August 19, 20206 yr Author KIS detects and deletes a file from Windows update causing update to fail. OS recovers itself. mccspal.dll Object deleted NIGEL-HOME\win8 C:\Windows\System32\wuauclt.exe wuauclt.exe C:\Windows\System32\ Windows Update 14440 C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\mccspal.dll Object deleted Deleted C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\ mccspal.dll File Active user UDS:Trojan-Spy.Win32.Xegumumune Trojan High Exactly Deleted Today, 19/08/2020 17:49NIGEL-HOME\win8 C:\Windows\System32\wuauclt.exe wuauclt.exe C:\Windows\System32\ Windows Update 14440 C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\mccspal.dll Malicious object detected Detected C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\ mccspal.dll File Active user UDS:Trojan-Spy.Win32.Xegumumune Cloud Protection Trojan High Exactly Detected Today, 19/08/2020 17:49NT AUTHORITY\SYSTEM Task started System user Security level: Recommended, Machine learning and signature analysis: Yes Heuristic Analysis: Light, , Scan technologies: , iSwift: Yes, iChecker: Yes, Action on threat detection: Disinfect, if not possible – delete Today, 19/08/2020 17:39
August 19, 20206 yr Solution Welcome. Please contact Tech Support: https://my.kaspersky.com/support/Please attach the following items to your Tech Support request: a. Description of the issue and detailed detection report.b. Screenshot, as needed.c. GSI
KIS detects and deletes a file from Windows update causing update to fail. OS recovers itself.
mccspal.dll Object deleted
NIGEL-HOME\win8 C:\Windows\System32\wuauclt.exe wuauclt.exe C:\Windows\System32\ Windows Update 14440 C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\mccspal.dll Object deleted Deleted C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\ mccspal.dll File Active user UDS:Trojan-Spy.Win32.Xegumumune Trojan High Exactly Deleted Today, 19/08/2020 17:49
NIGEL-HOME\win8 C:\Windows\System32\wuauclt.exe wuauclt.exe C:\Windows\System32\ Windows Update 14440 C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\mccspal.dll Malicious object detected Detected C:\Windows\SoftwareDistribution\Download\70bcc863a990050b701f79b4ae7d2227\amd64_Microsoft-OneCore-ApplicationModel-Sync-Desktop-FOD-Package~~amd64~~10.0.20190.1000\amd64_microsoft-windows-mccs-mccspal_31bf3856ad364e35_10.0.20190.1000_none_8ef55971e141686e\ mccspal.dll File Active user UDS:Trojan-Spy.Win32.Xegumumune Cloud Protection Trojan High Exactly Detected Today, 19/08/2020 17:49
NT AUTHORITY\SYSTEM Task started System user Security level: Recommended, Machine learning and signature analysis: Yes Heuristic Analysis: Light, , Scan technologies: , iSwift: Yes, iChecker: Yes, Action on threat detection: Disinfect, if not possible – delete Today, 19/08/2020 17:39