A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #18130  by cjbi
 Sun Feb 10, 2013 11:20 am
PbBot.png
PbBot malware family (Visualized)
PbBot.png (73.1 KiB) Viewed 412 times
General description of PbBot malware family:
Korean online card gamer targeted malware (for spying and cheating)

1. Bootkit(s)
1) Guntior bootkit http://www.kernelmode.info/forum/viewto ... =16&t=1765
2) PbBot bootkit (alias Plite, GBPBoot, Gupboot) http://www.kernelmode.info/forum/viewto ... =16&t=1666
3) Yet another PbBot bootkit (alias Zegost, Verconf, Backboot) http://www.kernelmode.info/forum/viewto ... =16&t=2191
4) Aduska bootkit http://www.kernelmode.info/forum/viewto ... =16&t=2473

2. Non-bootkit(s)
PbBot(s) http://www.kernelmode.info/forum/viewto ... =16&t=2147