Cloud Protection is a rogue that belongs to the same family as OpenCloud Security. It tries to promote itself as a legitimate anti-virus program in order to make you pay for its fraudulent full version.
To creep into a computer, the rogue uses hacked website and the help of Trojans. Only visiting such a website can infect a PC with the rogue without the user’s knowledge.
As soon as the rogue manages to enter a machine, it starts displaying fake alerts and notifications and then performs fake scans, the results of which state that the computer has been infected with a number of viruses. This is a cleverly created move on the part of hackers – it makes the program look legitimate and at the same time frightens the user.
Provided that you have edited the register manually before, you can follow the instructions below:
Files associated with Cloud Protection infection:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random characters]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random characters]”
Cloud Protection processes to kill:
[random characters].exe
Remove Cloud Protection registry entries:
%AppData%\\
%AppData%\\
%AppData%\[random characters]\
%AppData%\[random characters]\
%AppData%\ldr.ini
%AppData%\svhostu.exe
%AppData%\\Cloud Protection.ico
%StartMenu%\Programs\Cloud Protection\
%StartMenu%\Programs\Cloud Protection\Cloud Protection.lnk
%StartMenu%\Programs\Startup\crss.exe
%System%\[random characters].exe
%UserProfile%\Desktop\Cloud Protection.lnk
%Temp%\svhostu.exe
Information About Cloud Protection
Cloud Protection’s interface indeed looks legitimate – this is the reason why some people fall victims to it. Armoured with signs like: “Your security status: At Risk” together with the red button saying “ALARM”, the villain prompts you to click on “Activate protection now” and purchase Cloud Protection – full version. Do not spend your money on this product – it is as much harmful as it is fraudulent.
Some of the fake alerts are:
Security Warning!
The file “[random].exe” is infected. Running of application is impossible.
Please activate your antivirus software.
The rogue will aslo stop all the programs you try to launch in an attempt to scare you.
Instead of falling for its tricks, you should remove it as soon as possible via a legitimate AV software!








No comments yet.