Rogue:Win32/Defru redirects users to fake malware protection service. The fake scanner shows users a list of non-existent malware it claims to have found on the computer in question. If the user clicks the Pay Now button, he will be redirected to a payment portal called payeer . Most of Defru s victim-machines appear to be located in Russia. The United States is a distant second to Russia with Kazakhstan following closely behind in third.
Source: https://threatpost.com/a-new-spin-on-rogue-antivirus/107846/

