Windows Defender finds PUA:Win32/Keygen but can't remove it.

Page 1 of 2 12 LastLast

  1. Posts : 10
    windows 10
       #1

    Windows Defender finds PUA:Win32/Keygen but can't remove it.


    I recently turned App and Browser control on and Windows Defender found PUA:Win32/Keygen affecting C:\Users\********\AppData\Local\Apple Inc\CloudKit\iCloudDrive\MMCS\tmpm-0x0000000000008289

    But it cannot quarantine it or remove it.


    The file location does not seem to exist when I search for it.

    I have scanned with Malwarebytes, adwcleaner, HitmanPro, and Zemana after following advice online and none of them find PUA:Win32/Keygen.

    Do you think it is a false positive?

    Any advise on what further action I should take gratefully received.



    Windows 10 Pro Version 2004 Build 19041.388
      My Computer


  2. Posts : 1,862
    Windows 10 Pro 2004 20H1
       #2

    This issue goes back to at least 2018.

    AppData\Local\Apple Inc\CloudKit\iCloudDrive\MMCS\tmpm - Google Search

    If you can find the file, upload it to VirusTotal and scan it there.
      My Computer


  3. Posts : 10
    windows 10
    Thread Starter
       #3

    OldNavyGuy said:
    This issue goes back to at least 2018.

    AppData\Local\Apple Inc\CloudKit\iCloudDrive\MMCS\tmpm - Google Search

    If you can find the file, upload it to VirusTotal and scan it there.
    That seems to be part of the issue. When I search the AppData location the file doesn't seem to exist. There is no tmpm file in the MMCS file.
      My Computer


  4. Posts : 12,801
    Windows 11 Pro
       #4

    stephensc said:
    That seems to be part of the issue. When I search the AppData location the file doesn't seem to exist. There is no tmpm file in the MMCS file.
    Some system files are hidden for a reason. See if this works for you. Show Hidden Files, Folders, and Drives in Windows 10
      My Computer


  5. Posts : 10
    windows 10
    Thread Starter
       #5

    essenbe said:
    Some system files are hidden for a reason. See if this works for you. Show Hidden Files, Folders, and Drives in Windows 10
    Yes , that is what I mean.

    I have show hidden files,folders and drives ticked. As well as Hide protected operating system files unticked for good measure but the iCloudDrive folder is empty.
    Attached Thumbnails Attached Thumbnails Windows Defender finds PUA:Win32/Keygen but can't remove it.-empty-iclouddrive-folder.png  
      My Computer


  6. Posts : 94
    Windows 10 Pro 64 bit. Ver. 22H2, Xubuntu 22.04
       #6

    stephensc said:
    Yes , that is what I mean.

    I have show hidden files,folders and drives ticked. As well as Hide protected operating system files unticked for good measure but the iCloudDrive folder is empty.

    Hi!
    Have you tried open a cmd prompt and do dir /a? Sometimes the old style directory listing reviles things the GUI doesn't see! I've seen that myself!

    Regards, snickie
      My Computers


  7. Posts : 1,807
    Windows 10 Pro 21H1 19043.1348
       #7

    snickie said:
    Hi!
    Have you tried open a cmd prompt and do dir /a? Sometimes the old style directory listing reviles things the GUI doesn't see! I've seen that myself!
    Regards, snickie

    That's always a worthwhile effort, good idea.

    Hi stephensc. I've posted the particulars to assist just in case you're not fluent with dos. I'd suggest trying this with an Administrative Command Prompt.


    C:\WINDOWS\system32>cd\
    C:\>
    C:\>cd users\********\appdata\local\Apple Inc\CloudKit\iCloudDrive\MMCS
    C:\users\********\appdata\local\Apple Inc\CloudKit\iCloudDrive\MMCS>dir

    If the sub-directory 'MMCS' contains more than 1 page of files, add a /p after dir.
    dir /p will display 1 page at a time and prompt you to hit any key to display the next page.
    Control C will terminate the command, if required.

    Last edited by W10 Tweaker; 31 Jul 2020 at 10:14.
      My Computer


  8. Posts : 10
    windows 10
    Thread Starter
       #8

    W10 Tweaker said:
    That's always a worthwhile effort, good idea.

    Hi stephensc. I've posted the particulars to assist just in case you're not fluent with dos. I'd suggest trying this with an Administrative Command Prompt.


    C:\WINDOWS\system32>cd\
    C:\>
    C:\>cd users\********\appdata\local\Apple Inc\CloudKit\iCloudDrive\MMCS
    C:\users\********\appdata\local\Apple Inc\CloudKit\iCloudDrive\MMCS>dir

    If the sub-directory 'MMCS' contains more than 1 page of files, add a /p after dir.
    dir /p will display 1 page at a time and prompt you to hit any key to display the next page.
    Control C will terminate the command, if required.

    Thank you W10 Tweaker and Snickie. I wouldn't have had a clue about which dos terms to use.

    However cmd does not seem to be able to find \MMCS path.
    I went up a level to \iCloudDrive dir

    I attach a screenshot.
    I'm not sure what it means.

    Thank you

    Windows Defender finds PUA:Win32/Keygen but can't remove it.-empty-iclouddrive-folder-cmd-prompt.png
      My Computer


  9. Posts : 1,807
    Windows 10 Pro 21H1 19043.1348
       #9

    stephensc said:
    Thank you W10 Tweaker and Snickie. I wouldn't have had a clue about which dos terms to use.
    However cmd does not seem to be able to find \MMCS path.
    I went up a level to \iCloudDrive dir
    I attach a screenshot.
    I'm not sure what it means.
    Thank you

    Good job stephensc.

    I started writing out the directions to un-hide hidden folders and then had another thought. According to my internet searches this could be a nasty Trojan and you might be best to try removing it with another anti-virus before fiddling with the folder or associated files.

    Try this;

    Online Malware Detection | ESET


    I believe you were able to navigate the folder immediately before \MMCS. Try using a manual scan with Windows Defender, select custom scan and navigate to the last folder before \MMCS.

    https://www.tenforums.com/tutorials/84796-how-scan-windows-defender-antivirus-windows-10-a.html#option2


    If you have any idea when this keygen software was downloaded and you have access to restore points or an OS image, that might be a more practical solution if anti-virus tools are unable to quarantine. Search *keygen.* using the windows explorer search box and verify folder or file creation dates. Then look for a restore point or image that predates the file or folder creation date.


    I have to be away for several hours but will check-in when I get home. Be careful if you do find the missing folder or any other irregularities that might surface on this pc.

    Last edited by W10 Tweaker; 31 Jul 2020 at 14:37.
      My Computer


  10. Posts : 7,607
    Windows 10 Home 20H2
       #10

    stephensc said:
    C:\Users\********\AppData\Local\Apple Inc\CloudKit\iCloudDrive\MMCS\tmpm-0x0000000000008289
    Boot into Linux and see whether it exists.
    Download Linux: http://muug.ca/mirror/linuxmint/iso/...n-64bit-v2.iso
    Use Rufus to create a bootable Linux device: Rufus - The Official Website (Download, New Releases)

    It is so simple that even an idiot like me can do it with ease.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 06:17.
Find Us




Windows 10 Forums