Hmm, a FakeAV using the winlocker method. That's a little different. Thanks for the upload.

A forum for reverse engineering, OS internals and malware analysis
hxxp://rghost.net/50995422
hxxp://futsyscarepay.com/payment.php
http://futsyscarepay.com/payment_process.php
> https://migs.mastercard.com.au/vpcpay (vpc_Merchant=9800000100)
>> https://www.vbv.ktb.co.th/vbvads/paWarning.aspx
• dns: 1 ›› ip: 130.185.105.68 - adresse: FUTSYSCAREPAY.COM
• dns: 1 ›› ip: 203.42.65.51 - adresse: MIGS.MASTERCARD.COM.AU *legit*
• dns: 1 ›› ip: 202.12.117.153 - adresse: WWW.VBV.KTB.CO.TH *legit*