TFA is checking those via imports, not copied DLLs.
I suppose they could LoadLibrary/GetProcAddress at runtime, but that'd be a lot of effort for obfuscation.
I suppose they could LoadLibrary/GetProcAddress at runtime, but that'd be a lot of effort for obfuscation.
No comments yet.