GridinSoft Threat Intelligence
atikmdag.sys threat report
GridinSoft Anti-Malware detection
Detected by GridinSoft before you download
The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.
- Detection name
- Trojan.Generic
- Recommended action
- Scan and remove
- Last analysis
- 2023-10-13 23:02:42 (2 years ago)
- File hash
- f35cc07ef4ec22014cdec45b4451a22b
Why it matters
Why GridinSoft flags this file
GridinSoft identifies the sample as Trojan.Generic.
First seen 2023-07-02 23:04:39 (2 years ago); latest analysis 2023-10-13 23:02:42 (2 years ago).
Company metadata: Advanced Micro Devices, Inc.. Product metadata: ATI Radeon Family.
ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.
Recommended action
What to do next
- Compare the MD5 above with the file found on the device.
- Check whether the file appears in the observed locations or under one of the alternate names.
- Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.
File context
atikmdag.sys is a Windows file recorded in the ThreatInfo database. It is associated with ATI Radeon Family. The reported company name is Advanced Micro Devices, Inc.. The current detection status is Trojan.Generic, based on the latest analysis from 2023-10-13 23:02:42 (2 years ago).
If atikmdag.sys appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.
File Details
| Product Name: | ATI Radeon Family |
| Company Name: | Advanced Micro Devices, Inc. |
| MD5: | f35cc07ef4ec22014cdec45b4451a22b |
| Size: | 19 MB |
| First Published: | 2023-07-02 23:04:39 (2 years ago) |
| Latest Published: | 2023-10-13 23:02:42 (2 years ago) |
| Status: | Trojan.Generic (on last analysis) | |
| Analysis Date: | 2023-10-13 23:02:42 (2 years ago) |
Detection screenshot
The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.
Common Places:
| %sysdrive%\sm850\windows.old.000\windows\system32\driverstore\filerepository\c7183844.inf_amd64_neutral_83df91b9c4e896c5 |
| %sysdrive%\windows.old.000\windows\system32\driverstore\filerepository\c7183844.inf_amd64_neutral_83df91b9c4e896c5 |
| %sysdrive%\sm850\windows.old\windows\system32\driverstore\filerepository\c7183844.inf_amd64_neutral_83df91b9c4e896c5 |
| %sysdrive%\windows.old.000\windows\system32 |
| %system%\driverstore\filerepository\c7183844.inf_amd64_neutral_83df91b9c4e896c5 |
| %sysdrive%\windows.old\windows\system32\driverstore\filerepository\c7183844.inf_amd64_neutral_83df91b9c4e896c5 |
| %sysdrive%\sm850\windows.old.000\windows\system32 |
| %sysdrive%\desktop\windows\system32\driverstore\filerepository\c7183844.inf_amd64_neutral_83df91b9c4e896c5 |
ThreatInfo has observed atikmdag.sys in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.
Geographic signal
Observed country distribution
ThreatInfo has seen atikmdag.sys across 1 countries. Use this signal to compare local evidence with where the sample is most often reported.
The strongest geographic signal for this file is United States with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.
OS Version:
The most common operating system signal for atikmdag.sys is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.
Analysis
atikmdag.sys is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.
PE Sections:
Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.
07d6516fa6e37bd2f1fb82151909957d
4a17a765c2138ca1e21da1c2a7e4cf50
e8d7a2a9625cab8c3194156d33ae2521
90ed3a1cf0fb4b03f372b2402c63ca23
527dd419efcea3221b9dfad65f3f49bb
35d518de1d79f86844e630d6d1523f3d
4e572f8ecd9b60add8adaaf201e3f049
00270293d76ccbb2903b0a4c7d6f4584
3ea55bb21b683f929fa7c8a5320e332f
633f2cbe3f1275894fa5ad63ef8edbc7
05bd2f3ab70f7e8fe64c6993cef33dd4
7ae3255c6989d1297cf745722bb3d15f
aa03086e1fcf12bd2a457ba7d97e1100
f22d8f766d44fcfe3f12f4dd5b9cf022
a7202368f7b7120450a4f824d5542920
b1c8bd553c4296309ebca3624cd2def8
84f44ccdc6357c6fdee49e606a5a48fd
298dd61a1a82b75f537964b7d6fd0b90
286de0c3216518d96041bc9a08b387d1
95be5059e7d144fc5057cbbc5ba597a8
32d65f1b53141bfa89c455aeea2c52de
21f071463d6d8fb00aab633de3fbf91e
3e7a588db225750f809420cad0d246e9
17a460c1f0862a1c6343210a4e5cb204
2a86e558b22c9a54ef85e01eb3f08e72
f25e0914097e52cdcac44339d06c8ffe
6d86b43e1c6dbd29f232434e42c014f5
0c822e73f50504d99fb06ddbf6ba10a2
512d361821b429079b072598f179dcba
96f6cd425f1694be4d2faa3f47f4607e
821c7b046e303118e94217afe5b277db
0b63b350295d0f818b63b0c00caa385b
9c02761a46db5d23f0d4fea223b70374
92dd4fbe26970a3a23ede8b7df082068
04d472a5f4fec969e7891268e6421b27
293e1b191310cee3f31060ce0ee79014
2a95c7c5c3a20288d17cc95e970d6c36
4dc68c7ed7f5ede0956a9cf0012949b8
bb8222a8fa11efc3f69ba75b5d74f679
c0e7a818d35dc7b647f76e4f7be48f80
eae5d83fcb372538c587eb700f3b457b
f4aea67688b698c1c7e76bd03cf79c81
222611777ae92221712f46b66243d356
146f5be0709dc3eed343a52436030517
8ff763cf05ba4365d077723c056d66b0
13093414f8da7c21e14a4fe79b8b599c
690a24b7162f0033be67625051f24f5f
30f225d035e92559642f72689be434f9
46bc18cd96c556167a8211adf011cab3
856408247d6aa44356674a84ea672082
68a929bf12852d444c805d52e25f8e2c
981392e47a59c9b18e630c9fe4a1344a
37b4eac56f16bc420598e870c68ce7cb
0a218b9fdf8db165c76cc33fbec925c6
a044f9c4f5bc4e5e842eb092e446cb93
PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.
Report conclusion
GridinSoft detects this file as Trojan.Generic
This report identifies atikmdag.sys by MD5 f35cc07ef4ec22014cdec45b4451a22b. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.