Cloudnet virus: what it is and how to remove it

Cloudnet virus is a miner malware that creates cryptocurrency by running on infected devices' resources. This behavior causes lots of frustration for the user because this process slowdowns the machine and keeps the victim from using the PC normally.

Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Not sure whether Cloudnet.exe is the only thing running? An automatic scan of the PC gives a second opinion.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Cloudnet virus yourself 6 steps, about 18 minutes, no software needed.

Start the steps
Cloudnet virus: backdoor trojan steals information
Cloudnet virus as our 2020 report showed it.

Cloudnet virus: summary

NameCloudnet virus
TypeTrojan, backdoor, cryptocurrency-miner
Rekated processCloudnet.exe
Alternative namesHEUR:Trojan-Proxy.Win32.Glupteba.gen Win32:Dropper-gen [Drp] Gen:Variant.Mikey.67423 BKDR_GLUPTEBA.JNA Win32/Glupteba.BC trojan, etc.
ActivitiesConnects to various IPs and URLs, collects and sends out data, compromises system security
Main dangersPersonal data theft, additional malware infection
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
InfiltrationDownloaded from malicious websites, installed by other malware
Detection namesNo Microsoft detection name is known
DistributionNot recorded in the old report
DamageNot recorded in the old report
SymptomsAn unknown process using the processor or graphics card
Evidence6 write-ups by security sites; details still limited
FilesCloudnet.exe
First seen4 June 2020
Facts checked6 October 2026

What Cloudnet virus does

From our report of Jun 2020 · not reviewed since

Cloudnet virus the trojan that hides its malicious purposes behind various background processes

Cloudnet virus is a miner malware that creates cryptocurrency by running on infected devices' resources.

This behavior causes lots of frustration for the user because this process slowdowns the machine and keeps the victim from using the PC normally. The virus runs Cloudnet.exe process in the background, which is located in a subfolder of the user's profile folder, allowing it to perform its malicious activities.

Additionally, because the virus is usually transferred with the help of other malicious applications, the possibility of the system being infected with such hazards as ransomware, backdoors, keyloggers, and similar threats is quite high.

This malware belongs to the Trojan category. Created by Epic Net Inc., it was bugging users since early 2017, and multiple anti-virus engines are still reporting infections all over the world. The threat is usually injected via the dropper malware already present on the system or is downloaded by users from malicious websites.

Once installed, the malicious virus compromises system security by performing a variety of changes to it. It connects to a remote server controlled by hackers who can remotely send and receive information, which puts sensitive data at risk.

Because the malware can compromise system security, experts advise not to delay Cloudnet virus removal. However, the process might be a little complicated, as Trojans are sometimes difficult to detect and remove due to the persistence techniques used. Therefore, it is highly recommended to enter the safe environment in Windows (Safe Mode) and performing a full scan with anti-virus software.

Once the malicious payload is executed, Cloudnet.exe backdoor performs the following tasks:

Once system modifications are complete, the virus can start its malicious activities. First of all, it sends out a variety of information (OS version, processor name, memory information, malware version, etc.) to a C2 server starts redirecting users to dangerous websites and also include users' emails in advertisement campaigns, which can spam the inbox rather quickly.

This malicious trojan runs the Cloudnet.exe CPU miner that creates digital currency without users' permission. The behavior starts once the malicious program is installed on the device. Unfortunately, the victim at first can only notice slowness or additional application installations and suspicious background processes.

The proper virus removal requires a thorough system cleaning with the professional anti-malware tool because only a full scan on the device can detect all malware and indicate other issues with the machine that may be caused by the backdoor trojan or additional programs running on your device.

The main purpose of Cloudnet virus is cryptocurrency mining. This type of malware comes second after ransomware as one of the most dangerous cyber threats for a reason. Trojans get on the system without the users' knowledge and runs the needed process for a long time until the victim notices anything.

