Jump to content

Potential False Positive madbasic_.bpl Files


Eli343

Recommended Posts

Hello. Recently I installed Malwarebytes and ran a scan that quarantined several files and which may have included two false positives, which are two same-name files in different locations, both labeled “Trojan.Loader” in the quarantined items list (both listings are attached). The file name is “madbasic_.bpl”. Since the scan, I now get an error message pertaining to those two files on startup, which I have attached, that goes away after 4 clicks on the X or ‘OK’. Through research I haven’t been able to determine whether the files are safe or not, which has brought me here. My question is, is it safe to remove both madbasic_.bpl files from quarantine?

Screenshot 2024-06-28 170547.png

Screenshot 2024-06-28 170749.png

Screenshot 2024-06-28 154253.png

Link to post
Share on other sites

  • Staff

Hi,

This is a valid detection, toghether with the other detections in the log. The C:\USERS\OWNER\APPDATA\ROAMING\OIVKSDUB\PRESENTATIONHOST.EXE detection in your log is related, which is a Remote Desktop Client (Netsupport) where the attacker can perform additional tasks such as installing more malware, collecting passwords etc etc...

Link to post
Share on other sites

  • Staff
Posted (edited)

It looks like it's launched by DPMHelper.exe, which might be legit, but it tries to load the malicious dll (sideloaded). Can you check if this DPMHelper.exe is present in the C:\Users\Owner\Appdata\Roaming\Fmmon_test_v3 folder and zip and attach that file here as well? 

Then please follow the instructions posted by Porthos in above.

Edited by miekiemoes
Link to post
Share on other sites

I couldn’t find Appdata under Owner for some reason but after searching I found that DPMHelper.exe is in the Fmmon_test_v3 folder. I had trouble but I believe I zipped correctly (I couldn't zip the folder for some reason so I zipped the files in it and it was automatically named DPMHelper.zip).

As a side note, in case it's helpful, all of the files were created the day malware was installed.

DPMHelper.zip

Link to post
Share on other sites

  • Staff

As expected, that file is not malicious. This one does need the madbasic_.bpl file to run, but in your case, it was replaced with an adjusted/malicious madbasic_.bpl. 

You can actually delete the Fmmon_test_v3 folder. (https://support.microsoft.com/en-us/windows/view-hidden-files-and-folders-in-windows-97fbc472-c603-9d90-91d0-1166d1d9f4b5#WindowsVersion=Windows_11)

In case you can't remove that folder, check your running processes and rightclick the DPMHelper.exe file in order to kill that running process. Then you should be able to delete that file. If you need additional help, please follow the instructions by Porthos posted earlier in order to clean up any remaining traces if still present.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.