HereWereTel.com is a browser hijacker that forces your web browser to redirect through unwanted search pages, replacing your homepage and default search engine without permission. This potentially unwanted program (PUP) typically arrives bundled with free software downloads and immediately alters browser settings across Chrome, Firefox, Edge, and other popular browsers. While not technically a virus, HereWereTel.com disrupts your browsing experience, tracks your search queries, and exposes you to advertising revenue schemes that benefit its operators at the expense of your privacy and system performance.

HereWereTel.com — cybersecurity illustration
Photo by Ann H on Pexels
Think you're infected right now? If HereWereTel.com has taken over your browser, disconnect from the internet immediately if you're concerned about ongoing data collection. Don't enter passwords or financial information until the hijacker is removed. Call us at (770) 695-6833 or bring your computer to our Roswell shop at 1000 Alpharetta St. We can typically remove browser hijackers same-day and verify your system is clean.

Threat Profile

Attribute Details
Threat Type Browser Hijacker / Potentially Unwanted Program (PUP)
Family Search redirect hijackers
Aliases HereWereTel, HereWereTel.com redirect, HereWereTelcom
Platform Windows (all versions), macOS (less common)
Affected Browsers Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera
Distribution Method Software bundling, deceptive installers, fake updates
Persistence Mechanism Browser extension installation, shortcut modification, scheduled tasks, registry keys (Windows)
Primary Behavior Homepage hijacking, default search engine replacement, search query redirection
Data Collection Search queries, browsing history, clicked links, possibly IP address and system information
System Impact Moderate — slows browsing, increases ad exposure, potential privacy concerns
Payload Delivery May download additional PUPs or adware components
Removal Difficulty Moderate — requires browser cleanup and system-level component removal

How It Spreads

HereWereTel.com rarely arrives alone or through direct user choice. The hijacker spreads primarily through software bundling, where it's packaged with legitimate-looking free programs that users download from third-party software sites. During installation, the bundled hijacker is presented in pre-checked optional offers that most users click through without reading. These deceptive installation wizards use confusing language like "recommended settings" or "enhanced search experience" to disguise the fact that you're agreeing to install browser modification software.

Once you've unknowingly agreed to the installation, HereWereTel.com embeds itself into your browser configuration. The operators of this hijacker profit through affiliate advertising schemes and pay-per-click revenue generated when your searches are redirected through their systems. Every search you perform potentially earns them money, which is why the hijacker is so persistent and difficult to remove through normal browser settings alone.

Common distribution vectors for HereWereTel.com include:

  • Bundled freeware and shareware — Download managers, PDF converters, video players, and system utilities from sites like Softonic, Download.com, or CNET that include optional installs
  • Fake software update notifications — Pop-ups claiming your Flash Player, Java, or media codec needs updating
  • Deceptive download buttons — Misleading "Download" buttons on file-sharing or streaming sites that actually install unwanted programs
  • Malvertising campaigns — Compromised or malicious advertisements on legitimate websites that redirect to installer pages
  • Email attachments disguised as documents — Less common but occasionally used to distribute installer packages
  • Torrent and peer-to-peer downloads — Pirated software that includes hijackers in the installation package

What It Does On Your Machine

Once installed, HereWereTel.com immediately modifies your browser configuration files and potentially adds extensions or helper objects that enforce its presence. Your homepage suddenly changes to HereWereTel.com or a related search page, and your default search engine switches to a branded search portal that you didn't choose. Any attempt to manually change these settings back through your browser's options menu typically fails — the hijacker simply reinstates itself within seconds or after the next browser restart.

The hijacker intercepts your search queries and routes them through its own servers before delivering results. This allows the operators to log your search terms, inject additional advertisements into search results pages, and potentially redirect you to sponsored pages rather than the legitimate search results you expected. The redirection chain often involves multiple intermediate domains before finally landing on a legitimate search engine like Bing or Google with modified results. This multi-hop process slows down your browsing experience noticeably and creates opportunities for additional tracking.

