A brand new rogue.
Home page:
Typical fake dialog box:
Fake scan:
Application:
This program creates fake “infection files” These files are placed into the document and SettingsUserAcctLocal SettingsTemp directory (list here). Here is an example of what is actually inside one of these fake files:
Payment is done through Bucksbill:
Alex Eckelberry
(Credit to Bharath and Patrick Jordan)