Cryptocurrency gets generated for the creator or sponsor without any interaction with the victim, so this virus is more harmful to the device it runs on than the user in comparison with ransomware. Using such files as executables or DLLs, malware creators can mask their activities on the device and drop additional payloads or malicious programs to devices.

Nevertheless, the uninstallation process of Cloudnet virus is not easier than any other malware removal. There is no particular application that can be removed from the machine manually, so the best option is anti-malware tools and system scans using those programs.

Because malware can modify proxy settings, some users might have troubles when trying to remove Cloudnet.exe virus. Nevertheless, powerful security software should be able to perform the task in the Safe Mode. Please refer to the bottom section of the blog.

Once virus elimination is complete, you should scan your devices with - it can repair Windows Registry automatically and recover from system damage in just a few minutes. This way you can fox virus damage.

  • Creates a new path %Application Data%\EpicNet Inc\CloudNet\;
  • Creates an executable %Application Data%\EpicNet Inc\CloudNet\cloudnet.exe;
  • Creates mutex to ensure one copy of executable is running;
  • Adds and modifies Windows Registry to ensure persistence;
  • Creates a proxy connection;
  • Downloads and executes arbitrary files.
Cloudnet virus: backdoor trojan steals information
Cloudnet virus in our 2020 report.
Cloudnet virus: trojan malware connects to remote server arbitary file
Cloudnet virus in our 2020 report.

From our report of Jun 2020 · not reviewed since

Be careful when surfing the internet - malicious scripts can install malware on your system

Malicious software developers have always been looking for new ways to infect as many users as possible.

While the most primitive methods range from hosting malicious links on websites, some sophisticated techniques rely on exploit kits that abuse software vulnerabilities.

While no method would keep you out of trouble 100%, there are several methods that you could decrease the chance of trojan infection by a lot. Some most basic security measures (which most users still fail to implement) include running anti-malware software and timely system updates. However, probably the most important thing is to be attentive while browsing the internet.

Security software cannot and will not protect you from ALL viruses, as new threats are being developed every day, and databases of AV engines and not immediately updated. Therefore, do not browse questionable sites (like torrent, porn, gambling), do not download pirated software, and use ad-block for your own safety.

Check your PC for Cloudnet virus

  • File: Cloudnet.exe

How to remove Cloudnet virus

Miners hide when Task Manager opens and add Defender exclusions.

The steps deal with both, then remove the files.

  1. Step 1: Check where Cloudnet.exe runs from and stop it

    Cloudnet.exe is the part you can see, and its location tells you whether it belongs there. Right-click it on the Processes page of Task Manager and choose Open file location, then right-click the file > Properties > Digital Signatures to see who signed it.

    An unsigned file, or one in a user folder such as %AppData%, is the one to remove: end the task, then delete the file.

    Note the folder name, because the same folder usually holds its other files. This is the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Close a frozen app (Task Manager, Force Quit) On uGetFix

  2. Step 2: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to Cloudnet virus or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  3. Step 3: Remove it from startup

    Whatever Cloudnet virus installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  4. Step 4: Turn Microsoft Defender back on and remove its exclusions

    Cloudnet virus turns protection off or adds exclusions so that Defender ignores it. In Windows Security > Virus & threat protection, open Manage settings and switch Real-time protection, Cloud-delivered protection and Tamper Protection back on.

    Then open Add or remove exclusions at the bottom of that page and remove whatever you did not add yourself, for example a folder in %AppData% or an entire drive. These pages look the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Turn off Microsoft Defender protection for a moment On uGetFix

  5. Step 5: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  6. Step 6: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Manual removal using Safe Mode

Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.

Step 1. Access Safe Mode with Networking

Manual malware removal should be best performed in the Safe Mode environment.

