How to Remove Banking-Site Pop-Up Adware Safely
Pop-ups that appear only when you visit online banking are a serious warning sign. The cause may be adware, a malicious browser extension, a notification permission, or malware that recognises banking domains and injects fake warnings, offers, or login prompts.
The behaviour can occur on Windows or macOS, and the unwanted window may look convincing even when the real bank website is genuine. Australian customers using CommBank, NAB, ANZ, Westpac, or smaller credit unions should treat unexpected security alerts as suspicious, especially if they request card details, one-time passwords, or remote-access software.
Do not click the pop-up, call a number displayed inside it, or enter banking information. Close the tab using the browser’s own controls, then use a different trusted device to contact your bank through its official app, card, or website. General malware removal guides can help with broader checks, but banking activity should be handled with extra care.
Identify What Is Producing The Pop-Ups
First, test whether the message appears in one browser or in every browser. If it is limited to Chrome, Edge, Firefox, or Safari, a rogue extension, saved notification permission, altered search setting, or corrupted browser profile is likely. If it appears across several browsers, investigate installed applications, DNS settings, system malware, and network equipment.
Look closely at the address bar before doing anything else. A fake banking page may use a misspelled domain, unusual country code, extra words, or a lookalike character. A padlock only indicates that the connection is encrypted; it does not prove that the website or computer is trustworthy.
Take a screenshot for your bank or security technician, but do not preserve clickable links or copy telephone numbers from the message. Australians who bank while travelling between Sydney, Melbourne, Brisbane, or regional areas should also avoid assuming that a location-related warning is legitimate. Geolocation and device data can be used to make scams appear more believable.
Protect Accounts Before Cleaning
If you entered a password, card number, PIN, or verification code into a suspicious window, contact your bank immediately using a verified channel. Ask whether payments, payees, transfers, or new devices have been added. Change the affected password from a clean device, and change it anywhere else that reused the same credentials.
Enable multi-factor authentication through the bank’s official process, review recent transactions, and temporarily reduce transfer limits if your bank allows it. A one-time code is not proof that a request is safe: scammers may be operating a live fake login page and asking for the code as soon as the bank sends it.
For Australian users, report suspected scams to Scamwatch and follow advice from the Australian Cyber Security Centre when appropriate. Keep records of dates, screenshots, messages, and unauthorised activity. Do not allow a caller claiming to be from a bank or NBN provider to install AnyDesk, TeamViewer, or similar remote-control software.
Remove Browser-Based Adware
Open the browser’s extensions or add-ons page and remove anything unfamiliar, recently installed, or unrelated to your normal work. Pay particular attention to coupon tools, video downloaders, PDF utilities, “security” extensions, and search enhancers. If an extension cannot be removed, restart Windows in Safe Mode where practical, or use the browser’s reset and administrator controls.
Clear site permissions for notifications, pop-ups, redirects, and stored data. A website may have been allowed to send alerts even though no traditional malware is installed. Remove suspicious permissions and review the default search engine, home page, proxy, and startup tabs. On Safari, check Safari extensions and website settings, then inspect Login Items and Applications for software you do not recognise.
If the browser keeps redirecting after a reset, uninstall suspicious programs from Windows Apps or macOS Applications. Avoid downloading “one-click cleanup” tools from advertisements. Use a reputable security product obtained from its official publisher, and consult security tips for safer general maintenance practices.
Scan The Computer And Network
Update the operating system, browser, and security software before scanning. Run a full scan rather than relying only on a quick check. Windows users can use Microsoft Defender Offline when persistent threats are suspected; macOS users should review installed profiles, extensions, background items, and unfamiliar applications as well as running an established security scanner.
A second-opinion scan can identify adware missed by the primary antivirus. For Windows, the ESET Online Scanner provides a useful additional check when downloaded directly from the legitimate source. Remove detected threats according to the scanner’s instructions, then restart the computer.
If every device on your home network shows similar redirects, inspect the router’s DNS settings, administrator password, firmware, and connected devices. Reset the router only after saving legitimate configuration details, and use a unique password afterwards. This matters in households using NBN connections, shared Wi-Fi, smart televisions, and work laptops on the same network.
Verify The Cleanup And Prevent A Repeat
After cleaning, open a fresh private window and type the bank’s address manually or use its official app. Confirm that the address, certificate warning status, and page behaviour are normal. Test with a non-sensitive website first, then monitor banking notifications and statements for several days.
| Warning sign |
Likely source |
Appropriate response |
| Pop-ups appear in one browser |
Extension, site notification, or altered settings |
Remove extensions and revoke site permissions |
| Pop-ups appear in every browser |
Installed adware, DNS change, or system malware |
Run full and second-opinion scans; inspect DNS |
| Fake bank warning requests a code |
Phishing page or injected advertisement |
Close it, contact the bank, and change credentials |
| Redirects affect several devices |
Compromised router or shared network |
Secure the router and check connected devices |
| Pop-ups continue after cleaning |
Persistent malware or unwanted software |
Use Safe Mode or professional incident support |
Keep browsers and operating systems patched, install software only from trusted publishers, and avoid pirated applications and unofficial browser add-ons. Use a password manager, unique passwords, banking alerts, and a separate browser profile for financial activity. These steps reduce the chance that adware can recognise banking sessions and display targeted pop-ups again.