GridinSoft Threat Intelligence

amdkmdag.sys threat report

Detected as Trojan.Generic File reputation report
MD5 4b7b9b7df5ce72f7725f38d82880062d
Latest seen 2025-10-15 23:00:46 (7 months ago)
First seen 2025-10-15 23:00:46 (7 months ago)
Size 79 MB

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2025-10-15 23:00:46 (7 months ago)
File hash
4b7b9b7df5ce72f7725f38d82880062d
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic.

Timeline

First seen 2025-10-15 23:00:46 (7 months ago); latest analysis 2025-10-15 23:00:46 (7 months ago).

Publisher context

Company metadata: Advanced Micro Devices, Inc. Product metadata: ATI Radeon Famil.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

amdkmdag.sys is a Windows file recorded in the ThreatInfo database. It is associated with ATI Radeon Famil. The reported company name is Advanced Micro Devices, Inc. The current detection status is Trojan.Generic, based on the latest analysis from 2025-10-15 23:00:46 (7 months ago).

If amdkmdag.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

Product Name: ATI Radeon Famil
Company Name: Advanced Micro Devices, Inc
MD5: 4b7b9b7df5ce72f7725f38d82880062d
Size: 79 MB
First Published: 2025-10-15 23:00:46 (7 months ago)
Latest Published: 2025-10-15 23:00:46 (7 months ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2025-10-15 23:00:46 (7 months ago)
amdkmdag.sys detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%system%\driverstodell\filerepository\u0369996.inf_amd64_341b825757693c75

ThreatInfo has observed amdkmdag.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for amdkmdag.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

amdkmdag.sys is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Native
Entry point 0x000adfd0
Image base 0x0000000140000000

PE Sections:

