Severity scale:  

Remove Auto Refresh Malware (Virus Removal Guide) - Easy Removal Guide

removal by Gabriel E. Hall - - | Type: Adware

Auto Refresh Malware is a deceptive Google Chrome addon that is underrated for causing redirects and displaying pornographic ads

Auto Refresh Chrome extension

Auto Refresh Malware (a.k.a. Auto Refresh Premium or Auto Refresh Plus) is a web browser's extension that has been launched in 2016 by a team of young and ambitious developers with an intention to ensure an on-time refresh and reload of visited websites. According to the community reports[1], this browser-based plug-in was quite popular up until now. However, experts included it in the malware and potentially unwanted programs (PUP) databases after its update in 2019 October when the 1.3.14 version has been released. 

According to experts, the Auto Refresh extension has received the crucial Privacy Policy changes, as well as some advertising policies. It seems to be injecting potentially dangerous scripts from, static/js/background.js,,,, and similar third-party domains. As a consequence, the affected web browser starts redirecting to affiliate third-party websites and generating new tab windows without permission. Based on people's reports, some of the Auto Refresh ads may contain pornographic content or redirect people to infamous dating websites. 

Name Auto Refresh or Auto Refresh Premium
Classification Malware, potentially unwanted program (PUP), adware
Distribution The extension is usually installed purposely for increasing the website's load time and ensure a regular reload/refresh functions. However, it can also sometimes be promoted via freeware bundles and infiltrate machines without being noticed
The problematic version Upon the release of the updated Auto Refresh version (1.3.14) users started reporting the extension for displaying intrusive ads and redirecting people to x-rated adult websites
 Symptoms The most prominent symptom – the presence of a new extension on the default web browser. However, the extension can start causing redirects to irrelevant websites, generate intrusive ads among search results, deliver altered search results, etc. 
Related The extension can regularly initiate redirects via the following:
 Elimination Since this extension is accused of installing malicious scripts and trojan JS/Chromex.Agent.AP, it's advisable to remove Auto Refresh malware using a professional AV engine
 Fix & Repair  Every time when malware affects the machine, it's recommended to repair Windows registry entries. For this purpose, you can try using Reimage Reimage Cleaner Intego tool

Auto Refresh Malware has been a quite popular extension of web browsers until its developers decided to fill it with potentially dangerous, highly obfuscated scripts. Although it's not dangerous, experts and users agree that the extension became a crapware and malware, the affiliated of which may be redirecting web browser's pages to porno sites. 

The first Auto Refresh Premium was created in 2016 with limited functionalities and since then we have added some useful features that have been requested from you – e.g. several auto refresh timers for the different websites.

Unfortunately, the features that its developers claim[2] to be useful are not useful at all. The scrips are not the only problem that provoked the negative reaction of the users. It seems that the Auto Refresh virus may be closely related to the js/background.js file, which may try to download a malicious payload of the JS/Chromex.Agent.AP trojan. 

The latter trojan-related Auto Refresh Malware may not reroute web browser to misleading third-party sites that contain porno or dating offers. Based on the latest reports, the app most frequently redirects to the,, and similar domains. However, it can also track some pieces of personal information and perform other highly questionable browser-based performances:

  • extract search engine queries;
  • redirect the web browser to sponsored Yahoo-based search results instead of Google;
  • record information stored on the browser's cookies;
  • read page URLs and replace referrer codes if needed;
  • identify interaction with the e-commerce domains (register what products the user was interested in, the location of the service, the amount paid, etc.). However, there are no traces that the Auto Refresh Chrome extension would be capable of gathering PII (Personally Identifiable Information), such as banking information or names. 

To generalize, the Auto Refresh Plus and Premium Chrome extension is non-malicious on its own. However, it has been reported by many users on Reddit and other forums for potentially dangerous advertising schemes that may be used by third parties not only to promote dubious content but can also expose people to malware download sites. 

Auto Refresh virus
Auto Refresh extension is often dubbed as virus or malware due to the usage of malicious scripts that trigger redirects to x-rated sites

In some rare cases, this extension may directly affect web browsers by changing default settings, including start page, search engine, new tab, etc. by altered Yahoo search or other browser hijackers. The whole tandem of malware on the system may be difficult to remove. Therefore, we recommend you remove Auto Refresh virus from the extensions and programs list with the help of a professional anti-malware tool. 

