I've already see alots of FakeAV samples who got a filename like 'BestAV.exe' Man, you have definitely intrigued me with your post :) And like that, i've started to hunt these 'BestAV' guys. After alot of coffee, i finally come inside the network. You will see, it's nicely organized, they are responsible for the MS Removal Tool plague. The main site is named BestAV2, you'll see only this: nicline.