Rogue.anti.fake. Files;

Please if any of Bitdefender Lab is reading this and not just download the samples.


These samples are alot of big variant and i find them everyday out there but diffrience size but they have same FAKE-antivirus.


So Please try to make some strong heuristic or generic for these FAKE because it seem they will never stop, if you add those files to signature then tomorrow same Variant and same fake but UNDETECTED by Bitdefender.


Please try to do something so even the other Familiar of those fake will be detected...


here are the samples:


/applications/core/interface/file/attachment.php?id=3427" data-fileid="3427" rel="">Rogue_Antivirus_Fake.rar