Welcome!

By registering with us, you'll be able to discuss, share and private message with other members of our community.

SignUp Now!

Using BBufStuff plugin to GetVersionExW info

Aug
2,799
144
I asked Microsoft CoPilot to provide me with an example .btm to demonstrate the use of the GetVersionExW and RtlMoveMemory Win32 APIs.
It also includes a demo of POKEing a string into a buffer.

Code:
@echo off

rem --- Load BBufStuff plugin
if not plugin BBufStuff plugin /l E:\utils\BBufStuff.dll

rem --- OSVERSIONINFOEXW size
set structsize=284

rem --- Allocate structure buffer
set osvi=%@balloc[%structsize]
set _=%@bfill[%osvi,1,0,0,%structsize,0]

rem --- Write dwOSVersionInfoSize
set _=%@bpokex[%osvi,0,4,%structsize,0]

rem --- Allocate temp buffer for szCSDVersion (256 bytes)
set tmp=%@balloc[256]
set _=%@bfill[%tmp,1,0,0,256,0]

rem --- Write Unicode string manually (UTF‑16LE)
set str=Service Pack Test
set len=%@len["%str"]

do i=0 to %@dec[%len-1]
    set ch=%@instr[%i,1,"%str"]
    set code=%@ascii[%ch]
    rem write low byte
    set _=%@bpokex[%tmp,%@eval[%i*2],1,%@eval[%code & 0xFF],0]
    rem write high byte
    set _=%@bpokex[%tmp,%@eval[%i*2+1],1,0,0]
enddo

rem --- Copy ONLY the actual UTF‑16 string length (len * 2 bytes)
set bytelen=%@eval[%len * 2]

set dstptr=%@eval[%@bbinfo[%osvi,1] + 20]
set srcptr=%@bbinfo[%tmp,1]
set _=%@winapi[kernel32.dll,RtlMoveMemory,%dstptr,%srcptr,%bytelen]

rem --- Free temp buffer
set _=%@bfree[%tmp]
unset tmp srcptr dstptr _ bytelen

rem --- Call GetVersionExW
set osvi_ptr=%@bbinfo[%osvi,1]
set rv=%@winapi[kernel32.dll,GetVersionExW,%osvi_ptr]

echo API returned: %rv
echo.

echo Major Version: %@bpeekx[%osvi,4,4,0,0]
echo Minor Version: %@bpeekx[%osvi,8,4,0,0]
echo Build Number : %@bpeekx[%osvi,12,4,0,0]
echo Platform ID  : %@bpeekx[%osvi,16,4,0,0]

echo.
echo CSD Version (Unicode):
bbdump /c:20 /m:256 /h /i %osvi

rem --- Cleanup
set _=%@bfree[%osvi]
unset osvi osvi_ptr rv structsize

Output;
Code:
R:\>test1.btm
API returned: 1

Major Version: 10
Minor Version: 0
Build Number : 19045
Platform ID  : 2

CSD Version (Unicode):

Buffer 0000018180793230 :

00000014  00 00 53 00 65 00 72 00  76 00 69 00 63 00 65 00  00 00 50 00 61 00 63 00  ··S·e·r·v·i·c·e···P·a·c·
0000002c  6b 00 00 00 54 00 65 00  73 00 74 00 00 00 00 00  00 00 00 00 00 00 00 00  k···T·e·s·t·············
00000044  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
0000005c  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
00000074  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
0000008c  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
000000a4  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
000000bc  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
000000d4  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
000000ec  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  ························
00000104  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00                           ················

Displayed 256 bytes from 0000018180793230.

Interesting how Microsoft Copilot did not UNSET _ at the end of the code.

Joe
 
Back
Top