Beyond the obvious browser changes, HereWereTel.com may install supporting components at the system level to maintain its grip on your machine. On Windows systems, the hijacker typically creates scheduled tasks that re-apply browser modifications at regular intervals. It may also add entries to the Windows registry that launch helper processes at startup or modify browser shortcut targets to include command-line parameters that force the hijacked homepage to load. These persistence mechanisms are specifically designed to survive simple browser resets and continue operating even after you think you've removed the hijacker.

Typical HereWereTel.com Artifacts (Windows)
File System Locations: %LOCALAPPDATA%\HereWereTel\ %APPDATA%\HereWereTel\ %PROGRAMFILES(X86)%\HereWereTel\ C:\Users\[Username]\AppData\Local\Temp\[random].exe Registry Keys: HKCU\Software\HereWereTel HKLM\Software\WOW6432Node\HereWereTel HKCU\Software\Microsoft\Windows\CurrentVersion\Run\HereWereTel Browser Extensions (varies by browser): Chrome: [random string] or "Search Manager" Firefox: [GUID]@hereweretel.com Modified Shortcuts: Target: "C:\Program Files\Google\Chrome\Application\chrome.exe" http://hereweretel.com # Check all browser shortcuts on desktop and taskbar for appended URLs

The privacy implications deserve attention even though HereWereTel.com isn't classified as traditional malware. The hijacker collects data about your browsing habits, search queries, frequently visited sites, and potentially personally identifiable information if you enter it into search boxes. This data collection happens continuously while the hijacker is active, building a profile that can be sold to advertising networks or used to target you with specific offers. While the operators claim this data is "anonymized," the tracking occurs without meaningful consent and violates your reasonable expectation of privacy when using your own computer.

Manual Removal — Step by Step

01

Disconnect and Document

Disconnect your computer from the internet (unplug Ethernet or disable Wi-Fi) to prevent the hijacker from downloading additional components during removal. Take a quick photo or write down any unusual homepage URLs or extension names you see in your browsers — this helps verify complete removal later. Note which browsers are affected since you'll need to clean each one individually.

02

Boot Into Safe Mode with Networking

Restart your computer in Safe Mode to prevent the hijacker's background processes from running. On Windows 10/11, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart, and press F5 for Safe Mode with Networking. This mode loads only essential system processes and makes it easier to locate and remove the hijacker components.

03

Uninstall Suspicious Programs

Open Control Panel (Windows) or Applications folder (Mac) and look through your installed programs list sorted by installation date. Remove any programs you don't recognize that were installed around the time the hijacking started — look for names like "HereWereTel," "Search Manager," "Browser Assistant," or generic names with version numbers. Use the standard uninstall process but watch for checkboxes during uninstallation that try to keep some components installed.

04

Check and Fix Browser Shortcuts

Right-click each browser shortcut on your desktop, taskbar, and Start menu, then select Properties. In the Target field, verify it ends with the browser executable (like "chrome.exe" or "firefox.exe") without any URLs appended after it. If you see a URL after the .exe, delete everything after the closing quotation mark following the executable path, click Apply, and repeat for all browser shortcuts.

05

Remove Browser Extensions and Reset Settings

Open each affected browser and navigate to the extensions or add-ons manager (usually found in Settings or via three-dot menu). Remove any extensions you don't recognize or didn't intentionally install, especially those with generic names or recent installation dates. Then find your browser's reset or restore settings option (Chrome: Settings > Reset; Firefox: Help > More Troubleshooting Information > Refresh Firefox) and use it to return browser settings to defaults while keeping your bookmarks.

06

Clean Registry and Startup Items (Windows)

Press Win+R, type "regedit" and press Enter to open Registry Editor. Navigate to HKEY_CURRENT_USER\Software and HKEY_LOCAL_MACHINE\Software and look for folders named HereWereTel or similar — delete these keys if found. Then press Win+R again, type "msconfig" and check the Startup tab (or use Task Manager > Startup on Windows 10/11) to disable any entries related to HereWereTel or suspicious unknown programs. Be conservative — only disable items you're certain are related to the hijacker.

07

Delete Remaining Files

Open File Explorer and navigate to %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES% (type these directly in the address bar). Look for folders named HereWereTel or folders with random names that contain executable files with recent creation dates matching when the hijacking started. Delete these folders completely. Also check your Temp folder (%TEMP%) and delete all contents — these temporary files often contain installer remnants.

