How to remove AmdTools64.sys

AmdTools64.sys

The module AmdTools64.sys has been detected as Suspicious Object

AmdTools64.sys

AmdTools64.sys is a Windows file recorded in the ThreatInfo database. It is associated with AMD Tools Driver. The reported company name is AMD. The current detection status is Suspicious Object, based on the latest analysis from 2026-03-24 23:00:59 (a month ago).

If AmdTools64.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Suspicious Object.

Product Name: AMD Tools Driver
Company Name: AMD
MD5: c430d33293f9abf681899ff0e25de3ac
Size: 75 KB
First Published: 2024-08-30 23:01:11 (2 years ago)
Latest Published: 2026-03-24 23:00:59 (a month ago)
Status: Suspicious Object (on last analysis)
Analysis Date: 2026-03-24 23:00:59 (a month ago)

The signature on AmdTools64.sys is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%temp%
%temp%
%temp%
%temp%

ThreatInfo has observed AmdTools64.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

75.0%
25.0%

The strongest geographic signal for this file is United States with 75.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for AmdTools64.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

AmdTools64.sys is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000140f0

PE Sections:

Name Size of data MD5
.text 30720 839c319f347fcfd08d23f5c1b9c5813e
.rdata 7168 7553cd0e2d71ed1c838b54f90df4abfc
.data 2560 55e2d936683d99127d5969a7b053055d
.pdata 2048 326629d6e892a0d8760b5d07b81e59e3
PAGE 7680 bcde4fadd1fe1ad19edf1253c7d31a60
INIT 3584 100d48d76fdcdc9de5d705bc6523d57c
.rsrc 1024 52977bc97c778752d0c9597da1213e4b
.reloc 512 cbde0e649c54ddbdc7fbda3fdef3b5ab

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for AmdTools64.sys