Upgradeprotectcleansmart.rest e-mail scam: how to spot it and what to do
Upgradeprotectcleansmart.rest is a phishing site created to extract users' personal information such as name, address, phone number, credit card details, etc. It is made to look like an announcement from Google.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Do it yourself · free Remove Upgradeprotectcleansmart.rest e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Upgradeprotectcleansmart.rest e-mail scam: summary
| Distribution | Shady websites, deceptive ads, software bundling |
|---|---|
| NAME | Upgradeprotectcleansmart.rest |
| TYPE | Scam, phishing, adware |
| SYMPTOMS | A page that looks like an announcement from Google suddenly appears on the screen and urges users to complete a survey in exchange for a prize |
| DANGERS | Users can be tricked into providing personal information, downloading potentially unwanted programs and even malware |
| Name | Upgradeprotectcleansmart.rest |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Type | Phishing message |
|---|---|
| Symptoms | A phishing e-mail asking you to sign in |
| Evidence | 5 write-ups by security sites; details still limited |
| Arrives as | |
| Pretends to be | A well-known company |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 24 March 2022 |
| Facts checked | 7 October 2026 |
What the Upgradeprotectcleansmart.rest e-mail scam e-mail looks like
You've made the 9.68-billionth search!
Congratulations! You are the lucky winner!
Every 10 millionth search is reached worldwide, we will proclaim a winner to send out a thank-you gift.
Please select your lucky prize below and claim it by following the instruction.
How to tell the Upgradeprotectcleansmart.rest e-mail scam e-mail is fake
From our report of Mar 2022 · not reviewed since
Upgradeprotectcleansmart.rest is a phishing site created to extract users' personal information such as name, address, phone number, credit card details, etc. It is made to look like an announcement from Google. People who stumble upon the page can get the impression that they were chosen by Google and will receive a prize if they fill out a survey.
There is no doubt that Google has nothing to do with this fraudulent campaign and that the site was simply created by crooks that try to impersonate a well-known company to appear legitimate. If something seems too good to be true, it probably is. Google does not choose random visitors on the Internet and shower them with gifts.

Is Upgradeprotectcleansmart.rest e-mail scam dangerous? What the senders want
From our report of Mar 2022 · not reviewed since
Upgradeprotectcleansmart.rest in detail
When the scam page opens, people are met with this message:
When you see such claims, you should think critically. Fraudsters want people to act based on emotions. They want users to fill out their details without thinking, hoping that they will receive something for free.
However, you should always research and find out if Google actually does these giveaways. It is best to first confirm the information than rush and give out your personal details to unknown parties.
Crooks use various social engineering methods to make the scam more believable. They include fake comments or pictures of people who have supposedly successfully claimed the prize. This is a trick used by many other schemes we previously wrote about, like Story-board.co.

What to do after the Upgradeprotectcleansmart.rest e-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you entered a password after clicking the link in the Upgradeprotectcleansmart.rest message, treat that account as known to the sender.
Open the provider's real site by typing its address yourself, not through any link in the e-mail, and change the password there. Choose a new one you have never used before, and change it on every other account that shared the old one.
Then use the option to sign out of all other sessions or devices, if the provider has one. This works the same in any browser on Windows 11 and Windows 10.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
Two-step verification asks for a code from your phone or an authenticator app whenever someone signs in from a new device. A stolen password alone is then not enough to open the mailbox.
Turn it on in the security settings of the e-mail account first, then for the bank, shop and social accounts that send their reset links to that address.
While you are there, check the recovery e-mail and phone number and the forwarding rules, which attackers sometimes change to keep access. The settings pages look the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Report the message instead of only deleting it. In Outlook choose Report > Report phishing, in Gmail the three-dot menu > Report phishing; the provider then blocks the same message for other people.
Do not reply and do not click anything else in it. On a work account, forward it to your IT team as an attachment first. Web mail and the mail apps on Windows 11 and Windows 10 offer the same options.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A page that only asked for a password installs nothing, so most readers can skip this step.
If the Upgradeprotectcleansmart.rest e-mail or the page it opened made you download or open a file, delete it and run a full scan, then a Microsoft Defender Offline scan.
