GridinSoft Threat Intelligence

atikmdag.sys threat report

Detected as Trojan.Generic File reputation report
MD5 dd3067ab95a04cbb9f4ef24d88c06d8f
Latest seen 2023-04-27 23:26:45 (3 years ago)
First seen 2023-04-27 23:26:45 (3 years ago)
Size 23 MB

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2023-04-27 23:26:45 (3 years ago)
File hash
dd3067ab95a04cbb9f4ef24d88c06d8f
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic.

Timeline

First seen 2023-04-27 23:26:45 (3 years ago); latest analysis 2023-04-27 23:26:45 (3 years ago).

Publisher context

Company metadata: Advanced Micro Devices, Inc.. Product metadata: ATI Radeon Family.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

atikmdag.sys is a Windows file recorded in the ThreatInfo database. It is associated with ATI Radeon Family. The reported company name is Advanced Micro Devices, Inc.. The current detection status is Trojan.Generic, based on the latest analysis from 2023-04-27 23:26:45 (3 years ago).

If atikmdag.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

Product Name: ATI Radeon Family
Company Name: Advanced Micro Devices, Inc.
MD5: dd3067ab95a04cbb9f4ef24d88c06d8f
Size: 23 MB
First Published: 2023-04-27 23:26:45 (3 years ago)
Latest Published: 2023-04-27 23:26:45 (3 years ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2023-04-27 23:26:45 (3 years ago)
atikmdag.sys detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%system%

ThreatInfo has observed atikmdag.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for atikmdag.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

atikmdag.sys is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Native
Entry point 0x00002120
Image base 0x0000000000010000

PE Sections:

