Threat Database Trojans Trojan.Downloader.Agent.BTAS

Trojan.Downloader.Agent.BTAS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 6,540
Threat Level: 80 % (High)
Infected Computers: 102
First Seen: June 21, 2025
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Agent.BTAS on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security of your computer, allowing unauthorized access to your personal data and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Downloader.Agent.BTAS?

Trojan.Downloader.Agent.BTAS is a type of Trojan horse malware that can download and install additional malicious software on your computer without your knowledge or consent. The name itself suggests that it is a downloader-type Trojan, which means it is designed to connect to remote servers and download other malware components. This type of malware can be particularly dangerous, as it can lead to a wide range of malicious activities, including data theft, ransomware attacks, and spyware infections.

How Trojan.Downloader.Agent.BTAS Operates

Trojan.Downloader.Agent.BTAS typically operates by exploiting vulnerabilities in your system or tricking you into installing it. Once installed, it can connect to remote command and control servers to receive instructions and download additional malware components. This malware can also modify system settings, create new files and folders, and disable security software to evade detection. Its primary goal is to establish a persistent presence on your system, allowing attackers to gain unauthorized access to your data and use your computer for malicious purposes.

Symptoms of Infection

Identifying the symptoms of a Trojan.Downloader.Agent.BTAS infection can be challenging, as it is designed to operate stealthily. However, you may notice some unusual activity on your computer, such as slow performance, unexpected pop-ups, or unfamiliar programs running in the background. You may also experience issues with your internet connection, such as slow browsing or frequent disconnections. Additionally, you may notice that your antivirus software is disabled or that your system settings have been modified without your consent.

How to Remove Trojan.Downloader.Agent.BTAS

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all instances of the malware have been removed.

Conclusion

Removing Trojan.Downloader.Agent.BTAS from your system requires careful attention to detail and a thorough understanding of the malware's operating characteristics. By following the steps outlined above, you can help ensure that your system is free from this malicious software and that your personal data is protected. It is essential to remain vigilant and to regularly scan your system for malware to prevent future infections. Additionally, keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads and email attachments can help prevent similar threats in the future.

