Skip to content

Instantly share code, notes, and snippets.

@jaxFF
Last active July 13, 2026 16:15
Show Gist options
  • Select an option

  • Save jaxFF/7e9e74279a75900d0908536c5b18566b to your computer and use it in GitHub Desktop.

Select an option

Save jaxFF/7e9e74279a75900d0908536c5b18566b to your computer and use it in GitHub Desktop.
Reverse engineered HWiNFO 12-hour shared memory limit patch
>hwinfo64.exe
000000000022005C:3D->90
000000000022005D:00->90
000000000022005E:2E->90
000000000022005F:93->90
0000000000220060:02->90
0000000000220061:0F->E9
0000000000220062:86->81
0000000000220063:80->00
>hwinfo64.exe
0000000000232818:3D->90
0000000000232819:00->90
000000000023281A:2E->90
000000000023281B:93->90
000000000023281C:02->90
000000000023281D:0F->E9
000000000023281E:86->81
000000000023281F:80->00
@Styphoryte

Copy link
Copy Markdown

Note, that the technique used here (DLL sideloading) is commonly used by malware. A similar technique was recently used to hack CPU-Z, although with a malicious payload in the DLL. I'm not saying that this might contain any malicious payload, and I'm not intending to analyze it.

Neither am I going to explain the license terms or argue with certain individuals but note, that crossing certain boundaries can have consequences.

Also, your example is completely wrong anyway. The CPUID incident was a compromised web server and mirror host on their own official site distributing a malicious package. It had absolutely nothing to do with community made DLL bypasses like this even if they can potentially be "malware" so why bring up CPU-ID?

@malikm

malikm commented Jul 11, 2026

Copy link
Copy Markdown

@Styphoryte

Styphoryte commented Jul 11, 2026

Copy link
Copy Markdown

https://gist.github.com/N3mes1s/b5b0b96782b9f832819d2db7c6684f84

Equating a Russian supply-chain attack on CPUID to a local winmm.dll paywall bypass is a massive stretch, and we both know it. You can stop playing internet security guard in my mentions. I’ve already moved on to LibreHardwareMonitor anyway. I'm out, peace...

So to sum it up: you openly admit you refuse to analyze the .DLL file, and instead you're just using vague, pseudo-intellectual corporate threats to fear-monger some more. Glad we've gotten this far, thanks for all your help I guess.

Anyways, lmk if u manage to wake up and actually analyze this .DLL file yourself instead of randomly trying to argue with me about something that doesn't have anything to do with the .DLL within this repo specifically.

@kumit19

kumit19 commented Jul 12, 2026

Copy link
Copy Markdown

https://gist.github.com/N3mes1s/b5b0b96782b9f832819d2db7c6684f84

Equating a Russian supply-chain attack on CPUID to a local winmm.dll paywall bypass is a massive stretch, and we both know it. You can stop playing internet security guard in my mentions. I’ve already moved on to LibreHardwareMonitor anyway. I'm out, peace...​So to sum it up: you openly admit you refuse to analyze the .DLL file, and instead you're just using vague, pseudo-intellectual corporate threats to fear-monger some more. Glad we've gotten this far, thanks for all your help I guess.​Anyways, lmk if u manage to wake up and actually analyze this .DLL file yourself instead of randomly trying to argue with me about something that doesn't have anything to do with the .DLL within this repo specifically.

Note, that the technique used here (DLL sideloading) is commonly used by malware. A similar technique was recently used to hack CPU-Z, although with a malicious payload in the DLL. I'm not saying that this might contain any malicious payload, and I'm not intending to analyze it.
Neither am I going to explain the license terms or argue with certain individuals but note, that crossing certain boundaries can have consequences.

Winmm.dll is widely used in tons of things for memory hijacking and other such things I just know that's one of them from my simple knowledge over the years.

Anyways what's your point? Are you windows defender now or what?

Nobody asked you what the .DLL does why the hell out of anyone here would anyone expect the creator of HWinfo to analyze the .DLL file?

You're still off you're rocker with these goofy replies I see and can match the energy.

