Hmm, a FakeAV using the winlocker method. That's a little different. Thanks for the upload.
					
										
																										
            
A forum for reverse engineering, OS internals and malware analysis

hxxp://rghost.net/50995422hxxp://futsyscarepay.com/payment.phphttp://futsyscarepay.com/payment_process.php
> https://migs.mastercard.com.au/vpcpay (vpc_Merchant=9800000100)
>> https://www.vbv.ktb.co.th/vbvads/paWarning.aspx
• dns: 1 ›› ip: 130.185.105.68 - adresse: FUTSYSCAREPAY.COM
• dns: 1 ›› ip: 203.42.65.51 - adresse: MIGS.MASTERCARD.COM.AU *legit*
• dns: 1 ›› ip: 202.12.117.153 - adresse: WWW.VBV.KTB.CO.TH *legit*