Sections 62
Raw data 24378880

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 2223616 bytes · 9.1% of section data
MD5 959f56975475568a2c6d41a1cb117958
_wtext 512 bytes · 0.0% of section data
Uncommon name
MD5 5174a6b85cc2b1b9f9b19521d16eaa61
.rdata 1448960 bytes · 5.9% of section data
MD5 8ae9181643f6e03eacd729bdcd7780d3
.data 6987264 bytes · 28.7% of section data
Large raw data
MD5 2bf31b30da94bd4d5a06d91d368146d5
.pdata 364032 bytes · 1.5% of section data
MD5 1050af71bd842d79d727564d4c5f02c9
.gfids 512 bytes · 0.0% of section data
Uncommon name
MD5 1aa8837c179b2965e631b1f18d8fe11c
PAGE_COM 510464 bytes · 2.1% of section data
Uncommon name
MD5 18560f59da8a3cc352b3ea45aa830375
PAGE 8192 bytes · 0.0% of section data
Uncommon name
MD5 c49cd0cb0b3af820a616675e7ebec3d3
PAGE_CAI 302080 bytes · 1.2% of section data
Uncommon name
MD5 d05029f1621873288ffa36724ecc6137
PAGE_DAL 2144256 bytes · 8.8% of section data
Uncommon name
MD5 b0448eeac1954ae490ddc3022f0e93f7
PAGE_ISR 31232 bytes · 0.1% of section data
Uncommon name
MD5 57ab9f7d84bcfa9971915602f15b7012
PAGEDC40 1024 bytes · 0.0% of section data
Uncommon name
MD5 2bb4bc57e8903d12228c0e5f62e2a88b
PAGEDC41 1536 bytes · 0.0% of section data
Uncommon name
MD5 dafa607e3c8dbeec951c976bb779ccab
PAGEDC50 1024 bytes · 0.0% of section data
Uncommon name
MD5 d727eb3d09ca63aa03830a809fd0c416
PAGEDC60 1536 bytes · 0.0% of section data
Uncommon name
MD5 4b16b6fe2cd5844c955b4f5210ee4881
PAGEDC80 28672 bytes · 0.1% of section data
Uncommon name
MD5 5811c04527028dce9548dabc67aabd90
PAGEDC10 16384 bytes · 0.1% of section data
Uncommon name
MD5 852cac477a469b7aaab9de3a09884e29
PAGEDC11 47104 bytes · 0.2% of section data
Uncommon name
MD5 d2129001c7a42245174a8a84feb1cc16
PAGEDC11 11264 bytes · 0.0% of section data
Uncommon name
MD5 9094cd050720fcba829413e61e9c672f
PAGEDC12 16384 bytes · 0.1% of section data
Uncommon name
MD5 5a8d0e7b95cbb942e0f1f08771fe3b52
PAGE_PPL 862720 bytes · 3.5% of section data
Uncommon name
MD5 fe4d89a08b23b5e8d38d766c7a4ac826
PAGE_CPC 182784 bytes · 0.7% of section data
Uncommon name
MD5 7ef18160d5847144eee9138cc2ec1e0b
PAGE_CAI 2636800 bytes · 10.8% of section data
Uncommon name
MD5 7c2fe0608260501e30299452ba42ec35
PAGE 4197376 bytes · 17.2% of section data
Uncommon name
MD5 b05a0f13fe80c58ac9ab08c8308ecc21
PAGE_IEG 44032 bytes · 0.2% of section data
Uncommon name
MD5 53f7124e814a3b948f4f7781df15e19a
PAGE_ILN 23040 bytes · 0.1% of section data
Uncommon name
MD5 86d5f8b3882bd030a943c1fbff914397
PAGE_IBT 39936 bytes · 0.2% of section data
Uncommon name
MD5 ae3930cf6142bccba98299875d34996c
PAGE_INI 43008 bytes · 0.2% of section data
Uncommon name
MD5 7faa10fe9600d09e09fac31ddc19e2ef
PAGE_ITN 30720 bytes · 0.1% of section data
Uncommon name
MD5 12ab294dafb7ec729e10fbaff5d80102
PAGE_ISI 43008 bytes · 0.2% of section data
Uncommon name
MD5 10ca863e553f32146a299c4c26a0ae93
PAGE_ICI 48640 bytes · 0.2% of section data
Uncommon name
MD5 c2f60f64edce5eda69409910c1ec2921
PAGE_IKV 45568 bytes · 0.2% of section data
Uncommon name
MD5 138cba6b26e2c6e261aee9d101ca2723
PAGE_IIL 20992 bytes · 0.1% of section data
Uncommon name
MD5 7828c8a4274d5767f7df5245c3452b72
PAGE_IVI 52736 bytes · 0.2% of section data
Uncommon name
MD5 c8ef42210f23b95199f2a162abafd7b3
PAGE_ICZ 51200 bytes · 0.2% of section data
Uncommon name
MD5 1ed17244818707cd9f95574bbe75e525
PAGE_IGN 11264 bytes · 0.0% of section data
Uncommon name
MD5 3b7eb7ccf94cdbd1329cc0fed065429a
PAGE_RO 360960 bytes · 1.5% of section data
Uncommon name
MD5 74ecc28a556c047bf9e949cf92aa094a
PAGE_ISR 16384 bytes · 0.1% of section data
Uncommon name
MD5 354ed917453caa7bde75f97304b516c8
PAGE_RW 1111040 bytes · 4.6% of section data
Uncommon name
MD5 cbfa509a7aa406995ad28c6298a4e67c
PAGE_ISR 1024 bytes · 0.0% of section data
Uncommon name
MD5 3d783c13b0b1e99f2f5d033b518b75c1
PAGEDC11 512 bytes · 0.0% of section data
Uncommon name
MD5 a0fb7026084a600c39fde18b5f6f2ae5
PAGEDC40 512 bytes · 0.0% of section data
Uncommon name
MD5 568d674600d933f887fbdd342a71175a
PAGEDC10 512 bytes · 0.0% of section data
Uncommon name
MD5 ebb006492a4e43f4ab990f754d29f54d
PAGEDC41 512 bytes · 0.0% of section data
Uncommon name
MD5 93d84042238132533f99345d436fffad
PAGEDC12 1024 bytes · 0.0% of section data
Uncommon name
MD5 b63ef41c1dd0f14d32aed399e8004be5
PAGEDC50 512 bytes · 0.0% of section data
Uncommon name
MD5 647956372a0b42fbef67870e02744e6a
PAGEDC60 512 bytes · 0.0% of section data
Uncommon name
MD5 537f3440dd6ba6a6fc4d12790833daf7
PAGEDC11 8704 bytes · 0.0% of section data
Uncommon name
MD5 fb1a8c46906eb405b3d7573d4bd57ac8
PAGEDC80 2048 bytes · 0.0% of section data
Uncommon name
MD5 5538c04210bcdf1d4f91b3159f5e38ea
PAGEDC40 512 bytes · 0.0% of section data
Uncommon name
MD5 39261130f335ad18c58fa1d75383ea55
PAGEDC41 512 bytes · 0.0% of section data
Uncommon name
MD5 53e859ece39afa0c275b696d90008f49
PAGEDC50 512 bytes · 0.0% of section data
Uncommon name
MD5 3bf5c49365b2babb9c6bbd67bda8d29b
PAGEDC60 512 bytes · 0.0% of section data
Uncommon name
MD5 4c0a1b0294d56188efd74ca9bbc2ad63
PAGEDC80 512 bytes · 0.0% of section data
Uncommon name
MD5 acfe6d700f667a16ffa043564e347850
PAGEDC10 512 bytes · 0.0% of section data
Uncommon name
MD5 7e19f2d12345350b9a79502b6aed5804
PAGEDC11 512 bytes · 0.0% of section data
Uncommon name
MD5 8e8e036626a3db539c391904b84e952f
PAGEDC11 512 bytes · 0.0% of section data
Uncommon name
MD5 477647d7eeb6448d6a0877e7dde738e7
PAGEDC12 512 bytes · 0.0% of section data
Uncommon name
MD5 a260353adea2d0c7bd5d6d2be5ee5a3f
PAGE_CPR 35328 bytes · 0.1% of section data
Uncommon name
MD5 ac1ea2181523da2cde3fc7b48c2c4114
INIT 6656 bytes · 0.0% of section data
Uncommon name
MD5 133f1bebfdc6bb2ae800c06102ba53df
.rsrc 9216 bytes · 0.0% of section data
MD5 56d6c96c24a9cb5a2646100adb52b721
.reloc 338944 bytes · 1.4% of section data
MD5 25803efdf33ee3757f867fefc30e37f3

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Trojan.Generic

This report identifies atikmdag.sys by MD5 dd3067ab95a04cbb9f4ef24d88c06d8f. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with dd3067ab95a04cbb9f4ef24d88c06d8f.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found.