This document presents a kernel rootkit prevention model using multiclass (KRPMM) to detect and prevent rootkits in cloud environments. The proposed system analyzes downloaded files for rootkit presence by comparing MD5 hashes against a database of known malicious software, ensuring that only clean files are allowed into the user's node. The methodology employs dynamic detection techniques and aims to enhance overall security in virtual environments by blocking malicious files before they can cause harm.