GridinSoft Threat Intelligence

atikmdag.sys file report

Under review File reputation report
MD5 7db538ce17bebb51c0182adcc264c63a
Latest seen 2021-01-12 16:17:44 (5 years ago)
First seen 2021-01-12 16:17:44 (5 years ago)
Size 62 MB

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2021-01-12 16:17:44 (5 years ago); latest analysis 2021-01-12 16:17:44 (5 years ago).

Publisher context

Company metadata: Advanced Micro Devices, Inc.. Product metadata: ATI Radeon Family.

Digital signature

Signed by Advanced Micro Devices, Inc.;Advanced Micro Devices INC.;Microsoft Windows Hardware Compatibility Publisher. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

atikmdag.sys is a Windows file recorded in the ThreatInfo database. It is associated with ATI Radeon Family. The reported company name is Advanced Micro Devices, Inc.. The current detection status is Undefined, based on the latest analysis from 2021-01-12 16:17:44 (5 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: ATI Radeon Family
Company Name: Advanced Micro Devices, Inc.
MD5: 7db538ce17bebb51c0182adcc264c63a
Size: 62 MB
First Published: 2021-01-12 16:17:44 (5 years ago)
Latest Published: 2021-01-12 16:17:44 (5 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2021-01-12 16:17:44 (5 years ago)

The signature on atikmdag.sys is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%localappdata%\slimware utilities inc\slimdrivers\backups\20200430t181054726041\pci

ThreatInfo has observed atikmdag.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for atikmdag.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

atikmdag.sys is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Native
Entry point 0x000075a0
Image base 0x0000000140000000

PE Sections:

