Jump to content

[Help] Remove KMS-R@1n from my computer

Recommended Posts

First of all i would like to say thank you for allowing me to join this huge community

Here my problem, I've read topic about removing KMS-R@1n and downloading some files (FRST.txt, Additional.txt, and fixlist.txt). Once i running FRST and click "Scan" then "Fix" and waited about 30minutes the program keep runing nonstop (i think the program is frozen) so i restart my PC, but Fixlogs.txt is created and KMS-R@1n still not deleted

So did i make something wrong? or something i dont understand. please help me

*I placed the files in the attachmen





Link to post
Share on other sites


You should never perform a FRST fix unless you know what the tool does. FRST does not automatically fix your issue. The fixlist.txt is manually created to suit the need of individual PC. Using them for another computer won't work, for example, the issue you faced. 

That being said, perform a Threat Scan with Malwarebytes and post the resultant log. 

Link to post
Share on other sites

For some reason i didnt get the notification from you, sorry for being able to answer now. And thx for your response

Hmm so that explain why the program freezing, sorry about my foolishness. Please can you create me fixlist.txt that suit my PC? im not a script expert so i dont really understand about creating script or something like that

Here the log from malwarebytes


Link to post
Share on other sites

Are you using any pirated version of Microsof Office 2016 software? If yes, please, remove it as piracy is not condoned here. Please, uninstall YTD Video Downloader 4.8.9.

  • Step # Fix with FRST
    Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
    • Open Notepad.exe. Do not use any other text editor software;
    • Copy and Paste the contents inside the code-box to your Notepad --
      Task: {078F4231-72FC-49C9-B2A8-7E24041FEB30} - System32\Tasks\R@1n-KMS\Office16ProPlus => wmic [Argument = path SoftwareLicensingProduct where (ID="d450596f-894d-49e0-966a-fd39ed4c4c64") call Activate]
      Task: {7702DA29-1E6C-4ED1-ACC6-853E1791B273} - System32\Tasks\KMSAuto => C:\Windows\KMSAuto.exe
      ShortcutWithArgument: C:\Users\ACER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Uninstall Google Chrome.lnk -> C:\Users\ACER\AppData\Local\Google\Chrome\Application\17.0.963.12\Installer\setup.exe (Google Inc.) ->  --uninstall
      2017-06-13 20:13 - 2017-06-13 20:13 - 000026112 _____ () C:\Windows\KMS-R@1n.exe
      2017-06-13 20:13 - 2017-06-13 20:13 - 000005120 _____ () C:\Windows\KMS-R@1nHook.exe
      2017-06-13 20:13 - 2017-06-13 20:13 - 000004096 _____ () C:\Windows\KMS-R@1nHook.dll
      FirewallRules: [{F9536D79-720A-48C0-9475-20C2105EF6EA}] => (Allow) C:\Windows\KMS-R@1n.exe
      FirewallRules: [{2601DB46-1E7D-445E-B6AD-A838AF511D55}] => (Allow) C:\Windows\KMS-R@1n.exe
      HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
      HKU\S-1-5-21-4205702092-4189507904-3592599686-1001\...\MountPoints2: {b67f9a69-4b3f-11e7-90e4-806e6f6e6963} - "E:\AutoRun\AutoRunX\AutoRunX.exe" 
      HKU\S-1-5-21-4205702092-4189507904-3592599686-1001\...\MountPoints2: {d75655d4-797f-11e7-910d-a81e8453cd4f} - "F:\Setup.exe" 
      IFEO\OSppSvc.exe: [Debugger] KMS-R@1nHook.exe
      IFEO\SppExtComObj.exe: [Debugger] KMS-R@1nHook.exe
      GroupPolicy: Restriction <==== ATTENTION
      R2 KMS-R@1n; C:\Windows\KMS-R@1n.exe [26112 2017-06-13] () [File not signed]
      CMD: bitsadmin /reset /allusers
      CMD: ipconfig /flushdns
    • Click on File > Save as...
      • Inside the File Name box type fixlist.txt;
      • From the Save as type drop down list, choose All Files
    • Save the file to your Desktop;
    • Re-run FRST.exe and click Fix;
      • Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.
    • After the completion, a log will be produced;
    • Copy and Paste the contents of the log in your next reply.

  • Step #2 ESET Online Scanner
    Disable your security programs which includes but not limited to anti-virus, anti-malware, anti-spyware et cetera. Peruse this for additional information. 
    • Download esetsmartinstaller_enu.exe by clicking here.
    • Right-click on the program and choose Run as administrator.
    • Accept their terms and condition and proceed.
    • Install Add-On/Active X if prompted.
    • From the Computer Scan Setting check the following box --
      • Enable detection for potentially unwanted programs
    • Click on Advanced Setting --
      • Check the box beside Remove Found Threats;
      • Check the box beside Scan archives
      • Check the box beside Scan for potentially unsafe applications
      • Check the box beside Enable Anti-Stealth Technology
    • Click on Start and wait for the virus signature database to update.
    • The online scan will begin automatically and can take several hours.
      • Note: Do not touch either the Mouse or keyboard during the scan. Otherwise it may stall.
    • After the Scan finishes --
      • If no threats were found:
        • Put a checkmark in Uninstall application on close.
        • Close the program and report that nothing was found
      • If threats were found:
        • Open the file located in C:\Program Files\ESET\ESET Online Scanner\log.txt (32-bit) or C:\Program Files (x86)\ESET\ESET Online Scanner\log.txt (64-bit).
        • Copy and Paste contents of the log file in your next reply.

    Note: Enable your security programs afterwards.

  • Required Log(s):
    • FRST Fixlog;
    • ESET Log


Link to post
Share on other sites

  • 2 weeks later...
  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.