What to do if…
an unknown browser extension appears and you cannot remove it
Short answer
Treat the extension as unsafe for now: stop using that browser profile for sensitive logins, then remove the extension and whatever is making it come back.
Do not do these things
- Don’t sign in to banking, email, NHS, benefits, tax, or work systems in the affected browser or profile.
- Don’t follow pop-ups offering a cleanup download or a phone number for support.
- Don’t install random extension remover or cleanup tools from ads, redirects, or unfamiliar sites.
- Don’t paste admin passwords, recovery codes, or card details into the affected browser.
- Don’t assume it is safe because it has a familiar name, logo, or high rating.
- Don’t delete device management or work profiles if this is a work or school device; ask the IT team first.
What to do now
- Stop sensitive use immediately. Close the affected browser. If you must access key accounts now, use a different device, or a different browser profile that you already trust.
- Record the visible clues. Screenshot or write down the extension name, publisher, permissions, and any message such as “Installed by policy” or “Managed by your organisation”.
- Check whether management is expected. If this is a work, school, or organisation-managed device, contact the IT or helpdesk route and do not try to bypass their controls. If it is your personal device and you did not set up management, treat that as suspicious.
- Try the browser’s own removal and reset route.
- Chrome: Open Extensions, remove or turn off the extension if possible, then use Reset settings. If it returns, create a fresh Chrome profile and stop using the old one for sensitive browsing.
- Edge: Open Extensions, Manage extensions, and remove or turn off the extension if possible. If Edge says it is managed on a personal device, record that message before changing anything else.
- Firefox: Use Mozilla’s steps for an add-on that cannot be removed, especially if the remove option is disabled.
- Safari on Mac: Open Safari Settings or Preferences, then Extensions. Turn off or uninstall anything you did not choose.
- Look for the app that may be reinstalling it. Check your installed apps or programs for anything new or unfamiliar from around the time this started, especially search, coupon, PDF, video, assistant, toolbar, cleaner, or security apps you did not mean to install. Uninstall suspicious items and restart.
- Run a malware scan from the operating system.
- Windows: Use Windows Security to run a scan. If you use Microsoft Defender Offline, save open work first because it restarts the device; if BitLocker is on, make sure you can access your recovery key before starting.
- macOS: Update macOS and Safari. If you see configuration profiles, device management, or security software you do not recognise, pause and get trusted hands-on help before removing management settings.
- Secure key accounts from a clean place if exposure is possible. From a different device or a fresh trusted browser profile, change your email password first, then financial accounts. Turn on two-step verification where you can.
- Report it if it involved phishing, a scam, account takeover, or money loss.
- Forward suspicious emails to report@phishing.gov.uk.
- Forward suspicious texts to 7726.
- If money was lost or accounts were taken over, use Report Fraud if you live in England, Wales or Northern Ireland. If you live in Scotland, report via 101.
What can wait
- You do not need to identify the exact malware family today.
- You do not need to work out who caused it before making the browser safer.
- You do not need to wipe the whole computer as a first move if removal, reset, uninstalling suspicious apps, and scanning stop it returning.
- You do not need to contact every service at once. Prioritise email and financial accounts first.
Important reassurance
An extension that will not remove is often the visible part of a bigger browser or device setting. The useful first pattern is simple: stop sensitive use, record the clues, remove the extension or old profile, remove suspicious apps, scan the device, then secure key accounts from a clean place.
Scope note
These are first steps only. If the extension returns after browser reset or a new profile, uninstalling suspicious apps, and a malware scan, later decisions may need specialist technical help.
Important note
This is general information, not legal, financial, cyber security, or other professional advice. On work, school, or organisation-managed devices, follow the organisation’s IT or security process. If you are unsure about removing device management settings or profiles, pause and get qualified help to avoid breaking access or losing data.
Additional Resources
- Google — Install and manage extensions - Chrome Web Store Help
- Google — Reset Chrome settings to default
- Microsoft — Add, turn off, or remove extensions in Microsoft Edge
- Mozilla — Client Challenge
- Apple Support — Use Safari extensions on your Mac
- Microsoft — Virus and Threat Protection in the Windows Security App
- GOV.UK — Avoid and report internet scams and phishing
- Police.uk
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.