Ed should take a look at *S!Ri's blog. It nicely illustrates how the same malware is re-used with slight modifications over and over. For example, looking at the rogue.fakevimes, the latest version is Windows Antivirus Patch
. There are over 50 other versions in the family, each slightly different. After all, there is no money in paying for malware code if it can't be reused. Scroll down the page at S!Ri.URZ
and note that even the same GUI is reused.
(*S!Ri was the developer of Smitfraudfix, one of the early tools used for removing rogues. He is a member of the Malwarebytes team as a Research Engineer.)