At risk of being a pendant, BO wasn't self-replicating so it isn't a "virus" - it was just a trojan/backdoor utility.
BO was a virus as much as an OpenSSH server is a virus. It actually provided some pretty useful remote administration tools that weren't available for consumer versions of Windows until Windows NT became the standard.
The attacker would send you a file ICQ called 'mypic.jpg', with a button 'Open file' below the name. Most users weren't aware that ICQ would just cut off any characters from a filename that were too long to display. So 'mypic.jpg _ _ _ _ _ _ _ _ _ _ .exe' would just show 'mypic.jpg'.
If you click 'Open', BackOrifice would install invisibly and delete the original installing file. You would be confused and look for the picture after 'Open' just did nothing, but it wouldn't be on the disk. So you message the attacker back with "Oh I didn't get it." and they send you some other, actual jpg, 'mypic.jpg' and you forget all about it.
This was before UAC, before Zone.id and Mark of the Web marking programs as 'Dangerous files' if they came from the internet. So no confirmation was required to execute. No firewall came up saying "Hey this is trying to access the internet".
And it could do everything CDC said it could. View a screen, look through files, access their camera, control their desktop.
I'm sure someone at MS eventually regretted their statements because the initial response then doesn't reflect their reaction over the long term:
> "Back Orifice" does not expose or exploit any security issue regarding Windows, Windows NT, or the Microsoft BackOffice suite of products.
> Users of Windows 95 and Windows 98 following safe computing practices (including not installing software from unknown and untrusted sources) are not at risk.
> As far as demonstrating an inherent security vulnerability in the Windows platform, this is simply not true. "Back Orifice" could introduce security vulnerabilities in the system on which it is installed, but, as with all other software, a user must make the choice to install it.
Anyway, BackOrifice is why you now get so many pop-ups trying to run an executable from the internet.