GridinSoft Threat Intelligence

atikmdag.sys file report

Under review File reputation report
MD5 a803e2a6494cb9186e8b51a971e6f254
Latest seen 2022-09-30 23:17:43 (3 years ago)
First seen 2017-11-20 09:07:39 (8 years ago)
Size 18 MB

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2017-11-20 09:07:39 (8 years ago); latest analysis 2022-09-30 23:17:43 (3 years ago).

Publisher context

Company metadata: Advanced Micro Devices, Inc.. Product metadata: ATI Radeon Family.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

atikmdag.sys is a Windows file recorded in the ThreatInfo database. It is associated with ATI Radeon Family. The reported company name is Advanced Micro Devices, Inc.. The current detection status is Undefined, based on the latest analysis from 2022-09-30 23:17:43 (3 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: ATI Radeon Family
Company Name: Advanced Micro Devices, Inc.
MD5: a803e2a6494cb9186e8b51a971e6f254
Size: 18 MB
First Published: 2017-11-20 09:07:39 (8 years ago)
Latest Published: 2022-09-30 23:17:43 (3 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2022-09-30 23:17:43 (3 years ago)
%system%\drivers
%localappdata%\slimware utilities inc\slimdrivers\backups\20170501t002912363268\pci\ven_1002&dev_6760
%system%

ThreatInfo has observed atikmdag.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 7 100.0%

The most common operating system signal for atikmdag.sys is Windows 7 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

atikmdag.sys is identified as pe for 32-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 32-bit
Subsystem Native
Entry point 0x0002c4e3
Image base 0x00010000

PE Sections:

Sections 53
Raw data 19578368

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 1611776 bytes · 8.2% of section data
MD5 f11ab08d6827b169a94b8ccf38133b4f
_wtext 2048 bytes · 0.0% of section data
Uncommon name
MD5 0a109570d06a90d3db81cb9e0de80c50
.rdata 1137664 bytes · 5.8% of section data
MD5 43c2522d3c4cf6c28cace3bd052a1db5
.data 6296064 bytes · 32.2% of section data
Large raw data
MD5 8a51536179cc4ec6ad1190151b72ee46
PAGE_COM 363008 bytes · 1.9% of section data
Uncommon name
MD5 495f898365715f5eac98f0db6caaa958
PAGE 6656 bytes · 0.0% of section data
Uncommon name
MD5 5379844f73be0825498445b73b4837b5
PAGE_CAI 228864 bytes · 1.2% of section data
Uncommon name
MD5 75b0e75b011ed8948d44b35b2eeef923
PAGE_DAL 1623552 bytes · 8.3% of section data
Uncommon name
MD5 4423ab736c37827b05ab2208f952db56
PAGE_ISR 16896 bytes · 0.1% of section data
Uncommon name
MD5 4c231076175da798833521306b5ea3d2
PAGEDC40 1024 bytes · 0.0% of section data
Uncommon name
MD5 df095028310afca28307cc5546bd667f
PAGEDC50 1024 bytes · 0.0% of section data
Uncommon name
MD5 48c43a1fea218c25c2ae0072638fc1e2
PAGEDC60 1536 bytes · 0.0% of section data
Uncommon name
MD5 507e3a98f88cb52f471f2cb3000a13d2
PAGEDC80 24064 bytes · 0.1% of section data
Uncommon name
MD5 b54f5c8ed4dea8bb34aef72227716388
PAGEDC10 13312 bytes · 0.1% of section data
Uncommon name
MD5 5953e8ce9cb77368c10e643ea88718dc
PAGEDC11 39936 bytes · 0.2% of section data
Uncommon name
MD5 14669688fa596abe460403b07a7f796a
PAGEDC11 23040 bytes · 0.1% of section data
Uncommon name
MD5 fc234a3b2306a64655bc1d3b16a3aa6a
PAGE_PPL 644096 bytes · 3.3% of section data
Uncommon name
MD5 bf6deedf1c36efeb9145d7e9d6105aea
PAGE_CPC 139776 bytes · 0.7% of section data
Uncommon name
MD5 24fe1cb7b333e18d848e8954242b7769
PAGE_CAI 1965056 bytes · 10.0% of section data
Uncommon name
MD5 1b6020de3a69a75bf88331caed25a5d2
PAGE 3933184 bytes · 20.1% of section data
Uncommon name
MD5 f72d4e96166fbedbd738aaadb3e24a5e
PAGE_IEG 27136 bytes · 0.1% of section data
Uncommon name
MD5 4d5ae59ead7e8c8a007b23f3366aa9ab
PAGE_ILN 14336 bytes · 0.1% of section data
Uncommon name
MD5 98c37149dd26ce1a5c013162ace85b87
PAGE_IBT 24576 bytes · 0.1% of section data
Uncommon name
MD5 bef59e81952f73b31d1a6143165efa89
PAGE_INI 26112 bytes · 0.1% of section data
Uncommon name
MD5 08675bc63854864f4b783006fb758a2c
PAGE_ITN 18944 bytes · 0.1% of section data
Uncommon name
MD5 286b4aebce2eb49af54f8981c8ceeea3
PAGE_ISI 26624 bytes · 0.1% of section data
Uncommon name
MD5 9876ef929134952e513b8c11747284a3
PAGE_ICI 29696 bytes · 0.2% of section data
Uncommon name
MD5 1036a1169285a70bfd1004e214fb8519
PAGE_IKV 27648 bytes · 0.1% of section data
Uncommon name
MD5 7ca4a91588d888f64ac23845799ea5d3
PAGE_IIL 12800 bytes · 0.1% of section data
Uncommon name
MD5 f816b3b2afa7e0a9c87beae0bf62c4df
PAGE_IVI 32256 bytes · 0.2% of section data
Uncommon name
MD5 e61f51dae155e2751e1f0a67ede1667a
PAGE_ICZ 31232 bytes · 0.2% of section data
Uncommon name
MD5 8137dac009c7ba812df65892c9b6404e
PAGE_RO 243200 bytes · 1.2% of section data
Uncommon name
MD5 8a4c0e80d26b417660e05f13f4ec3298
PAGE_RW 704512 bytes · 3.6% of section data
Uncommon name
MD5 751179bd64cb92e02b6d6e6cf673766f
PAGE_ISR 512 bytes · 0.0% of section data
Uncommon name
MD5 0e7b26f9d8202a11c88f5a3bdf6757af
PAGE_ISR 7168 bytes · 0.0% of section data
Uncommon name
MD5 e62dfd5bd634328c915ee68f32615ecc
PAGEDC40 512 bytes · 0.0% of section data
Uncommon name
MD5 9c99e2d47f7553bf8e3bb0747ef80f0d
PAGEDC40 512 bytes · 0.0% of section data
Uncommon name
MD5 c3950c8a13f13684b4028e4ffc495c05
PAGEDC50 512 bytes · 0.0% of section data
Uncommon name
MD5 fa93d77815bb6ddcc1603b1deeb3feb0
PAGEDC50 512 bytes · 0.0% of section data
Uncommon name
MD5 40985b2fdd7cfa1c55c5299ac3659ac8
PAGEDC60 512 bytes · 0.0% of section data
Uncommon name
MD5 17d83d4a3c5e8f3cbcbca112fc54096b
PAGEDC60 512 bytes · 0.0% of section data
Uncommon name
MD5 79e2e8d87992a79a7a9df17224a9f7cf
PAGEDC80 512 bytes · 0.0% of section data
Uncommon name
MD5 532c8d400ec7c2279f26a6e3de3890fd
PAGEDC80 1536 bytes · 0.0% of section data
Uncommon name
MD5 fea2c39c246f6a210f88e04d5710642e
PAGEDC10 512 bytes · 0.0% of section data
Uncommon name
MD5 0503c91db57b976df6115e47850a4433
PAGEDC10 512 bytes · 0.0% of section data
Uncommon name
MD5 3b80fb62bf1f24615c500086f45a1a02
PAGEDC11 512 bytes · 0.0% of section data
Uncommon name
MD5 c337887b797ee9e37617bd22a88922f8
PAGEDC11 6144 bytes · 0.0% of section data
Uncommon name
MD5 5d147b8d83e089abcd1d5171bf483cb3
PAGEDC11 512 bytes · 0.0% of section data
Uncommon name
MD5 ad8e7a3606aefa4a2dfc7aaad5529100
PAGEDC11 1024 bytes · 0.0% of section data
Uncommon name
MD5 13f47e2c472cfc89bcacb32d1c2764a5
PAGE_CPR 31744 bytes · 0.2% of section data
Uncommon name
MD5 905dae6b6b9c701883cbc4658cf32d5c
INIT 6144 bytes · 0.0% of section data
Uncommon name
MD5 bcddd77bb9de9da3b0bc66715d32bc23
.rsrc 2560 bytes · 0.0% of section data
MD5 fa6d4d4a22ee08dacc064959c46223d8
.reloc 224256 bytes · 1.1% of section data
MD5 62937a1c419d1d4dbee5eabe95cb55c5

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

This file is still under review

ThreatInfo has not assigned a final verdict yet. Compare the file hash, location, signature, and publisher before trusting the file on a production system.

Scan with GridinSoft Anti-Malware Use a local scan if the file origin or behavior is unclear. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with a803e2a6494cb9186e8b51a971e6f254.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan if the source, path, or behavior looks unusual.