Analysis Report

General information

Family Name: Trojan.Downloader.Agent.BTAS
Signature status: No Signature

Known Samples

MD5: 8c5f4ac12adaa99fee1db56d98e63ec5
SHA1: 0d78975787a0be4b5e4aeab9a9254b546430fbf4
SHA256: AAC065C439687864E90B77171887F17257B41D1B7D5E34AD798588CE175BEAAA
File Size: 2.20 MB, 2204160 bytes
MD5: f15a0f9cf95377a5e5a9bd8252c3e950
SHA1: 8523e02286ba6d300611bfb10932eaa7e9932cc5
SHA256: 718F0431AF0B0247B7FEC0594CC594A9003BA16BA7D35D4A2E3F91FCEFF079A7
File Size: 817.15 KB, 817152 bytes
MD5: 78d6bd857ba25260cee9081d5a783dc3
SHA1: 0ed7181c7dce0d7acc22c0d04d9f8494fa975b1f
SHA256: 663FE1EF10EEDAFD1B09947267B3FA40DBB9D69CC04B3BAE9391F544C8ADC9C0
File Size: 816.64 KB, 816640 bytes
MD5: 1f2ec767494ddc8e74be4c732bb58463
SHA1: c73c3fa4c1d0ac9bf7b8b98f9bdc4eeb1a6aeaab
SHA256: 6E0C18D535AC05C5D3B8EB5B78245EDB2AB52565C24AFF6E19EFB14915E4B47C
File Size: 817.15 KB, 817152 bytes
MD5: 48a33bd6252d24ad0a13f119408c8fe5
SHA1: 92244fdb98d9b2b180125195ad56b0e328f7ecb2
SHA256: 4F3E4796BC8D5F877237A851B83EA1B7A6B2B2F569D2553A5B2081D18A8A79BB
File Size: 1.92 MB, 1924608 bytes
Show More
MD5: fd87f904e6427c6209b1bff4e5007454
SHA1: 1fd1917b6fe3af7ae9498bb53d6c516b381ca3c0
SHA256: 1D100E7EA07A74CDBC2D82DDA8F2AA99AD6B685E4F043D0A296D3139A05E8790
File Size: 816.64 KB, 816640 bytes
MD5: ffa4f036f8b7099767ee297f32ad861a
SHA1: e57cd1faf345b1eb8a27bea6350bdd9dd0c4487c
SHA256: FE0A5E50A97CD80151832E87E2C96293083733A248824FB404C5D406BFB1BDBD
File Size: 3.05 MB, 3053056 bytes
MD5: a30cb2580ac963869cf7f3eba8891c53
SHA1: 9fe2bc7216b5936896b08347ea82104eccf53de7
SHA256: CFD8395461E6EF978769D8003CC0122E97A789F4D5C838ED9B85B7DF4AA65076
File Size: 4.41 MB, 4405760 bytes
MD5: a8b09e94e12bed5e6bada7d3adb8f118
SHA1: 36460e36cd100291791247a40942c0e38ed2ede3
SHA256: 69357F942FB4FA5AD4B5CED7D366732885FFF3472C262968C41078E03FED440F
File Size: 5.57 MB, 5572096 bytes
MD5: 2b8a97e9e668c2039c033bcf7a1f6a67
SHA1: 50aba2db945586e6840e57ef221151cc33301ca6
SHA256: 026F6E4E09F21318521A02147A66A08C33667C9D2CF1027E233B4ACFB2A64B6A
File Size: 817.15 KB, 817152 bytes
MD5: 0287c57e7e25f6fedc59819435f129b6
SHA1: 1af25eb76107cc7c1d9c773bc30d520f87322fd1
SHA256: 3405C2FBBB450C132593E00D85E44C8C73D6149F6AD8C6359A7D57F6C2D5990D
File Size: 5.55 MB, 5550080 bytes
MD5: feadfe40423a0214d0ebf6e6300073b2
SHA1: 141a910e9752fbcd557a072b0c2080b58d07f56f
SHA256: 96FFF3498B6DBFB502B1EA511398611084311AEAC4883C0C719C0D3E307B2B02
File Size: 7.37 MB, 7369728 bytes
MD5: bf0858c836ccbf93ed188baca013e8e3
SHA1: 71d262d616610c79d143100ab81d9d6bf471f7b1
SHA256: F4A290ADACE544C83AFC40D547A012A933E8C1DD61EE7CDB6641A787F31DDAE0
File Size: 4.43 MB, 4431360 bytes
MD5: 34a437cee83e4e341f2167484e6d22cc
SHA1: 29826364abed355dddc27ef6a2183769fa58ec77
SHA256: 575896B489E56ECECBEFF95FC30683F8392E9BB08F2804185039A86178B1A072
File Size: 816.64 KB, 816640 bytes
MD5: 2ac7fe8a226eaefdb6f65b2a5359a957
SHA1: f70d4dfd67bc831a526394f65596cf3b5d1fee31
SHA256: 7A3FD8A5B636A71F3EA819C1E110EFDB13E8B0CC93D3A8E99A36A1B5DFBB00A3
File Size: 8.93 MB, 8931840 bytes
MD5: 3bdc45ebdd8c352aeb858fd115c28b7b
SHA1: 42f687008ca6a1aecd4b825f94bccf846f5ea143
SHA256: 1466AEA16AB7C5FAEAD93096B74AE56C62547AAB7AE96DC2401E3C71ACB695A4
File Size: 873.47 KB, 873472 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 32.0.0.0
  • 10.0.26100.1
  • 1.0.0.0
Comments
  • DOT EXE PREMIUM OB51
  • Provides background audio processing for Windows applications
Company Name
  • Client
  • DOT CORPORATION
  • Microsoft Corporation
  • ReviOS 10 24.12
File Description
  • Client
  • COSMOS ON TOP BABY!
  • Dllinjector
  • DOT EXE PREMIUM OB51
  • SantaxCheat
  • SpaceX Bypass
  • Sync Store Free 2.0
  • Windows Background Audio Service
  • XXX
File Version
  • 32.0.0.0
  • 1.0.0.0
Internal Name
  • backgroundAudio.exe
  • benx.exe
  • BruceExternal.dll
  • Client.dll
  • CYBER DZ CHEAT.exe
  • Dllinjector.exe
  • SantaxCheat.exe
  • Sync Store Free 2.0.exe
  • XXX.exe
Legal Copyright
  • Copyright © 2024
  • Copyright © 2025
  • Copyright © 2025 BY MR. ABIR
  • Copyright © 2026
  • Copyright © BY F4X NAFIS !!
  • Copyright © Microsoft Corporation. All rights reserved.
  • Copyright © ReviOS 10 24.12 2025
Legal Trademarks DOT CORPORATION
Original Filename
  • backgroundAudio.exe
  • benx.exe
  • BruceExternal.dll
  • Client.dll
  • CYBER DZ CHEAT.exe
  • Dllinjector.exe
  • SantaxCheat.exe
  • Sync Store Free 2.0.exe
  • XXX.exe
Product Name
  • Client
  • COSMOS ON TOP BABY!
  • Dllinjector
  • DOT EXE PREMIUM OB51
  • Microsoft® Windows® Operating System
  • SantaxCheat
  • SpaceX Bypass
  • Sync Store Free 2.0
  • XXX
Product Version
  • 32.0.0.0
  • 1.0.0.0
  • 1.0.0

File Traits

  • dll
  • imgui
  • x64

Block Information

Total Blocks: 84
Potentially Malicious Blocks: 46
Whitelisted Blocks: 30
Unknown Blocks: 8

Visual Map

0 x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? x 0 0 0 0 x x 0 ? 0 0 0 0 0 0 x x x x x x x x x x x x x x ? ? x 0 x 0 x ? ? x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Downloader.Agent.BTAS
  • Gamehack.GAGE

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe f�zo�� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
Show More
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady

3 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Trending

Most Viewed

Loading...