When I create a Windows x86 process in a suspended state (CREATE_SUSPENDED) its CONTEXT contains:
- Virtual Address of Entry Point in
Eaxregister; - Virtual Address of Process Environment Block structure in
Ebxregister.
But when I do the same for x86_64 process then CONTEXT contains:
- Virtual Address of Entry Point in
Rcxregister (why notRax?) - Virtual Address of PEB structure in
Rdxregister (why notRbx?)
It seems logical to me to take Rax in x64 in place of Eax in x86 and Rbx in x64 in place of Ebx in x86 .
But instead of Eax→Rax and Ebx→Rbx we see Eax→Rcx and Ebx→Rdx.
Also, I see that 64-bit Cheat Engine is aware of this when opening the 32-bit process (notice the migration of the values eax↔ecx and ebx↔edx:
What was the reason to move from *ax register to *cx and from *bx to *dx in 64-bit processes?
Is it somehow connected to calling conventions?
Is it related to Windows only or do other OSes also have this kind of register repurposing?
Update:
Screenshots of just created x64 process in a suspended state:



