REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Network Instruments\Observer\Filters\(Hack) Back Orifice Trojan]
"FilterBuffer"=hex:c6,00,00,00,07,00,00,00,17,00,1f,00,00,00,1e,00,00,34,02,11,\
  00,69,7a,00,00,00,00,00,00,00,00,17,00,36,00,00,00,1e,00,00,ec,02,11,00,00,\
  04,00,00,01,00,69,7a,00,00,17,00,68,00,4d,00,1e,00,00,fd,01,06,00,50,00,00,\
  00,00,00,00,00,00,00,1b,00,00,00,7f,00,1f,00,00,eb,00,00,00,00,01,00,02,00,\
  01,0d,00,00,00,02,02,10,00,17,00,00,00,a1,00,1e,00,00,7c,02,11,00,69,7a,00,\
  00,00,00,00,00,00,00,22,00,00,00,00,00,1f,00,00,8a,00,00,00,00,01,00,06,00,\
  01,00,00,00,00,01,09,73,65,76,65,72,3a,42,4f,2f,25,00,00,00,00,00,1f,00,00,\
  22,00,00,00,00,01,00,0a,00,01,00,00,00,00,01,0c,ce,63,d1,d2,16,e7,13,cf,38,\
  a5,a5,86
"RGBValue"=dword:000000ff
"szDescr"="This indicates that either a scan, reply or connection has been made to or from a Back Orifice probe or Web Server."
"bFilterBasedAlarm"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Network Instruments\Observer\ProtocolPresetsV9]

