Use the FileWatcher plug-in (on the site) to find when key files are loaded and see how they are decoded (if your software loads data from a file to determine if it should work).
If they don’t use files to activate full versions (or whatever), just use the disassembler the way as you would with any other debugger/disassembler.
3.0.1.3 Pro is on the site.
It does a lot more in kernel-mode now, for example the Hex Editor can now view RAM above 0x7FFFFFFF.
The next release will have a new feature of considerable power.
Script Searching.
Memory Hacking Software will run its normal searching routines, managing buffers and the address list for you.
For each address, however, it will call a user-defined script callback function to determine if the address should be added to the list of returns.
The script function simply returns true or false, depending on whether the address should be added or not.
This allows the user to decide exactly what addresses are added to the final list, using any criteria he or she pleases.
This allows you to encapsulate any kind of searching feature you desire into the software, including all forms of encrypted searches, ArtMoney’s formula search, structure searches, etc.
L. Spiro