I've already see alots of FakeAV samples who got a filename like 'BestAV.exe' Man, you have definitely intrigued me with your post :) And like that, i've started to hunt these 'BestAV' guys. After alot of coffee, i finally come inside the network. You will see, it's nicely organized, they are responsible for the MS Removal Tool plague. The main site is named BestAV2, you'll see only this: nicline.
![Tracking Cyber Crime: Inside the FakeAV Business](https://cdn-ak-scissors.b.st-hatena.com/image/square/ebc3ab0e691c8e269142cffed70da97557284b0e/height=288;version=1;width=512/https%3A%2F%2Fblogger.googleusercontent.com%2Fimg%2Fb%2FR29vZ2xl%2FAVvXsEgLFBuFP5CMCP8pGb0upgLLcihoiAODMwhdp3uc9kNsB3tgv3R_iXGoSwzfz0PMMlU3wiuKQ3lNj1OC29U_E86IL4gxLdh8VOU6n6q0J0IY8Dmi719YuUu6TZq62QPraFtvI0p_e5tQ-K5w%2Fw1200-h630-p-k-no-nu%2F17.png)