Sections 48
Raw data 65719808

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 3735552 bytes · 5.7% of section data
MD5 3f6e883e00d7d32bbcdf1eb251f81910
.rdata 3691520 bytes · 5.6% of section data
MD5 77ad57af9c13a408c87dd83d609a353c
.data 9988096 bytes · 15.2% of section data
Large raw data
MD5 23f94782fb1f120fbc8633b716b7870d
.pdata 635904 bytes · 1.0% of section data
MD5 d6178968909a97698ffc10fa5f53aff7
PAGE_COM 612864 bytes · 0.9% of section data
Uncommon name
MD5 5256756fafe08c6486288fa8e1cf2dcf
PAGE 2048 bytes · 0.0% of section data
Uncommon name
MD5 f14e49ec441ee4913f67274625bb9bd7
PAGECALC 365568 bytes · 0.6% of section data
Uncommon name
MD5 5e53833ebeba59b6e667b96500859ba9
PAGE_DAL 77312 bytes · 0.1% of section data
Uncommon name
MD5 085f2801876a58317705c95d53ed89ba
PAGEPPLC 1516544 bytes · 2.3% of section data
Uncommon name
MD5 b6ea8fcede3827e30c4e5633377fe942
PAGE_PPL 28160 bytes · 0.0% of section data
Uncommon name
MD5 6ec28663fe954edaf1f8bfcabae1580b
PAGE_CPC 215040 bytes · 0.3% of section data
Uncommon name
MD5 8119f592a988274af7080da115b186ad
PAGE_DRM 7680 bytes · 0.0% of section data
Uncommon name
MD5 899b13e4e46f3a41391639c5f9ecb45e
PAGE_HDC 9728 bytes · 0.0% of section data
Uncommon name
MD5 587fd72fd03b2da26493f2a43893f96f
PAGE_OPM 4096 bytes · 0.0% of section data
Uncommon name
MD5 8079631f80beda51bec7a46900fed373
PAGE_WSC 2560 bytes · 0.0% of section data
Uncommon name
MD5 4cd49c57d1c072a36fb69548cdc72bd2
PAGE_PRE 2560 bytes · 0.0% of section data
Uncommon name
MD5 794b42d1af1dcca5e8ccc9a1018f9626
PAGESIPC 577536 bytes · 0.9% of section data
Uncommon name
MD5 daa40ab330d96d548ead4d84d7d573b8
PAGED2PC 4840960 bytes · 7.4% of section data
Uncommon name
MD5 68dc48b7ad1b36b62e2d3f634ce2dd33
PAGEDSIC 52224 bytes · 0.1% of section data
Uncommon name
MD5 cadafe465aea43b7b89731900b6126e3
PAGED3PC 952832 bytes · 1.4% of section data
Uncommon name
MD5 cdb6bd8ec43084e0331fcd44679a239e
PAGED2IC 370688 bytes · 0.6% of section data
Uncommon name
MD5 904c712d3e952de8070359c2ceebfd1f
PAGED3IC 145408 bytes · 0.2% of section data
Uncommon name
MD5 a56c47cdd1ac249f2af4ac789adfc424
PAGEDCIC 2642944 bytes · 4.0% of section data
Uncommon name
MD5 0514bf962610d0ec0ad3c164dd4c763c
PAGECALD 6638592 bytes · 10.1% of section data
Large raw data Uncommon name
MD5 d680fcfb58c07a63e6f1672e641ca634
PAGEIRQD 570880 bytes · 0.9% of section data
Uncommon name
MD5 b311b81653b5d48b34da57dd3a80e0c6
PAGE_RW 573952 bytes · 0.9% of section data
Uncommon name
MD5 9a8a5ea5d6f0f54c5a99e8bb44c3386c
PAGE_RO 14848 bytes · 0.0% of section data
Uncommon name
MD5 1c93d70a3aecfffc2baddd5fc346cb73
PAGEPPLD 3738624 bytes · 5.7% of section data
Uncommon name
MD5 c9d2dfeda8da34198145149cf7430ac4
PAGE_CPR 56320 bytes · 0.1% of section data
Uncommon name
MD5 41f3d3bd0271a14d7af0db6f1718b5e8
PAGE_DRM 512 bytes · 0.0% of section data
Uncommon name
MD5 27f0a429271ba1b421d608bc7bd858ac
PAGE_WSD 1024 bytes · 0.0% of section data
Uncommon name
MD5 6f308816c68554966057f150d32b22d2
PAGE_WSR 512 bytes · 0.0% of section data
Uncommon name
MD5 21bca2e9f1eb15b0bd5f6c2b67237d33
PAGESIPD 21896704 bytes · 33.3% of section data
Large raw data Uncommon name
MD5 2396e4a450f315aa5134b6d1eee38578
PAGEDSIR 14848 bytes · 0.0% of section data
Uncommon name
MD5 80bfb0a36edfb977fa0f946577bf23d5
PAGED2PR 339456 bytes · 0.5% of section data
Uncommon name
MD5 1f108cb8092602501d5b8cdfefc02406
PAGED2PD 233472 bytes · 0.4% of section data
Uncommon name
MD5 9564427a7f7f8ca9d5e0cef820e49dde
PAGEDSID 3584 bytes · 0.0% of section data
Uncommon name
MD5 e23a6e580df5aa4a6cdbbfdfe20d6c3b
PAGED3IR 10752 bytes · 0.0% of section data
Uncommon name
MD5 e597ca1b4f28019348765da0653f0d78
PAGED2IR 26624 bytes · 0.0% of section data
Uncommon name
MD5 9a818287da248b8919f2b437d20d2f60
PAGED3PR 102912 bytes · 0.2% of section data
Uncommon name
MD5 1f721b5e8d805bbcdae4bfa0322840cd
PAGED3PD 115200 bytes · 0.2% of section data
Uncommon name
MD5 ae4894abb25212c47af52b76bcea9286
PAGED2ID 1024 bytes · 0.0% of section data
Uncommon name
MD5 73cf89b7fc968475bf5d44a59bc7a879
PAGEDCIR 583680 bytes · 0.9% of section data
Uncommon name
MD5 312dbee60a0986f9a90235111d7cb845
PAGEDCID 22528 bytes · 0.0% of section data
Uncommon name
MD5 a764411beac4176fee6b9b8aeff210b7
PAGED3ID 37888 bytes · 0.1% of section data
Uncommon name
MD5 78097bbaf1f201bf634d5d8e1ece2d68
INIT 7168 bytes · 0.0% of section data
Uncommon name
MD5 511031bd53ce6a7642525798c670cb1a
.rsrc 34816 bytes · 0.1% of section data
MD5 73c2f89cdd91350c33df4a0a34e0847b
.reloc 216064 bytes · 0.3% of section data
MD5 0fb7c8ecaea8c591facf519adb0e776e

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

This file is still under review

ThreatInfo has not assigned a final verdict yet. Compare the file hash, location, signature, and publisher before trusting the file on a production system.

Scan with GridinSoft Anti-Malware Use a local scan if the file origin or behavior is unclear. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with 7db538ce17bebb51c0182adcc264c63a.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan if the source, path, or behavior looks unusual.