After launching ISESteroids (Start-Steroids), I clicked its update option and Chrome warned that the website might be unsafe. I proceeded anyway, after which Avast-style pop-ups repeatedly claimed that my computer had multiple viruses and no antivirus protection. Closing Chrome, clearing cookies and the temporary folder, and rebooting did not stop them, and Task Manager and Sysinternals Autoruns did not reveal an obvious process responsible. While preparing a Veeam Agent recovery USB, I found an unfamiliar Chrome extension, removed it, and rebooted. The pop-ups stopped and the system returned to normal without needing a restore. Has anyone seen this behavior, and what should I check next to determine whether the update or browser extension compromised the machine?
4 Answers
Since removing the unknown Chrome extension fixed the symptoms, inspect Chrome's extension list, notification permissions, startup settings, and recently installed software. Also run a full scan from a trusted offline or standalone security tool rather than relying only on the pop-up warnings.
The update source deserves scrutiny. The vendor's website may have been replaced or redirected to a scam page, and the unusually long gap between module updates followed by a recent update could indicate that the package or distribution site was compromised. I would avoid running that updater again until the publisher confirms the release is legitimate.
Assume that sensitive information could have been exposed until you finish checking the system. Rotate passwords, API keys, certificates, and other credentials stored locally in scripts, configuration files, environment variables, or browser profiles. Review sign-in logs and revoke anything that looks suspicious.
Check Chrome's notification permissions. A site may have been granted permission to send notifications, which can produce fake virus warnings through Windows even after the browser appears to be closed. Remove any unfamiliar allowed sites and review the installed extensions.

The product is licensed, but that does not rule out a compromised website or installer. Verify the download signature or hash from an independent, trusted source before reinstalling.