Ronen Tzur (later acquired by Invincea, then Sophos).

These patches often check if they are being run inside a virtual machine or a sandbox (ironically) to avoid analysis.

Often uses names like Patch.exe , Crack.exe , or Sbie-4.14-Full-Patch.exe . Behavioral Observations: