GridinSoft Threat Intelligence

amdkmdag.sys threat report

Detected as Trojan.Heur! File reputation report
MD5 adc150e1d1bfa6da6bf79690cb56014a
Latest seen 2026-05-20 13:00:20 (a week ago)
First seen 2026-05-20 13:00:20 (a week ago)
Size 101 MB

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Heur!. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Heur!
Recommended action
Scan and remove
Last analysis
2026-05-20 13:00:20 (a week ago)
File hash
adc150e1d1bfa6da6bf79690cb56014a
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Heur!, part of the Trojan threat category.

Category context

Malware disguised as legitimate software or delivered through deceptive packaging. Related Trojan reports help compare this file with nearby detections, publishers, and hashes.

Timeline

First seen 2026-05-20 13:00:20 (a week ago); latest analysis 2026-05-20 13:00:20 (a week ago).

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present. Review the Trojan category for related samples and common context.

amdkmdag.sys is a Windows file recorded in the ThreatInfo database. The current detection status is Trojan.Heur!, based on the latest analysis from 2026-05-20 13:00:20 (a week ago). ThreatInfo groups this verdict with Trojan reports for broader family-level investigation.

If amdkmdag.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

MD5: adc150e1d1bfa6da6bf79690cb56014a
Size: 101 MB
First Published: 2026-05-20 13:00:20 (a week ago)
Latest Published: 2026-05-20 13:00:20 (a week ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2026-05-20 13:00:20 (a week ago)
amdkmdag.sys detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%system%\driverstore\temp\{d751c2af-410e-fd43-81c3-6f3311ac26f1}

ThreatInfo has observed amdkmdag.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for amdkmdag.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

amdkmdag.sys is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Native
Entry point 0x000f4340
Image base 0x0000000140000000

PE Sections:

Sections 59
Raw data 106561536

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 7610368 bytes · 7.1% of section data
Large raw data
MD5 37e408bb5aae7076674f5c6e604a749c
.rdata 5802496 bytes · 5.4% of section data
Large raw data
MD5 f177af75ade89adc97c2c6d89550c47d
.data 9051136 bytes · 8.5% of section data
Large raw data
MD5 82963ac6aaa0c5a09863c685461c4efe
.pdata 865792 bytes · 0.8% of section data
MD5 43432c92dad1e51af3cd6f5988c301cc
KMDDKFQT 512 bytes · 0.0% of section data
Uncommon name
MD5 4c023024ceb6894dad44f1ad65b3b6ba
PAGE_COM 497152 bytes · 0.5% of section data
Uncommon name
MD5 8f71b854518c4ea5148817d1161b6d80
PAGE 2560 bytes · 0.0% of section data
Uncommon name
MD5 96eafd1c5543dca66e0cae29d0f4340a
PAGEPPLC 1172480 bytes · 1.1% of section data
Uncommon name
MD5 dde640864744592382b54f985ed08537
PAGE_CPC 240640 bytes · 0.2% of section data
Uncommon name
MD5 21805c8ec96e31cd4562bbf009f69470
PAGE_DRM 11776 bytes · 0.0% of section data
Uncommon name
MD5 afcaefc80a35ac6667d007f85981634c
PAGE_HDC 19968 bytes · 0.0% of section data
Uncommon name
MD5 a1f9e132e9185ee89f59565f4519ca26
PAGE_OPM 8192 bytes · 0.0% of section data
Uncommon name
MD5 033ec06e17a07dd1a524cb9da54d0afe
PAGE_WSC 6656 bytes · 0.0% of section data
Uncommon name
MD5 d49a04bf8a40c3bcf521667cad49a671
PAGE_PRE 3072 bytes · 0.0% of section data
Uncommon name
MD5 d2e7f9f6e832ffc38f3070c01f2f6ca8
PAGESIPC 905216 bytes · 0.8% of section data
Uncommon name
MD5 467e0f01d96a59f7ff34994ffede6848
PAGEDMCC 11776 bytes · 0.0% of section data
Uncommon name
MD5 36ea516b8a149db2a14f2ac9f345fbb9
PAGEKMDC 1536 bytes · 0.0% of section data
Uncommon name
MD5 304dec26cf4d907c4fe65cd071e0d5f1
PAGECALC 381952 bytes · 0.4% of section data
Uncommon name
MD5 9f2aca5028e91f335e4d6e2c92face35
PAGED3PC 835072 bytes · 0.8% of section data
Uncommon name
MD5 e729157b58238fe3bf81e6de3f9e6e85
PAGED2PC 3452928 bytes · 3.2% of section data
Uncommon name
MD5 18a49c21d7edc38bc7441c8056ef84af
PAGEDSIC 102400 bytes · 0.1% of section data
Uncommon name
MD5 2eb1e56320022e903cbad742b8c19ad9
PAGED2IC 208896 bytes · 0.2% of section data
Uncommon name
MD5 4d52ec9af3ca3ef0930e990730616e74
PAGEDCIC 2861568 bytes · 2.7% of section data
Uncommon name
MD5 c0815c4506ea81e35bcf4b5155f4ffbc
PAGED3IC 332288 bytes · 0.3% of section data
Uncommon name
MD5 c97bb77f7cef651d48134a512e746755
PAGEKMDD 1536 bytes · 0.0% of section data
Uncommon name
MD5 5d2add83bb5ca92231bec687c9703613
PAGEIVEG 146944 bytes · 0.1% of section data
Uncommon name
MD5 bd9f43780d2add3dd02be1ed67bab855
PAGEINAV 210432 bytes · 0.2% of section data
Uncommon name
MD5 59ebf2a0297b5060f7cc5338400a3eb9
PAGEINV3 77312 bytes · 0.1% of section data
Uncommon name
MD5 96d0b187006faa247542e14c4d0b849c
PAGEINV4 27136 bytes · 0.0% of section data
Uncommon name
MD5 433138eaba0b76cc9cc85fca75ada9d7
PAGEILEG 82944 bytes · 0.1% of section data
Uncommon name
MD5 009821197f0ddca926343106ece3dfa3
PAGEICMN 16384 bytes · 0.0% of section data
Uncommon name
MD5 3f5c06ac5cc62a4677fc3bd0035313a7
PAGEPPLD 120832 bytes · 0.1% of section data
Uncommon name
MD5 e5e2601aafc1934752ba6afdfa0c599c
PAGE_RW 572928 bytes · 0.5% of section data
Uncommon name
MD5 0ae3e75cdf6a48704ef076094c180690
PAGE_CPR 57856 bytes · 0.1% of section data
Uncommon name
MD5 fe9050ac4f044d8a94459b749d5d6002
PAGE_DRM 2048 bytes · 0.0% of section data
Uncommon name
MD5 dbcf687811fb9b1e7327fd8b86e50d92
PAGE_HDC 6656 bytes · 0.0% of section data
Uncommon name
MD5 44ca99aeb0280bfe4a3eedf5fc5064d3
PAGE_OPM 3584 bytes · 0.0% of section data
Uncommon name
MD5 8f26521a11b9582afb244d3677e451f7
PAGE_WSR 5632 bytes · 0.0% of section data
Uncommon name
MD5 4718c3188070fefcd4fc9100455a2a65
PAGE_WSD 512 bytes · 0.0% of section data
Uncommon name
MD5 379335896504b10c82ea7b5ba2e81a6c
PAGE_PRE 512 bytes · 0.0% of section data
Uncommon name
MD5 bce87ef823d81edb938f307b79a2a233
PAGESIPD 56544768 bytes · 53.1% of section data
Large raw data Uncommon name
MD5 7ac38047ce8741ea528fe2928add5658
PAGEDMCD 1668608 bytes · 1.6% of section data
Uncommon name
MD5 6e0fc78901ddbacebfdd2b59d0030b32
PAGE 512 bytes · 0.0% of section data
Uncommon name
MD5 f932b21d3ac81c5a990dd8904c03c9d9
PAGECALD 6647808 bytes · 6.2% of section data
Large raw data Uncommon name
MD5 2e8b83b4cf05b01bfb3f14b34c86b253
PAGED3PR 1812480 bytes · 1.7% of section data
Uncommon name
MD5 b8a39865e6b19b3225f8a1029f8a02b5
PAGEDSIR 19456 bytes · 0.0% of section data
Uncommon name
MD5 c3479db8dad2b6990c7b9a5999a99eb3
PAGED3IR 38912 bytes · 0.0% of section data
Uncommon name
MD5 903ce1f6195a4ffa34ca770a03360dde
PAGED2PR 251392 bytes · 0.2% of section data
Uncommon name
MD5 fd620720d5d212a1edb36867805ed638
PAGED2PD 59392 bytes · 0.1% of section data
Uncommon name
MD5 46c10d52ae5212bfbec2097c2112995e
PAGED2IR 17920 bytes · 0.0% of section data
Uncommon name
MD5 494bb7a42e7c1e5a07a14105b9ef7ccb
PAGEDSID 4608 bytes · 0.0% of section data
Uncommon name
MD5 467d6498a5a9ec45fa08855c2f79ecfa
PAGEDCIR 1015296 bytes · 1.0% of section data
Uncommon name
MD5 3df2dd81f528d781eadeee3bc9237a72
PAGED3ID 2209280 bytes · 2.1% of section data
Uncommon name
MD5 e7fd99b1b6d21c543e180452a6bfcb9e
PAGED3PD 52736 bytes · 0.0% of section data
Uncommon name
MD5 1a3aa2341e347d461a208ff26da5fa3a
PAGEDCID 77824 bytes · 0.1% of section data
Uncommon name
MD5 747a516217eeffaba6e8d1c90646cc76
PAGED2ID 1024 bytes · 0.0% of section data
Uncommon name
MD5 0f343b0931126a20f133d67c2b018a3b
INIT 9728 bytes · 0.0% of section data
Uncommon name
MD5 a162f87d777e2631927c2ead8ba75cf1
.rsrc 36864 bytes · 0.0% of section data
MD5 18747fcb2508eeec79415b32f63f3654
.reloc 373248 bytes · 0.4% of section data
MD5 cf7af328e9151f159a4272f3e044cac3

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Trojan.Heur!

This report identifies amdkmdag.sys by MD5 adc150e1d1bfa6da6bf79690cb56014a. It is part of the Trojan report group. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with adc150e1d1bfa6da6bf79690cb56014a.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found. Use the Trojan category to compare similar reports.