Processes:
KiesTrayAgent.exe
DeviceDataService.exe
ConnectionManager.exe
DeviceManager.exe
Kies.exe
KiesPDLR.exe
KiesHelper.exe
KiesAirMessage.exe
File System:
C:\Users\[UserName]\AppData\Local\Temp\{A9E68544-3AA6-4AB9-9A4B-2BF631975A17}\
C:\Users\[username]\AppData\Local\Temp\KiesTemporary\
C:\Users\[username]\AppData\Local\Temp\MarkAny\
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MaAgent.exe
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MAAuthProc.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MACLICX13.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MACLicX15.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MACSMANAGER.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MaCSMgr.exe
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MaCSProHook.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\mapshapi.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\mapwij10.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MaSyncP.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MaWAMP.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MAWebControl.exe
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MaWMP.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MPXBox.exe
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\MtpAccess.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAFileUpdate.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\UserShare.dll
C:\Users\[username]\AppData\Local\Temp\MarkAny\ContentSafer\XSYNCClt.dll
C:\Users\[username]\AppData\Local\Samsung\
C:\Users\[username]\AppData\Local\Temp\KiesLiveupdateTemp\
C:\Users\[username]\AppData\Local\Temp\KiesTemporary\
C:\Users\[username]\AppData\Local\Temp\MarkAny\
C:\Users\[username]\AppData\Local\Temp\SAMSUNG\
C:\[KiesInstallPath]\Kies\External\FirmwareUpdate\AgentVer.txt
C:\[KiesInstallPath]\Kies\EULAVer.txt
C:\Users\[UserName]\AppData\Local\Temp\{A9E68544-3AA6-4AB9-9A4B-2BF631975A17}\WriteDescExecuteFileName.exe Software\Samsung\KIESSETUP Samsung Kies Installer 2.0
C:\[KiesInstallPath]\Kies\External\DeviceModules\ConnectionManager.exe
C:\[KiesInstallPath]\Kies\External\DeviceModules\DeviceManager.exe
C:\[KiesInstallPath]\Kies\External\DeviceModules\DeviceDataService.exe
C:\[KiesInstallPath]\Kies\External\DeviceModules\DeviceServiceModelDB.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DeviceServiceCore.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DeviceCommunication.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DCADU.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DCAKOREAMITSOBEX.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DCAPARAGONATOBEX.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DCAPARAGONGM.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DCAPARAGONOBEX.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DCAWM.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DCAOBEX.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\THNRProghelp.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DevFileService.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\DeviceSearch.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\RASWraper.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\BackupRestoreLib.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\CDBurnCOM.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\StarburnX12.dll
C:\[KiesInstallPath]\Kies\External\DeviceModules\UPNPDevice_Kies.dll
C:\[KiesInstallPath]\Kies\External\TransModules\TG_Dump0708.DLL
C:\[KiesInstallPath]\Kies\External\MediaModules\MP3FileInfoCOM.dll
C:\[KiesInstallPath]\Kies\External\MediaModules\OGGFileInfoCOM.dll
C:\[KiesInstallPath]\Kies\External\MediaModules\AStoreMarshal.dll
C:\[KiesInstallPath]\Kies\External\MediaModules\MACSReaderAVI.ax
C:\[KiesInstallPath]\Kies\External\MediaModules\NEDFilter4Samsung.ax
C:\[KiesInstallPath]\Kies\External\SyncModules\secman.dll
C:\[KiesInstallPath]\Kies\External\SyncModules\metastore2.dll
C:\[KiesInstallPath]\Kies\External\SyncModules\Synchronization2.dll
C:\[KiesInstallPath]\Kies\External\SyncModules\nktwab.dll
C:\Windows\SysWOW64\Redemption.dll
C:\[KiesInstallPath]\Kies\External\smdecryption.dll
C:\[KiesInstallPath]\Kies\External\PRPlayerCore.dll
C:\Windows\MusicCityDownload.exe
Registry:
HKEY_CURRENT_USER\Software\AppDataLow\Software\MarkAny
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\090B0474CB502846DABF6D9B6BD86327
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C0EAADEC0B0BEC47056488271833ED1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\290A1BAC3852561E434EDCF37ADDC650
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F51676373E2C8FAFD1C3CB5D0FC6F78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\32947F291B037BB37F4C94D15C71AFCC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\364651BA342348B03E7E38A50F61D602
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3749FA404D1387FD0883E182C92F5AB1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4482C36BEE44B81F7D56DABE40984FCE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5390087D56653F56BFE40693A70A5A2A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61F50ED3728E668469DD5A9B7663EEFF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F5AD8238986F445D49AC9AE6A9CDD06
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\72798142C6A7CA8AEAFB493E6CA75C3D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90F0105370096E802C973171912E5EC9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\93098AC90CB9B9D9E0B7DAF98117ABD6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B0BA626160FBB7AF5AF852DC3D4E8C5C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B245A3B6DB9BDEE94D368EAD00DF75C1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C0153905C28C684AD92906E7C31D656A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DAB70100ACFDAE9CF043224B28091403
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E71E9BD78DFE557AE8AD19C38A450BD8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF765801CEFE877C538A6FB5CFB97515
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB0AD455040F4F919919F27A26A877CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDA9F652221F00D6C071019FF16552A4
HKEY_USERS\S-1-5-21-1034364882-3164073863-2110962517-1000\Software\AppDataLow\Software\MarkAny