Hacker News new | ask | show | jobs
by muststopmyths 195 days ago
TFA is checking those via imports, not copied DLLs.

I suppose they could LoadLibrary/GetProcAddress at runtime, but that'd be a lot of effort for obfuscation.