What Is A Pum

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mark59, Aug 18, 2023.

  1. mark59

    mark59 MajorGeek

    Malwarebytes wanted to run a scan on my PC* because it said there had been changes to my PC. I’m afraid I don’t recall the actual wording. I selected to run the scan.

    I ran the scan and it found two items it identifies at PUMs. I elected to quarantine them because I don’t know what risk they pose.

    I have saved the scan results and I attach them: PUMs.txt

    Can someone please (1) tell me what a PUM is; (2) what level of risk they pose; (3) read the scan report; (4) tell me if I did the right thing to quarantine them; (5) is there anything else I should now do?

    *PC: Acer Aspire XC-840 1.0; OS: Windows 11 Home (x64) Version 22H2
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to the MajorGeeks Malware Forum.

    PUM is an acronym for Potentially Unwanted Modification. Generally speaking it simply throws up a caution flag alerting you to take a look at it to see if you set it or are OK with it or if the modification was the result of malicious software.

    Though I suspect it is not malware related I would like for us to take a look at your computer system. Please do this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download Farbar Recover Scan Tool for 64 bit systems and save it to your Desktop. <<< Important
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
    • 2 Notepad documents should now be open on your desktop.
    • Please attach both reports to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

    • FRST.txt
    • Addition.txt
     
  3. mark59

    mark59 MajorGeek

    Thank you for helping me. I appreciate your time and effort.

    With respect to your first bullet point I could not download FRST64 to Desktop. I attempted to change where downloads go but counld not. Almost certainly my imcompetence and not any malware preventing me. Once FRST64 was downloaded to Downloads I cut and pasted it to my Desktop prior to following your other instructions. I hope this is acceptable.

    As per your final bullet point I attach both reports.

    Thank you!
     

    Attached Files:

  4. Oh My!

    Oh My! Malware Expert Staff Member

    You are quite welcome.

    Just wanted to touch base and apologize for the delay. I intend on posting something for you tomorrow morning (my current time is 7:00 PM).

    Thanks in advance for your understanding and patience.

    See you tomorrow.......
     
  5. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings, and thank you again for your patience.

    I am happy to report there is no evidence of malicious software on your computer. There is one program (Sweetlabs) that needs to be removed but it is junk more than anything else.

    Regarding these entries, these lines are merely reporting settings in Windows Defender. Basically this is telling us Windows Defender is not to contact Microsoft and give them information about infections on your system that Windows Defender has detected. Many people are a little uncomfortable allowing information sharing with Microsoft if it is a choice they have to allow or deny.

    Let me know if you have any questions.

    Let's clean up the little tidbits. Please do this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    C:\Users\markc\AppData\Local\Host App Service
    C:\Users\Jessica\AppData\Local\Host App Service
    S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X] 
    Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File) 
    Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File) 
    Task: {C13979EA-8B35-4037-BDB7-949872536D91} - System32\Tasks\App Explorer => C:\Users\markc\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7574560 2023-03-29] (SweetLabs Inc -> SweetLabs, Inc) <==== ATTENTION 
    AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [136] 
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • Fixlog
     
  6. mark59

    mark59 MajorGeek

    Thank you again, your help is greatly appreciated.

    I'm pleased to know there's no malware on my machine.

    I followed your instructions and I attach the Fixlog.
     

    Attached Files:

  7. Oh My!

    Oh My! Malware Expert Staff Member

    That report looks good.

    I think we are all set. Are there any remaining questions or concerns you might have before I post some tool/log clean up instructions and other information for you to consider going forward?
     
  8. mark59

    mark59 MajorGeek

    Thank you for all your help.

    No specific questions I can think of asking. I've a more general one. Why was it important that FRST was run from the Desktop?

    I look forward to your next post.

    Thanks!
     
  9. Oh My!

    Oh My! Malware Expert Staff Member

    You are welcome.

    It is not a requirement, FRST64 can be run from other locations as well. The reason I focus on the Desktop is because it is the most visible location and requesting everything be done from the Desktop avoids confusion or complications. Browsers can vary in the default download location so rather than trying to deal with the various locations it is cleaner to request all activity be done from the Desktop.

    Here is our final step and some additional information to consider.

    ===================================================

    KpRm by Kernel-panik

    --------------
    • Download KpRm and save it to your Desktop (see here if you must use Chrome)
    • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
    • Right click on the icon and select Run as administrator
    • Click Yes on the Disclaimer
    • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
    • Click Run
    • Click OK on All operations are completed
    • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
    • You are free to remove any other tools/reports still remaining
    ===================================================

    All Clean!

    --------------

    Your computer is now clean. Please consider this going forward.

    ===================================================

    Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean.

    Thank you for placing your trust in Major Geeks. It was a pleasure serving you.
     
    mark59 likes this.
  10. mark59

    mark59 MajorGeek

    Thank you!

    I have downloaded KpRm. I will run it later.

    I shall also be working through the links you've provided.

    Thank you so much for your help. I really appreciate it.
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    You are quite welcome, and welcome here anytime.

    Gary
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds