Every time I run “Malware Bytes”, it identifies a malicious registry code, PUP.Optional.Bandoo.A. Specifically, it’s location is: HKCUSOFTWAREMicrosoftWindowsCurrentVersionExtStats{9D717F81-9148-4F12-8568-69135F087DB0} (PUP.Optional.Bandoo.A).
I’ve tried isolating it and deleting using Malware Bytes, and by doing a RegEdit. I have MSE and AVG antivirus running. I’ve also run TrendMicro’s “Housecall”. It always comes back, within 5-10 minutes.
I’m wondering, is Bandoo really a “malicious” code? If so, what threat does it present? I can’t seem to really find a difinitive answer. What can I do to permanently delete it?
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Malicious registry code: can’t remove it
Home » Forums » AskWoody support » Windows » Windows – other » Malicious registry code: can’t remove it
- This topic has 17 replies, 10 voices, and was last updated 11 years, 5 months ago.
AuthorTopicWSOlgimp
AskWoody LoungerDecember 5, 2013 at 7:56 am #492287Viewing 9 reply threadsAuthorReplies-
WSMedico
AskWoody LoungerDecember 5, 2013 at 8:16 am #1426834See if one of these tips using a Google searchmight help.
-
WSveegertx
AskWoody LoungerDecember 5, 2013 at 10:53 am #1426872JRT can remove I think. Handy tool to have anyways Junkware Removal Tool
-
WSOlgimp
AskWoody Lounger
-
-
WSruirib
AskWoody LoungerDecember 5, 2013 at 11:15 am #1426880PUPs are apps that usually sneak by you. Most malware protection vendors don’t see it as real malware, they are usually just annoying apps that are installed when you install something else. So, are they really malicious? Most, probably not. They just “sneaked” their install – in some cases it’s possible that the user actually agreed to download it.
-
WSveegertx
AskWoody LoungerDecember 7, 2013 at 6:56 pm #1427604PUPs are apps that usually sneak by you.
They just “sneaked” their install – in some cases it’s possible that the user actually agreed to download it.Thats why you don’t do DEFAULT installs of nothing, click through each thing and READ
LOL Like Google Chrome, have several things want to install that mess and I ain’t having it.
-
-
cmptrgy
AskWoody LoungerDecember 5, 2013 at 12:40 pm #1426932Check out what Bandoo is for http://search.yahoo.com/search?ei=utf-8&fr=slv1-hpd03&p=bandoo&type=
If you still don’t want it see if it can be uninstalled
Check your startups
Since you know how to use regedit, search for anything Bandoo and delete them especially an exe entryHP EliteBook 8540w laptop Windows 10 Pro (x64)
-
WSOlgimp
AskWoody Lounger
-
-
RetiredGeek
AskWoody_MVPDecember 5, 2013 at 12:44 pm #1426935Olgimp,
Have you tried running MalwareBytes in Safe Mode? HTH :cheers:
-
b
AskWoody_MVPDecember 5, 2013 at 2:41 pm #1427044 -
WSOlgimp
AskWoody LoungerDecember 6, 2013 at 5:55 pm #1427360After reading and checking out all the helpful suggestions, I’m not as concerned about this redundant registry “stat” entry being malicious….more appropriately, annoying. I am going to attempt the malware scan in safe mode to see if I can finally get rid of it. I note it is used in social network sites, and I do use facebook to keep up w/the kiddies ;-). At least it’s not a .exe file.
-
WSruirib
AskWoody LoungerDecember 6, 2013 at 6:02 pm #1427362After reading and checking out all the helpful suggestions, I’m not as concerned about this redundant registry “stat” entry being malicious….more appropriately, annoying. I am going to attempt the malware scan in safe mode to see if I can finally get rid of it. I note it is used in social network sites, and I do use facebook to keep up w/the kiddies ;-). At least it’s not a .exe file.
Have you tried the suggestion by BruceR? Probably you can remove Bandoo without even messing with the registry…
-
-
WSOlgimp
AskWoody Lounger
-
-
cmptrgy
AskWoody LoungerDecember 8, 2013 at 3:41 am #1427623I hope you follow up on the uninstall recommendation.
My brother uses facebook and I checked out his computer for anything Bandoo and there isn’t any Bandoo’s in his computer
I have a friend who’s always trying to keep up with his kids since things including PUP’s for whatever reason come in many times. He also uses Facebook and he doesn’t have anything Bandoo either.
If Bandoo is needed for whatever site it will probably come back; if it does you might be able to figure which site it comes in from
BTW I also suspect that’s why it isn’t an exe, it’s probably part of some site that has been visited
In your case Bandoo might be only an annoyance but I would uninstall it unless there’s a compelling reason not to
One reason is the possibility of allowing spyware at a minimum, another reason is not knowing what website it works with – andthe possibilty of eventually some malware creeping in
Anyway, I like to keep my computer good and clean like you are dong and if my children were still kids I’d be following up on Bandoo are anything unfamiliar to meHP EliteBook 8540w laptop Windows 10 Pro (x64)
-
WSMJSabol
AskWoody LoungerDecember 17, 2013 at 9:59 pm #1429640I’m not familiar with Bando but I had Qone that I had problems removing. I followed all recommendations but nothing. I decided to do a restore point and that solved my problem. The virus got in by tagging on a download I suspect. I did not download a critical program to get it and now all is well. My solution was simple and no aggravation.