If Auto Refresh Malware removal is disrupted some malicious processes, you should restart your machine into Safe Mode with Networking to disable all malicious malware-run processes. After that, launch a thorough system scan with a robust antivirus.

Finally, the users of the AutoRefresh extension should not forget to reset the web browser's settings to default and repair the system's performance. Windows registries and core OS components can be repaired with the help of Reimage Reimage Cleaner Intego tool. 

Shady third-party websites and misleading links can make people download malware

Most of the cyber threats are distributed in a misleading manner. Even though most of the potentially unwanted programs, malware, adware, browser hijackers, etc. have their official websites. However, that stand-alone fact does not make them reliable. The official website may be treated as a camouflage allowing to disguise stealthy distribution methods. 

According to[3], malware and potentially unwanted programs are usually distributed by bundling (attached to freeware apps as optional downloads). Nevertheless, this method, despite being misleading, is legitimate as it allows potential victims to deselect additional components. However, it's a must to select the Advanced or Custom installation technique to see all setup windows. 

In addition to that, people can download malware-laced files via spam emails, dangerous third-party ads displayed on hacked websites, hyperlinks injected into random texts, pirated software, software cracks, keygens, etc. In general, all content that is accessible online should be inspected with carefulness. 

You should immediately leave the pages that you are forced to visit. Browser's redirects are usually triggered by third-party extensions that seek to promote affiliate parties, their services, products, or simply boost traffic. However, in practice, the browser's redirects can cause redirects to malware download sites, offensive or adult content where less experienced users can be tricked into giving away personal information or even money. 

Auto Refresh official website
Auto Refresh may be promoted as a legitimate extension, though it's a PUP and adware in reality

Auto Refresh Malware elimination guide 

You may think that Auto Refresh extension is useful for your browsing activities until you start seeing intrusive redirects to websites full of pornographic scenes or ads promoting some dubious services. The extension must have been popular some time ago, however, its latest update seems to contain some potentially dangerous script that are programmed to reroute websites to pre-selected domains, as well as harvest some browser-based data.  

The app is under investigation right now, though there are some references for the Auto Refresh Premium Chrome extension to the js/background.js or JS/Chromex.Agent.AP trojan. Therefore, it's advisable to scan the machine as soon as Auto Refresh ads emerge on the web browser. 

If you are using a professional anti-malware tool already, Auto Refresh Malware removal should not be a difficult task for you to perform. All you have to do is launch the AV scanner or, at best, restart the machine into Safe Mode before launching the scanner. 

If, however, you are not using an anti-malware tool, try installing Malwarebytes or SpyHunter 5Combo Cleaner tools to remove Auto Refresh Malware once and for all. As a final point, perform Windows repair with the help of Reimage Reimage Cleaner Intego utility, which may address Windows Registry entries, system files, and cache. 


You may remove virus damage with a help of Reimage Reimage Cleaner Intego. SpyHunter 5Combo Cleaner and Malwarebytes are recommended to detect potentially unwanted programs and viruses with all their files and registry entries that are related to them.

do it now!
Reimage Happiness
Intego Happiness
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage Intego, submit a question to our support team and provide as much details as possible.
Reimage Intego has a free limited scanner. Reimage Intego offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Intego, try running Combo Cleaner.

To remove Auto Refresh Malware, follow these steps:

Remove Auto Refresh Malware from Windows systems

To get rid of intrusive Auto Refresh ads and popups from Windows, eliminate malware from your machine and then reset your web browser's settings as explained below.

