Hello Wenda, Leon,
I wanted to briefly follow up on the Paint 3D removal to ensure the SIEM alerts have ceased. As previously mentioned, the vulnerability scanner is flagging the application because the binaries still reside in the system image (C:\Program Files\WindowsApps) as a provisioned package, even after user-level removal. The critical resolution step is running Get-AppxProvisionedPackage -Online | Where-Object {$_.DisplayName -eq "Microsoft.MSPaint"} | Remove-AppxProvisionedPackage -Online in an elevated SYSTEM context; this physically deletes the application payload from the OS disk, which is the only method to permanently clear the detection.
If the issue has been successfully resolved, please consider accepting the answer as it helps other people sharing the same question benefit too. Thank you!
VP