← Back to driver explorer
Driver intelligenceVulnerableVerified

thelper.sys

OCular THelper driver with arbitrary kernel memory read/write and process manipulation capabilities. Identified in ESET EDR killers research (March 2026) with 46 execution parents linked to AgentStp campaigns abusing the driver to disable EDR products.

UUID / 4c009d0a-8dfa-49f7-b043-b9cef3b01101ADDED / 2026-03-20AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

thelper.sysSample 1 · HVCI unknown
MD5
0f5b41e746b09c740e57c0262edbd140
SHA1
6ee94f6bdc4c4ed0fff621fec36c70ff093659ed
SHA256
7e783b0a0ff4710306bb3bca29296cf962ae77abc81245a99f12a9039158226f
Imphash
9823fa9dc48fb8be6f585ea4c49bdb7e
Authentihash MD5
fff1ff5603c26272f633b8899888fbad
Authentihash SHA1
33f90e874ba571db4ba40e173c4dfbdb6da28378
Authentihash SHA256
014b08b368700360821dc007724afe3f4305bf5fbe09fc0d24f5865f19ace197
Machine
AMD64
Version
4, 71, 408, 0
Publisher
TEC Solutions Limited.

Recorded command

sc.exe create thelper.sys binPath=C:\windows\temp\thelper.sys type=kernel && sc.exe start thelper.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: ESET Research @ESETresearch