I still switched to LibreHardwareMonitor anyways because this is not worth it at all when there's an open source alternative when I only need it for HotSpot temp sensor overlay in-game using MSI afterterburner. Not quite sure what I'm doing use the wrong program to begin with.... That's my fault though there.

My point is before all of this non-sense I would've bought a perpetual license for lifetime one day if I could since your program does have some nice features I might use one day...

But after seeing your opened Issue which caused the creator of other AHK script to take it down I am definitely never going to now. Not that it matters to you anyways.

I have no gripe with you patching the "vulnerabilities" in your license to prevent stuff like this from working. That's totally understandable and expected from a dev with this sort of "feature" or paywalled feature I should just say in your program.

But going out of your way to fear monger some rando on a GitHub repo trying to automate the 12-hour reset counter is mind-boggling insane work to me.

Now especially after you're coming in here spewing common sense for no apparent reason adding absolutely nothing to answer any of the questions pertaining to my paragraph above I do not feel 1 bit of regret saying what I just said right now.

Bye now I'm going to decisively ignore any of your goofball replies that add nothing to anything if I can manage in the future

So it's not any disrespect towards you it's just the fact, or more specifically the methodology you go about choosing to handle these kind of things as a developer.

I think you need to, in my opinion fix in general or at least reflect upon your metholdogies here and if they're really helping anyone positively or not.

If you truly cared about HWinfo users, you would analyze the .DLL and see if it's malicious, to be more frank with you, instead of spewing your typical fear-mongering generic nonsense.

For your situation I would actually either ignore it number 1 and accept that no matter what you do u cannot stop people from trying to bypass license requirements. In general there's always going to be people who are trying to bypass licenses and these sort of stupid pay-walled "features". So no matter what you do someone will come along and get around it over and over and over and over as long as the feature is in the program you have running on your PC someone will come along and activate it...

Anyways so u go right ahead and lecture us all on the "malware" potentiality and try to fear monger us all instead of bothering to even begin to scratch any of my questions. But it is totally not surprising to me though, no qualms I understand you're protecting your program but my point still stands.

Accept the fact ppl are going to attempt to bypass your program's BS 12-hour time limit and move on. I don't see how it's worth a headache for either side here. Just keep patching out the memory they use and call it a day.​But why bother going out of your way to fearmonger more, exactly like you're still doing right now with your last reply?????

​God, you devs just don't comprehend this because you aren't the ones on the other end. We are the ones having to deal with the hassle of installing this software, only to realize the single useful feature is locked behind a 12-hour paywall.

And yet here you are, still lurking around seeking to find ppl bypassing your license just to fearmonger some more.

​Go crawl back home and shh already plz, as respectfully as possible. I don't think you understand where I'm coming from so hopefully now you can, even if it's a fractional amount then that's good in my books.

If you even read all of this which I highly doubt.....

Thank you for your support.
I think we probably only really need to use HWiNFO to measure the in-depth parameters of the computer system.
I find that MSI Afterburner itself does a good job of measuring FPS, temperature, usage, clock, etc., for both GPUs and CPUs, since I mainly use it to measure FPS and game performance.
I also tried LibreHardwareMonitor and it works really well, not to mention it's completely free.
But I still decided that using only MSI is fine.
In short, just use whichever software you feel most comfortable with.
Thank you for answering my question.
Best regards

@Ano-byte

Ano-byte commented Jul 13, 2026

Copy link
Copy Markdown

Note, that the technique used here (DLL sideloading) is commonly used by malware. A similar technique was recently used to hack CPU-Z, although with a malicious payload in the DLL. I'm not saying that this might contain any malicious payload, and I'm not intending to analyze it.

Neither am I going to explain the license terms or argue with certain individuals but note, that crossing certain boundaries can have consequences.

https://gist.github.com/N3mes1s/b5b0b96782b9f832819d2db7c6684f84

@malikm After you threatened that guy to make him remove the auto restart script from his git, anything that comes out of your mouth has no more worth than diarrhea.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment