http://bugs.winehq.org/show_bug.cgi?id=35027
Anastasius Focht focht@gmx.net changed:
What |Removed |Added ---------------------------------------------------------------------------- Keywords| |obfuscation
--- Comment #5 from Anastasius Focht focht@gmx.net 2013-12-02 04:40:58 CST --- Hello,
--- quote --- no, actually that is a chinese patch for euphoria need that function. --- quote ---
probably this thing here: http://vndb.org/r26314
The site needs registration so I can't really look at that patch/binary.
Anyway, why would a 'patch' need this internal API? The only reason I can think of is that this thing might be loader which does some hooking/hot patching business because the API lies in between CreateProcess() and native API NtCreateProcess() call chain. Hooking standard kernel32 or native process creation API as all the other gazillion protection or malware schemes do (which is proven to work and stable) seemed to be to easy for the authors?
Regards