  1. Click Start Control Panel Programs and Features (if you are Windows XP user, click on Add/Remove Programs). Click 'Start -> Control Panel -> Programs and Features' (if you are 'Windows XP' user, click on 'Add/Remove Programs').
  2. If you are Windows 10 / Windows 8 user, then right-click in the lower left corner of the screen. Once Quick Access Menu shows up, select Control Panel and Uninstall a Program. If you are 'Windows 10 / Windows 8' user, then right-click in the lower left corner of the screen. Once 'Quick Access Menu' shows up, select 'Control Panel' and 'Uninstall a Program'.
  3. Uninstall Auto Refresh Malware and related programs
    Here, look for Auto Refresh Malware or any other recently installed suspicious programs.
  4. Uninstall them and click OK to save these changes. Right click on each of suspicious entries and select 'Uninstall'

Delete Auto Refresh Malware from Mac OS X system

Mac users can be negatively surprised after disclosing an unwanted Auto Refresh Plus extension installed on every web browser. In this case, you should perform the below-given steps to disable Auto Refresh Chrome extension completely.

  1. If you are using OS X, click Go button at the top left of the screen and select Applications. Cick 'Go' and select 'Applications'
  2. Wait until you see Applications folder and look for Auto Refresh Malware or any other suspicious programs on it. Now right click on every of such entries and select Move to Trash. Click on every malicious entry and select 'Move to Trash'

Uninstall Auto Refresh Malware from Internet Explorer (IE)

  1. Remove dangerous add-ons
    Open Internet Explorer, click on the Gear icon (IE menu) on the top right corner of the browser and choose Manage Add-ons. Click on menu icon and select 'Manage add-ons'
  2. You will see a Manage Add-ons window. Here, look for Auto Refresh Malware and other suspicious plugins. Disable these entries by clicking Disable: Right click on each of malicious entries and select 'Disable'
  3. Change your homepage if it was altered by virus:
    Click on the gear icon (menu) on the top right corner of the browser and select Internet Options. Stay in General tab.
  4. Here, remove malicious URL and enter preferable domain name. Click Apply to save changes. Delete malicious URL, enter your desired domain name and click 'Apply' to save changes
  5. Reset Internet Explorer
    Click on the gear icon (menu) again and select Internet options. Go to Advanced tab.
  6. Here, select Reset.
  7. When in the new window, check Delete personal settings and select Reset again to complete Auto Refresh Malware removal. Go to 'Advanced' tab and click on 'Reset' button. Now select 'Delete personal settings' and click on 'Reset' button again

Erase Auto Refresh Malware from Microsoft Edge

Reset Microsoft Edge settings (Method 1):

  1. Launch Microsoft Edge app and click More (three dots at the top right corner of the screen).
  2. Click Settings to open more options.
  3. Once Settings window shows up, click Choose what to clear button under Clear browsing data option. Go to Settings and select 'Choose what to clear'
  4. Here, select all what you want to remove and click Clear. Select 'Clear' button
  5. Now you should right-click on the Start button (Windows logo). Here, select Task Manager. Open the start menu and select 'Task Manager'
  6. When in Processes tab, search for Microsoft Edge.
  7. Right-click on it and choose Go to details option. If can’t see Go to details option, click More details and repeat previous steps. Right-click 'Microsoft Edge' and select 'Go to details' Select 'More details' if 'Go to details' option fails to show up
  8. When Details tab shows up, find every entry with Microsoft Edge name in it. Right click on each of them and select End Task to end these entries. Find Microsoft Edge entries and select 'End Task'

Resetting Microsoft Edge browser (Method 2):

If Method 1 failed to help you, you need to use an advanced Edge reset method.

  1. Note: you need to backup your data before using this method.
  2. Find this folder on your computer: C:\Users\%username%\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe.
  3. Select every entry which is saved on it and right click with your mouse. Then Delete option. Go to Microsoft Edge folder on your computer, right-click every entry and click 'Delete'
  4. Click the Start button (Windows logo) and type in window power in Search my stuff line.
  5. Right-click the Windows PowerShell entry and choose Run as administrator. Find Windows PowerShell, right-click it and select 'Run as administrator'
  6. Once Administrator: Windows PowerShell window shows up, paste this command line after PS C:\WINDOWS\system32> and press Enter:
    Get-AppXPackage -AllUsers -Name Microsoft.MicrosoftEdge | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register $($_.InstallLocation)\AppXManifest.xml -Verbose}
    Copy and paste a required command and press 'Enter'

Once these steps are finished, Auto Refresh Malware should be removed from your Microsoft Edge browser.

Get rid of Auto Refresh Malware from Mozilla Firefox (FF)

  1. Remove dangerous extensions
    Open Mozilla Firefox, click on the menu icon (top right corner) and select Add-ons Extensions. Click on menu icon and select 'Add-ons'
  2. Here, select Auto Refresh Malware and other questionable plugins. Click Remove to delete these entries. Select 'Extensions' and look for malicious entries. Click 'Remove' to get rid of each of them
  3. Reset Mozilla Firefox
    Click on the Firefox menu on the top left and click on the question mark. Here, choose Troubleshooting Information. Click on menu icon and then on '?'. Select 'Troubleshooting Information'
  4. Now you will see Reset Firefox to its default state message with Reset Firefox button. Click this button for several times and complete Auto Refresh Malware removal. Click on 'Reset Firefox' button for a couple of times

Eliminate Auto Refresh Malware from Google Chrome

The Auto Refresh virus attacks the Google Chrome web browser in particular. It can be downloaded from Chrome Web Store intentionally or slither onto the system via freeware. If it has started displaying intrusive ads while your browser or trigger redirects, run a scan with anti-malware and then disable the extension by following this tutorial:

  1. Delete malicious plugins
    Open Google Chrome, click on the menu icon (top right corner) and select Tools Extensions. Click on menu icon. Select 'Tools' and 'Extensions'
  2. Here, select Auto Refresh Malware and other malicious plugins and select trash icon to delete these entries. Look for malicious entries and delete each of them by clicking on the Trash bin icon
  3. Click on menu icon again and choose Settings Manage Search engines under the Search section. When in 'Settings', select 'Manage search engines...'
  4. When in Search Engines..., remove malicious search sites. You should leave only Google or your preferred domain name. Click 'X' to remove malicious URLs
  5. Reset Google Chrome
    Click on menu icon on the top right of your Google Chrome and select Settings.
  6. Scroll down to the end of the page and click on Reset browser settings. When in 'Settings', scroll down to 'Reset browser settings' button and click on it
  7. Click Reset to confirm this action and complete Auto Refresh Malware removal. Click on 'Reset' button to complete your removal

Remove Auto Refresh Malware from Safari

  1. Remove dangerous extensions
    Open Safari web browser and click on Safari in menu at the top left of the screen. Once you do this, select Preferences. Click on 'Safari' and select 'Preferences'
  2. Here, select Extensions and look for Auto Refresh Malware or other suspicious entries. Click on the Uninstall button to get rid each of them. Go to 'Extensions' and uninstall malicious add-ons
  3. Reset Safari
    Open Safari browser and click on Safari in menu section at the top left of the screen. Here, select Reset Safari.... Click on 'Safari' and select 'Reset Safari...'
  4. Now you will see a detailed dialog window filled with reset options. All of those options are usually checked, but you can specify which of them you want to reset. Click the Reset button to complete Auto Refresh Malware removal process. Select all options and click on 'Reset' button

Access your website securely from any location

When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. It is a hassle when your website is protected from suspicious connections and unauthorized IP addresses.

The best solution for creating a tighter network could be a dedicated/fixed IP address. If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for server or network manager that need to monitor connections and activities. This is how you bypass some of the authentications factors and can remotely use your banking accounts without triggering suspicious with each login. 

VPN software providers like Private Internet Access can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world. It is better to clock the access to your website from different IP addresses. So you can keep the project safe and secure when you have the dedicated IP address VPN and protected access to the content management system.

Backup files for the later use, in case of the malware attack

Computer users can suffer various losses due to cyber infections or their own faulty doings. Software issues created by malware or direct data loss due to encryption can lead to problems with your device or permanent damage. When you have proper up-to-date backups, you can easily recover after such an incident and get back to work.

It is crucial to create updates to your backups after any changes on the device, so you can get back to the point you were working on when malware changes anything or issues with the device causes data or performance corruption. Rely on such behavior and make file backup your daily or weekly habit.

When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware occurs out of nowhere. Use Data Recovery Pro for the system restoring purpose.

About the author

Gabriel E. Hall
Gabriel E. Hall - Passionate web researcher

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Gabriel E. Hall
About the company Esolutions


Your opinion regarding Auto Refresh Malware