Windows 7 / Vista / XP

  1. Click Start > Shutdown > Restart > OK.
  2. When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
  3. Select Safe Mode with Networking from the list.Windows 7/XP

Windows 10 / Windows 8

  1. Right-click on Start button and select Settings.
    Settings
  2. Scroll down to pick Update & Security.
    Update and security
  3. On the left side of the window, pick Recovery.
  4. Now scroll down to find Advanced Startup section.
  5. Click Restart now.
    Reboot
  6. Select Troubleshoot.Choose an option
  7. Go to Advanced options.Advanced options
  8. Select Startup Settings.Startup settings
  9. Press Restart.
  10. Now press 5 or click 5) Enable Safe Mode with Networking.Enable safe mode

Step 2. Shut down suspicious processes

Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Click on More details.
    Open task manager
  3. Scroll down to Background processes section, and look for anything suspicious.
  4. Right-click and select Open file location.
    Open file location
  5. Go back to the process, right-click and pick End Task.
    End task
  6. Delete the contents of the malicious folder.

Step 3. Check program Startup

  1. Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
  2. Go to Startup tab.
  3. Right-click on the suspicious program and pick Disable.
    Startup

Step 4. Delete virus files

Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:

  1. Type in Disk Cleanup in Windows search and press Enter.
    Disk cleanup
  2. Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
  3. Scroll through the Files to delete list and select the following: Temporary Internet Files
    Downloads
    Recycle Bin
    Temporary files
  4. Pick Clean up system files.
    Delete temp files
  5. You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter): %AppData%
    %LocalAppData%
    %ProgramData%
    %WinDir%

After you are finished, reboot the PC in normal mode.

Protect your privacy - employ a VPN

There are several ways how to make your online time more private - you can access an incognito tab.

However, there is no secret that even in this mode, you are tracked for advertising purposes. There is a way to add an extra layer of protection and create a completely anonymous web browsing practice with the help of VPN. This software reroutes traffic through different servers, thus leaving your IP address and geolocation in disguise.

Besides, it is based on a strict no-log policy, meaning that no data will be recorded, leaked, and available for both first and third parties. The combination of a secure web browser and VPN will let you browse the Internet without a feeling of being spied or targeted by criminals.

No backups? No problem. Use a data recovery tool

If you wonder how data loss can occur, you should not look any further for answers - human errors, malware attacks, hardware failures, power cuts, natural disasters, or even simple negligence.

In some cases, lost files are extremely important, and many straight out panic when such an unfortunate course of events happen. Due to this, you should always ensure that you prepare proper data backups on a regular basis.

If you were caught by surprise and did not have any backups to restore your files from, not everything is lost. is one of the leading file recovery solutions you can find on the market - it is likely to restore even lost emails or data located on an external device.

From our report of Jun 2020 · not reviewed since

Remove Cloudnet virus and prevent further system compromise

If the backdoor entered your machine with the help of other malware, your device might be infected with multiple threats.

Different malware serves different purposes, however, they do not bring anything beneficial for the victim and can even result in loss of funds, personal files, or even identity theft.

Therefore, computer security should not be treated lightly. Talking about this particular threat, you can open Task manager and check if Cloudnet.exe is running. For complete virus removal use , , or and ensure that machine is virus-free. Such tools can also eliminate possible virus damage and corrupted files.

Remove the virus with the help of security software. Beware that not all anti-virus applications may recognize the threat, so you might have to use a different program to eliminate malware completely. Besides, if your machine is affected by other malicious threats, AV software should be able to get rid of it all in one scan.

Questions about Cloudnet virus

Can Cloudnet.exe damage my computer?

A miner does not usually destroy files, but running the processor or graphics card at full load for weeks raises temperatures, wears out fans and shortens laptop batteries. It also makes the PC slower and raises the electricity bill.

The bigger risk is what came with it: miners are often installed by loaders or bundled with cracks that also drop password stealers. That is why removing Cloudnet.exe should be followed by a full offline scan, and, if the PC shows other signs, by changing the passwords saved in your browsers.

Should I delete the Cloudnet.exe file myself?