In Windows 11 and Windows 10 open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts and the scan takes about 15 minutes, so save your work first.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Choose a proper web browser and improve your safety with a VPN tool
Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online.
One of the basic means to add a layer of security - choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features.
However, if you want true anonymity, we suggest you employ a powerful VPN - it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.
Lost your files? Use data recovery software
While some files located on any computer are replaceable or useless, others can be extremely valuable.
Family photos, work documents, school projects - these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur:
- power cuts
- Blue Screen of Death errors
- hardware failures
- crypto-malware attack
- even accidental deletion
To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, can be your only hope to retrieve your invaluable files.
From our report of Mar 2022 · not reviewed since
Remove malicious browser extensions
The appearance of the "You've made the 9.68-billionth search!" scam may be caused by a browser extension.
They can be programmed to cause pop-ups, banners, and redirects. Crooks who develop them may also use rogue advertising networks that place ads leading to dangerous websites.
You should go to your browser settings, and see if there are any suspicious plugins. If you need help, step-by-step instructions are available below:
MS Edge (Chromium)
MS Edge (legacy)
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all the suspicious plugins that might be related to the unwanted program by clicking Remove.
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the window's top-right).
- Select Add-ons.
- In here, select the unwanted plugin and click Remove.
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click on Uninstall at the bottom.
- Click Safari > Preferences...
- In the new window, pick Extensions.
- Select the unwanted extension and select Uninstall.
From our report of Mar 2022 · not reviewed since
Check your system for adware
Upgradeprotectcleansmart.rest could have also been opened by adware, which is a type of PUP (potentially unwanted program) that can hide in the background of the machine and generate commercial content.
Such infections often appear after the installation of freeware. Freeware distribution platforms include additional programs in the installers to make their activity profitable. Many people skip through the installation steps and do not notice the bundled software.
If you have installed any programs recently, we suggest removing them to see if the unwanted symptoms disappear. If you do not know how you can follow instructions for Windows and Mac machines.
The best way to make sure that your system is virus-free is by using professional security tools like and . Besides that, you can avoid infections as security tools give warnings about unsafe files trying to enter your system.
To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:
- Enter Control Panel into Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- From the list, find the entry of the suspicious program.
- Right-click on the application and select Uninstall.
- If User Account Control shows up, click Yes.
- Wait till the uninstallation process is complete and click OK.
- From the menu bar, select Go > Applications.
- In the Applications folder, look for all related entries.
- Click on the app and drag it to Trash (or right-click and pick Move to Trash)
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any dubious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.
From our report of Mar 2022 · not reviewed since
How to get rid of browsing trackers?
Tracking technologies can collect information like your IP address, geolocation, the websites you visit, links you click on, and things you purchase online.
That is why it is so important to clear your browsers regularly. Websites and web-based applications can use this data to personalize the user experience but they can also sell it to advertising networks and other third parties.
It can get rid of cookies and cache with a click of a button. This will make any collected data inaccessible and stop the tracking process. This software can also fix various system errors, registry issues, corrupted files which is especially useful after a virus infection. If you prefer doing this manually, follow the guide below:
MS Edge (Chromium)
MS Edge (legacy)
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.
- Click Menu and pick Options.
- Go to Privacy & Security section.
- Click on Clear Data...
- Select Cookies and Site Data, as well as Cached Web Content and press Clear.
- Click on Menu and go to Settings.
- Select Privacy and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Privacy & security.
- Under Clear browsing data, pick Choose what to clear.
- Select everything (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.
- Click Safari > Clear History...
- From the drop-down menu under Clear, pick all history.
- Confirm with Clear History.
Questions about Upgradeprotectcleansmart.rest e-mail scam
I opened the "You've made the 9.68-billionth search!" e-mail. Am I hacked?
No. Opening and reading a phishing e-mail does not give anyone access to your account or your PC. Modern mail programs block scripts and remote content by default, so reading the message "You've made the 9.68-billionth search!" only showed you text and pictures.
The danger comes from clicking the button and typing your password on the page it opens, or from opening an attached file. If you did neither, report the message as phishing and delete it.