08

Scan with Reputable Anti-Malware

Reconnect to the internet and download Malwarebytes Free (from malwarebytes.com — verify the URL carefully) if you don't already have it. Run a full system scan to catch any components you might have missed and to check for additional PUPs that may have arrived with HereWereTel.com. Let the scan complete fully even if it takes an hour or more, then quarantine or remove everything it finds.

09

Verify Browser Behavior

Open each browser you cleaned and manually set your preferred homepage and search engine through the proper settings menus. Close the browser completely, wait ten seconds, and reopen it to verify your settings stuck. Perform several test searches and confirm you're not being redirected through HereWereTel.com or similar intermediate pages. Check that new tabs open to your chosen page rather than a hijacked search portal.

10

Change Passwords and Monitor Accounts

Since the hijacker was tracking your browsing activity, change passwords for important accounts (email, banking, shopping sites) from a known-clean device or after you've verified removal. Monitor your accounts over the next few weeks for any suspicious activity. Consider enabling two-factor authentication on critical accounts if you haven't already — this protects you even if passwords were somehow compromised during the hijacking period.

Prevention

  1. Download software only from official sources. Get programs directly from the developer's website rather than third-party download portals. When you must use a download site, choose "Direct Download" options rather than installer packages or download managers that bundle additional software.
  2. Read every installation screen carefully. Select "Custom" or "Advanced" installation options instead of "Express" or "Recommended." Uncheck any pre-selected boxes offering to change your homepage, install browser extensions, or add toolbars — these are almost always unwanted additions.
  3. Keep your operating system and browsers updated. Enable automatic updates for Windows or macOS and all your browsers. Security patches close vulnerabilities that hijackers and malware exploit to gain access without your direct interaction.
  4. Use a reputable ad blocker. Browser extensions like uBlock Origin reduce exposure to malvertising campaigns that redirect to hijacker download pages. Ad blockers also improve page load times and reduce tracking across the web.
  5. Maintain active anti-malware protection. Keep Windows Defender enabled (it's built into Windows 10/11) or install a reputable third-party solution. Supplement with occasional scans from Malwarebytes Free to catch PUPs that traditional antivirus might classify as "low risk."
  6. Be skeptical of update notifications. Legitimate software updates through the application itself or official system update mechanisms. Pop-ups claiming you need to update Flash, Java, video codecs, or drivers are almost always scams. Close them and manually check for updates through official channels if concerned.
  7. Avoid pirated software and key generators. Cracked applications and keygens are common delivery mechanisms for hijackers, trojans, and worse. The money you save isn't worth the security risks and potential data loss from malware infections.
  8. Review browser extensions regularly. Once a month, check what extensions are installed in your browsers and remove anything you don't actively use or don't remember installing. Hijackers sometimes add extensions that re-apply their modifications even after manual cleanup.
Our 90-Day Warranty — When Computer Repair Roswell removes HereWereTel.com or any other malware from your system, we guarantee our work for 90 days. If the same infection returns within that period, we'll re-clean your computer at no additional charge. We also verify that all supporting components are removed, not just the visible browser symptoms, so you can trust your system is genuinely clean.

Bring It In

While manual removal is possible if you're technically comfortable, browser hijackers like HereWereTel.com often leave components behind that recreate the problem days or weeks later. Our technicians at Computer Repair Roswell have specialized tools and experience to completely remove these infections, including the system-level persistence mechanisms that most users miss. We'll clean your browsers, verify no supporting malware came along for the ride, check for system vulnerabilities that allowed the infection, and give you specific prevention advice for your computing habits.

We're located at 1000 Alpharetta Street in Roswell, just minutes from the historic downtown square. Call us at (770) 695-6833 to describe what you're experiencing — we can often tell you over the phone whether you can safely bring the machine in or if you should shut down immediately. Most hijacker removals are same-day service, and we'll explain everything we find in plain English without the technical jargon. We've been serving Roswell-area homes and businesses since our doors opened, and we back our malware removal work with that 90-day warranty because we're confident in our thoroughness. Don't let HereWereTel.com continue tracking your browsing and disrupting your work — bring it in and let's get your computer back to normal.