After initial check of this src, which is just helping to load dumped cheat, thus this is not src of neverlose, it seems to be real, I'll soon test it. All these things which are related with spoofing are essential to bypass security of neverlose dll, thus this is normal, but ngl I bet it was a lot of hard work...