A browser that keeps changing its search engine, opening new tabs or reinstalling extensions may be affected by an unwanted program, a managed policy or a user setting. Google's Chrome reset can restore search, homepage, site settings, cookies, pinned tabs, extensions and themes to defaults; bookmarks and saved passwords are not deleted. It does not guarantee that the underlying software has been removed. Diagnose the origin first, then use reset as one controlled step and verify persistence.
Before you start
Record the current search provider, startup pages, extensions and suspicious URLs. Save essential tabs and note sites where a reset will sign you out. Check whether the browser says it is managed by your organization; a legitimate work policy should not be bypassed. Do not install a 'one-click repair' utility advertised by a pop-up.Do it step by step
- Open Chrome Extensions and inspect unfamiliar items, permissions and recent changes. Remove a suspicious extension through the browser; if it returns, note that fact before repeating removal.
- Review operating-system installed applications and remove unwanted programs using Windows or macOS controls, following Google's guidance. If a device belongs to an employer, coordinate with IT.
- In Chrome Settings, inspect Search engine, On startup and Site settings. Capture the unwanted values for evidence, especially if you must report a potentially harmful installer.
- Use Settings, Reset settings, Restore settings to their original defaults, then confirm. Expect some extensions to be disabled and site cookies or permissions to change. Bookmarks and passwords should remain, but check your own backup before a consequential reset.
- Relaunch Chrome and confirm the search engine, startup page and extensions behave as expected. Run Chrome Safety Check and trusted system security tools if malware symptoms existed.
- Revisit after a reboot. If the hijack returns, investigate a persistent application, policy or synced setting rather than resetting repeatedly. Change passwords from a trusted device if you entered them on a suspicious page.