. BoDetect comes pre-configured, but you can easily customize its operation to your preferences:
- Autoscan: If this box is checked, then BoDetect will scan your system automatically when it is first run.
- Silent Mode: Selecting this option will let BoDetect run silently, only alerting you if Back Orifice is found on your system, or in the event of an error.
- Monitor System: This option will enable BoDetect to run in the background and scan your system at user-defined intervals (which you select from the list, in increments of one minute). If silent mode is also enabled, BoDetect runs silently in the background until an infection is discovered.
- Enable Logging: This option lets you turn scan logging on or off. You can also clear or view the log file by clicking the 'Clear Log' or 'View Log' buttons.
- AdminAlert: If this option is selected, BoDetect will send an email to a user-specified recipient if an infection is found. This feature is primarily aimed at network administrators to keep an eye on their networks. The alert email message will note the machine on which the infection was found, as well as the username of the user currently logged in to the machine. To configure AdminAlert, fill in the required fields:
- To: The email address of the person you want to receive the alert.
- Subject: The subject as it will appear on the email message.
- Mail Server: The mail server to use for sending the alert. This can be a machine name or an IP address.
- Port: The mail server port to use (typically 25).
Before using AdminAlert, please use the 'Send a Test Message' option to ensure AdminAlert works correctly on your network.
Once you have configured the options, click on the 'Detect/Remove' tab. Click the button labeled 'Detect'. If either Back Orifice or NetBus is detected, you get detailed information on how many instances were found, and the names of the executables and registry keys they were installed as.
Then, just click on 'Remove' and BoDetect will remove the trojans from your system instantly. The infected files will be renamed to a safe name so they cannot be accidentally executed. The scheme BoDetect uses to rename files is like this:
The renamed file(s) will be moved to a directory called 'Infected Files' that will be created in the same directory as BoDetect. You can delete them or do whatever you want to with them! BoDetect also creates a log file (BoDetect.log) that details the registry keys that were removed and the program files that were renamed.
Open control panel, select 'Add/Remove Programs' and then select BoDetect for uninstallation.