You can, but only after you have stopped what restarts it, otherwise the file is simply downloaded or copied back. Note the full path of Cloudnet.exe first, using Open file location in Task Manager. Then disable its startup entry or task, end the process and delete the folder.

If Windows says the file is in use, restart in Safe Mode and try again. Never delete a file from C:\Windows\System32 that is signed by Microsoft; if that is where the busy process lives, the cause is something else using a genuine Windows file.

Can I just delete Cloudnet.exe?

You can, but it is rarely enough. Cloudnet.exe is the visible part of Cloudnet virus; a scheduled task, a service or a startup entry usually starts it again, and some versions restore the file within minutes. Deleting it while it runs may also fail.

Run the Microsoft Defender offline scan instead, which removes the file and its startup entries before Windows loads. Then check Task Scheduler and Startup apps for anything still pointing to the old location. Restart afterwards and confirm the file does not return.

How much electricity does a miner use?

It depends on the hardware and how hard the miner runs, so there is no single figure. A miner that keeps a desktop processor or graphics card busy around the clock can noticeably raise a household power bill over a month, and laptops lose battery life fast.

Some miners limit themselves to part of the available power to stay unnoticed, which lowers the cost but also hides the problem longer. Removing it is the only fix. Afterwards, idle use should fall back to a few percent.

Are my files and accounts safe after Cloudnet virus?

Your files are probably intact: nothing in the reports of Cloudnet virus mentions encryption or deletion, and the sign people saw is Cloudnet.exe using the processor or graphics card at full load. Accounts are the bigger question. Code that runs under your user account can read browser data, and threats like this one are often bundled with a stealer.

Until a scan proves the PC clean, avoid signing in to important accounts on it. Afterwards, change your main passwords from another device and turn on two-step verification. Check your e-mail for forwarding rules you did not set up, a common sign that an account was accessed.

Should I scan my other computers too?

It is a good idea, even for malware that does not spread by itself. The same download, USB stick or loader may have been used on other PCs in the household, and shared folders can carry files between them.

Run a full scan followed by the Microsoft Defender offline scan on each Windows PC that shared drives or files with the infected one. Do not copy programs or installers from the infected PC until it is clean, and change Wi-Fi and router passwords if they were saved on it.

How did Cloudnet virus get on my computer?

The route for Cloudnet virus is not documented yet. Malware that shows Cloudnet.exe using the processor or graphics card at full load usually arrives with something you ran yourself:

  • a cracked program or game cheat
  • a free tool from a mirror site
  • a fake installer found through a search ad
  • a file on a USB drive

Some infections are dropped later by a loader that was already on the PC. To find your source, sort Installed apps by install date and look at the Downloads folder for the days before the sign appeared. Remove that item as well; otherwise the same infection may come back after the clean-up.

Should I reset my PC because of Cloudnet virus?

Only if the signs point to deeper access. Reset when you see Cloudnet.exe using the processor or graphics card at full load again after removal, when Windows Security cannot start or update, when remote access tools you did not install keep appearing, or when you simply cannot trust the PC any more.

Otherwise, the plan in this guide plus an offline scan is enough. If you do reset, choose Remove everything and Cloud download for a fresh copy of Windows, restore only documents and photos, and reinstall programs from their official sites. Change important passwords from the clean system afterwards.

The PC is still slow after removing Cloudnet virus. What now?

Restart the PC first; some changes only take effect after a reboot. Then open Task Manager and check the Processes and Startup apps tabs for anything unfamiliar using the processor, disk or network. If something remains, run the Microsoft Defender offline scan once more.

Slowness can also come from a second infection installed alongside Cloudnet virus, or from programs that were damaged during the clean-up. If nothing helps, back up your files and reset Windows. Copy only documents and photos before a reset, and scan the copies.

Will Fortect remove Cloudnet virus?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Cloudnet virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Questions and experiences: Cloudnet virus

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year