If you clicked but closed the page without typing anything, there is also nothing to fix. If you did type a password, change it from another device and turn on two-step verification.
The "You've made the 9.68-billionth search!" page asked for my code too. Is two-step verification enough?
Not when you typed the code yourself. Some phishing pages pass your password and the one-time code to the real site in real time, which lets the attacker sign in once. Change the password immediately, then sign out of all sessions so the stolen session ends.
Check the account's security page for new devices, app passwords and recovery details, and remove anything you did not add. A passkey or a hardware key is the strongest protection against this trick, because it cannot be typed into a fake page. Keep the e-mail "You've made the 9.68-billionth search!" for your report, then delete it.
Is Upgradeprotectcleansmart.rest really from a well-known company?
No. It is sent by scammers who copy the name and look of a well-known company. The sender address and the links do not belong to it, and the message asks for your password, which a real company does not request through an unexpected message.
If you want to be sure about your account, open the website or app of a well-known company the way you normally do, not through the message, and look for notices there. Then delete the message and report it as phishing. If you already followed its instructions, use the steps in this guide for your case.
Is it true that your account needs urgent attention?
No. The claim that your account needs urgent attention is the hook of Upgradeprotectcleansmart.rest, invented to give you a reason to act quickly. Scammers pick a story that could plausibly apply to many people, so it may feel relevant to you, but nothing in the message is based on your real accounts or devices.
If the claim concerns a service you use, check it there directly, by opening the website or app yourself. You will find no such problem. Then delete the message and report it as phishing.
What happens if I do what Upgradeprotectcleansmart.rest asks?
The scammers get your password, and they use it quickly. Passwords are tried on the real service within minutes, cards are charged or added to phone wallets, remote access is used to open your bank, and crypto is moved on at once.
Documents surface later as accounts in your name. If you already did what the message asked, do not wait to see what happens; follow the steps in this guide for your case today. Speed matters more than anything else here.
Will a well-known company refund me if I fell for Upgradeprotectcleansmart.rest?
A well-known company did not send the message and is not responsible for it, so a refund usually comes from your bank or card issuer, not from the brand. Call the bank first if you paid.
It still helps to tell the real company: they can secure your account, add notes for their fraud team and take down pages that use their name. Contact them through their official website or app only, never through the message or a search ad. Keep the message as evidence.
How quickly do scammers use a phished password?
Often within minutes. Phishing kits send each password to the operators as soon as it is typed, and many test it automatically on the real service. Some kits also pass the two-step code through in real time.
That is why the first hour matters: change the password, end all sessions and check that the recovery details are still yours. If nothing has changed by then, you were probably fast enough, but keep watching for login alerts and password-reset e-mails for a few weeks.
How do I report Upgradeprotectcleansmart.rest to my mail provider?
Use the built-in button. In Outlook, select the message and choose Report > Report phishing. In Gmail, open the message, click the three-dot menu and choose Report phishing.
Scam text messages can be forwarded to your carrier's spam number, which is 7726 in the US and the UK.
On social networks, use the report option on the message or the profile. Reporting trains the filters that protect you and other users, and it takes a few seconds. Then delete the message.
What should I do first after Upgradeprotectcleansmart.rest?
Secure the account involved. From a device you trust, open the official app or website directly, change the password and sign out of all sessions. Turn on two-step verification with an app or a passkey rather than text messages if the service allows it.
Then check recent activity, linked e-mail addresses and recovery phone numbers for changes you did not make. If an e-mail with the subject "You've made the 9.68-billionth search!" involved money, call your bank using the number on the back of your card. Only after that look into how it happened.
Will Fortect remove Upgradeprotectcleansmart.rest?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Upgradeprotectcleansmart.rest, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Imperva: Social Engineering (read October 7, 2026)
- Wikipedia, the free encyclopedia: Potentially unwanted program (read October 7, 2026)
- FTC: How to recognize and avoid phishing scams (read October 7, 2026)
- CISA: Recognize and report phishing (read October 7, 2026)
- Microsoft Support: Protect yourself from phishing (read October 7, 2026)