MJ -
WSSudo
AskWoody LoungerDecember 18, 2013 at 4:55 am #1429677AdwCleaner is a program designed to rout out PuPs which you could try.
-
-
cmptrgy
AskWoody LoungerDecember 18, 2013 at 1:04 pm #1429723If you are still intersted in removing Bandoo, please let us know whether or not you have been able to uninstall it or if AdwCleaner worked for you.
If nothing has worked yet
You have already tried to delete
HKCUSOFTWAREMicrosoftWindowsCurrentVersionExt Stats{9D717F81-9148-4F12-8568-69135F087DB0} (PUP.Optional.Bandoo.A)
in the registry but Bandoo still comes back
You have checked your startups and it doesn’t have anything Bandoo in itUnisntall any program that you don’t need or looks fishy
If that doesn’t work go back into the registry,, in addition to deleting the above registry item aslo do a search for Bandoo
— It might be in more than one entry
— As it finds Bandoo entries, you might be able to even find which application/program Bandoo is associated with in your case
— I don’t like to assume things but I suspect you know how to work in the registry and ensure the computer stays okAfter all that if still unsuccesful, I would try CCleaner. I know many people don’t feel registry cleaners are worth using etc
— But I can guarantee you I have helped many friends and volunteers clean up their computers very well with CCleaner
— But it shouldn’t be used to clean up everything all at once plus normal maintenance items should already be in place
— If you decide to try it, just run the Cleaner section first
— Then in the registry section, unclick all items but one and clean out that section only
—— Make very sure the computer still runs ok after that
— Then if you want to continue continue, check in a 2nd item etc
Good luckHP EliteBook 8540w laptop Windows 10 Pro (x64)
-
joep517
AskWoody MVPDecember 18, 2013 at 8:52 pm #1429841You have not said whether you’ve used a tool such as Autoruns or WhatInStartup. If you haven’t use either one to display and manage what gets started when you boot the system. Autoruns produces a vast amount of information. You should refer to the Logon tab. If you aren’t sure of what some entries are post a screenshot and someone here will help identify it.
What ever is adding the registry entry is not necessarily named anything close to Bandoo.
Joe
--Joe
Viewing 9 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Just got this pop-up page while browsing
by
Alex5723
10 minutes ago -
KB5058379 / KB 5061768 Failures
by
crown
9 hours, 59 minutes ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
12 hours, 38 minutes ago -
At last – installation of 24H2
by
Botswana12
13 hours, 22 minutes ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
3 hours ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
1 day, 1 hour ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
18 hours, 54 minutes ago -
Limited account permission error related to Windows Update
by
gtd12345
1 day, 14 hours ago -
Another test post
by
gtd12345
1 day, 15 hours ago -
Connect to someone else computer
by
wadeer
1 day, 9 hours ago -
Limit on User names?
by
CWBillow
1 day, 12 hours ago -
Choose the right apps for traveling
by
Peter Deegan
1 day, 2 hours ago -
BitLocker rears its head
by
Susan Bradley
10 hours, 35 minutes ago -
Who are you? (2025 edition)
by
Will Fastie
9 hours, 32 minutes ago -
AskWoody at the computer museum, round two
by
Will Fastie
1 day, 4 hours ago -
A smarter, simpler Firefox address bar
by
Alex5723
2 days, 1 hour ago -
Woody
by
Scott
2 days, 10 hours ago -
24H2 has suppressed my favoured spider
by
Davidhs
10 hours, 11 minutes ago -
GeForce RTX 5060 in certain motherboards could experience blank screens
by
Alex5723
3 days, 1 hour ago -
MS Office 365 Home on MAC
by
MickIver
2 days, 18 hours ago -
Google’s Veo3 video generator. Before you ask: yes, everything is AI here
by
Alex5723
3 days, 15 hours ago -
Flash Drive Eject Error for Still In Use
by
J9438
9 hours, 56 minutes ago -
Windows 11 Insider Preview build 27863 released to Canary
by
joep517
4 days, 9 hours ago -
Windows 11 Insider Preview build 26120.4161 (24H2) released to BETA
by
joep517
4 days, 10 hours ago -
AI model turns to blackmail when engineers try to take it offline
by
Cybertooth
3 days, 13 hours ago -
Migrate off MS365 to Apple Products
by
dmt_3904
3 days, 14 hours ago -
Login screen icon
by
CWBillow
3 days, 4 hours ago -
AI coming to everything
by
Susan Bradley
19 hours, 24 minutes ago -
Mozilla : Pocket shuts down July 8, 2025, Fakespot shuts down on July 1, 2025
by
Alex5723
5 days, 1 hour ago -
No Screen TurnOff???
by
CWBillow
2 hours, 13 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.