Sections 58
Raw data 83080704

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 4801536 bytes · 5.8% of section data
MD5 8ed80e0f69665d481067caf04225b595
.rdata 4311040 bytes · 5.2% of section data
MD5 902e61982b8b3184c186cbd3d967d7be
.data 10060288 bytes · 12.1% of section data
Large raw data
MD5 81e436e2d26d6c4b733a876aed139603
.pdata 720896 bytes · 0.9% of section data
MD5 ff7a83680f63195c1a7bb541fe161dfc
KMDDKFQT 512 bytes · 0.0% of section data
Uncommon name
MD5 4c023024ceb6894dad44f1ad65b3b6ba
PAGE_COM 632320 bytes · 0.8% of section data
Uncommon name
MD5 57bdb0e1674a8801487a41c3b75d796c
PAGE 2048 bytes · 0.0% of section data
Uncommon name
MD5 c9fa8f065f319d71f476d53283a50a4c
PAGED2PC 4932608 bytes · 5.9% of section data
Uncommon name
MD5 a0526a925380f78f49460d42fc5d3c13
PAGEPPLC 1593856 bytes · 1.9% of section data
Uncommon name
MD5 113ff5f3c62fb90730bc239c8b471810
PAGE_CPC 236032 bytes · 0.3% of section data
Uncommon name
MD5 f6bfdaa7e60260837e29673285766108
PAGE_DRM 10752 bytes · 0.0% of section data
Uncommon name
MD5 2130e88a8dbb28756862ca736f303c09
PAGE_HDC 18432 bytes · 0.0% of section data
Uncommon name
MD5 63e76748fff5ae03662c0c1134b8ffb2
PAGE_OPM 7168 bytes · 0.0% of section data
Uncommon name
MD5 9473845499f2dcf16746f32d667a4d5f
PAGE_WSC 5120 bytes · 0.0% of section data
Uncommon name
MD5 2674cdd2632528aab30117a934ea1b8b
PAGE_PRE 3072 bytes · 0.0% of section data
Uncommon name
MD5 c4d2d0e8e5ec194c423c1e9bc1d4b573
PAGESIPC 528384 bytes · 0.6% of section data
Uncommon name
MD5 308c2e689e5f9fd61513cdba1d31dfe8
PAGEISPC 150016 bytes · 0.2% of section data
Uncommon name
MD5 814aa7609ac54967afb3c9c0425e6ea0
PAGEDMCC 10752 bytes · 0.0% of section data
Uncommon name
MD5 833495571285a1827fc96248c493a095
PAGECALC 370688 bytes · 0.4% of section data
Uncommon name
MD5 2d33f5e6b4a9b6faf862b17ba66ccae5
PAGED3PC 1119744 bytes · 1.3% of section data
Uncommon name
MD5 32f28db4f975c1ede5d49bc404b76c5a
PAGEDSIC 86016 bytes · 0.1% of section data
Uncommon name
MD5 89531721b244a717456832a64806cd93
PAGED2IC 376320 bytes · 0.5% of section data
Uncommon name
MD5 7aeff974acb2a5af0faf8b75df7b46fa
PAGEDCIC 3109376 bytes · 3.7% of section data
Uncommon name
MD5 17bce3dd519fc394301c59cfd42615e6
PAGED3IC 206336 bytes · 0.2% of section data
Uncommon name
MD5 225dd7a01d60e13472eed90d27063c64
PAGEKMDD 1536 bytes · 0.0% of section data
Uncommon name
MD5 b1ddbfc3637e43e35622636096909a3a
PAGEIVEG 146944 bytes · 0.2% of section data
Uncommon name
MD5 c8df284520f95e2289a55952c06cee7a
PAGEINAV 150016 bytes · 0.2% of section data
Uncommon name
MD5 e6d1e0c84c71b644e51d52766cb57a4f
PAGEINV3 30720 bytes · 0.0% of section data
Uncommon name
MD5 e5562ae7b29416425957f63b7f3d5ba9
PAGEILEG 289280 bytes · 0.3% of section data
Uncommon name
MD5 b94007b6988557708bc35d10bd7a7a3f
PAGEICMN 10752 bytes · 0.0% of section data
Uncommon name
MD5 7048a2df0f48e146181e3dad1ab6c337
PAGED2PD 234496 bytes · 0.3% of section data
Uncommon name
MD5 e77591eefc881de88ca3d9af93e6d034
PAGED2PR 355840 bytes · 0.4% of section data
Uncommon name
MD5 6f28db7815664c3323b28ee36a4ae9a7
PAGEPPLD 3738624 bytes · 4.5% of section data
Uncommon name
MD5 4777efcdd5d1b29652a38dbcab8a7e05
PAGE_RW 572928 bytes · 0.7% of section data
Uncommon name
MD5 7825344400ac7a70195f39f2bf194341
PAGE_CPR 59904 bytes · 0.1% of section data
Uncommon name
MD5 1f6747babbc3a84db243fe18cfdea9ae
PAGE_DRM 2048 bytes · 0.0% of section data
Uncommon name
MD5 24d3a652fa326dfa2c396b73f69a94d5
PAGE_HDC 6144 bytes · 0.0% of section data
Uncommon name
MD5 14f15f17b5762ca1633216fdcb14a41d
PAGE_OPM 3072 bytes · 0.0% of section data
Uncommon name
MD5 f0ed1398c16387f75b5270c86fc4b1d1
PAGE_WSD 1536 bytes · 0.0% of section data
Uncommon name
MD5 c5b4271026278a6bd4af44b183b0cd28
PAGE_WSR 4608 bytes · 0.0% of section data
Uncommon name
MD5 4f7346d8d502ec5d5232cc7eff9f2e35
PAGE_PRE 512 bytes · 0.0% of section data
Uncommon name
MD5 bce87ef823d81edb938f307b79a2a233
PAGESIPD 34370048 bytes · 41.4% of section data
Large raw data Uncommon name
MD5 d55a48fdf4213b4d1c995d7872090f5f
PAGEISPD 18944 bytes · 0.0% of section data
Uncommon name
MD5 5d327fa2cdd371e2556d829309ff77de
PAGEDMCD 1004032 bytes · 1.2% of section data
Uncommon name
MD5 23d0b27498292adc933284c39518cc86
PAGECALD 6643200 bytes · 8.0% of section data
Large raw data Uncommon name
MD5 a2c82f844bec4abc68531fbb41071d08
PAGEDSIR 16384 bytes · 0.0% of section data
Uncommon name
MD5 f0a9c2e6d8cb297f2fe411fb5b4640c4
PAGED3IR 12800 bytes · 0.0% of section data
Uncommon name
MD5 ae64aed642e9619c4a6c4e5dc95605d9
PAGED2IR 26624 bytes · 0.0% of section data
Uncommon name
MD5 a99b2610ae97987e784636f01691131a
PAGEDCIR 720896 bytes · 0.9% of section data
Uncommon name
MD5 a1130d31580563f23137c8ec062ef4aa
PAGED3ID 529408 bytes · 0.6% of section data
Uncommon name
MD5 e1ce7f438f895169444bf3029742c1b7
PAGED3PD 51712 bytes · 0.1% of section data
Uncommon name
MD5 ca01e015f8e4569ddef0eccc257540bb
PAGED3PR 396288 bytes · 0.5% of section data
Uncommon name
MD5 c5957fa82236e32a956df8ebaf2b550c
PAGEDSID 4096 bytes · 0.0% of section data
Uncommon name
MD5 3e8a3a1e5f57720965b49d631e331e13
PAGEDCID 58880 bytes · 0.1% of section data
Uncommon name
MD5 e2a749e6936d6e8d5a9ebd646d75d533
PAGED2ID 1024 bytes · 0.0% of section data
Uncommon name
MD5 dcbef2b96ddd4a971e790bc721b00749
INIT 8192 bytes · 0.0% of section data
Uncommon name
MD5 7a16e51c18c94c387b4035b857c2e7bf
.rsrc 36864 bytes · 0.0% of section data
MD5 cb27d82020af6cf28df2f978cecde771
.reloc 279040 bytes · 0.3% of section data
MD5 95e13575689ab1a43e0dcf79cfd3bbd6

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Trojan.Generic

This report identifies amdkmdag.sys by MD5 4b7b9b7df5ce72f7725f38d82880062d. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with 4b7b9b7df5ce72f7725f38d82880062d.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found.