How to remove Win32.PUP.Bandoo (800) Trojan & Bandoo Media malicious software

Last updated on September 28th, 2013

“Bandoo Media” software offers emoticons and winks that can be used inside common internet messengers like Windows Live Messenger, Yahoo Messenger, etc. The default installation settings of “Bandoo’s Media” installer program, is to install also malicious software that can infect your computer like “Search-Results Toolbar” hijacker, "iLivid" download manager and more. 

Also the program installer modifies your internet search settings, changes your internet home page to “” and performs browsing redirects . For that reason you must always pay attention when you install free software on your computer.

To remove “Bandoo Media” malicious software & "Win32.PUP.Bandoo (800)” Trojan from your computer, use the steps below:


How to remove “Bandoo Media” malicious software & "Win32.PUP.Bandoo (800)” Trojan from your computer:

Step 1. Uninstall applications installed from "Bandoo Media” from your Control panel.

1. To do this, go to Start > Control Panel.

{Start > Settings > Control Panel. (Windows XP)}


2. Double click to open “Add or Remove Programs” if you have Windows XP or

Programs and Features” if you have Windows 8, 7 or Vista.


3. In the program list, find and Remove/Uninstall these applications:

a. Bandoo* (By Bandoo Media Inc).

b. Search Results Toolbar (By APN LLC).

c. Also remove any software related to Bandoo Media.

Notice*: At Bandoo Uninstall options window choose “Just Uninstall Bandoo”.


Step 2. Remove malicious software installed by “Bandoo Media” from your internet browser.

Internet Explorer, Google Chrome, Mozilla Firefox

Internet Explorer

How to remove malicious software installed by “Bandoo Media” from Internet Explorer and restore IE search settings.

1. Open Internet Explorer and then open “Internet Options”.

To do this from IE’s file menu, choose “Tools” > “Internet Options”.

Notice*: In the latest versions of IE press the “Gear” icon image_thumb18 on the top right.


2. Click the “Advanced” tab.


3. Choose “Reset”.


4. Check (to enable) the “Delete personal settings” box and choose “Reset”.


5. After the resetting action is completed, press “Close” and then choose “OK” to exit Internet Explorer options.


6. Restart your browser.

7. Re-open Internet explorer and from IE’s file menu, choose “Tools” > “Manage Add-ons”.


8. Choose “Toolbars and Extensions” on the left pane and then disable the following extensions if they exist:

a. Search-Results Toolbar (By APN LLC)

b. BandooIEPluging Class (By Bandoo Media Inc)


9. Now click on “Search Providers” options at the left pane and then “Set as default” search provider another provider than “Search Results” (e.g. Google)

set default search provider

10. Then choose the “Search Results” search provider and click Remove.

remove search results internet explorer

9. Close all Internet Explorer windows and proceed to Step 3.

Google Chrome

How to remove remove malicious software installed by “Bandoo Media” from Google Chrome and restore Chrome search settings.

1. Open Google Chrome and go to chrome menu image and choose "Settings".


2. Find the "On startup" section and choose "Set Pages".


3. Remove the "" from startup pages by pressing the "X" symbol on the right.


4. Set your preferred startup page (e.g. and press "OK".


5. Under “Appearance” section, check to enable the “Show Home button” option and choose “Change”.

6. Delete the “” entry from “Open this page” box.

7. Type (if you like) you preferred webpage to open when you press your “Home page” button (e.g. or leave this field blank and press “OK”.


5. Go to "Search" section and choose "Manage search engines".


6. Choose your preferred default search engine (e.g. Google search) and press "Make default".


7. Then choose the "" search engine and remove it by pressing the "X" symbol at the right. Choose "Done” to close "Search engines" window.


8. Choose "Extensions" on the left.


9. In “Extensions” options remove the “Bandoo” & “Bandoo New Tabs” extensions by clicking the recycle icon at the right.


10. Close all Google Chrome windows and proceed to Step 3.

Mozilla Firefox

How to remove malicious software installed by “Bandoo Media” from Mozilla Firefox and restore Firefox search settings..

1. Click on “Firefox” menu button on the top left of Firefox window and go toHelp” > “Troubleshooting Information”.


2. In “Troubleshooting Information” window, press “Reset Firefox” button to reset Firefox to its default state.

remove firefox

3. Press “Reset Firefox” again.


4. After the resetting job is completed, Firefox restarts.

5. Close all Firefox windows and proceed to the next Step.

6. From Firefox menu, go to “Tools” > “Manage Add-ons”.


7. Choose “Extensions” on the left and then make sure that the following extensions don’t exist.*

Notice*: If they exist you must remove them.

a. Bandoo for Firefox

b. New Tab

c. Search-Results Toolbar


8. Close all Firefox windows and proceed to the next Step.

Step 3: Clean remaining registry entries using “AdwCleaner”.

1. Download and save “AdwCleaner” utility to your desktop.


2. Close all open programs and Double Click to open ”AdwCleaner” from your desktop.

3. Press “Delete”.


4. Press “OK” at “AdwCleaner – Information” window and press “OK” again to restart your computer.


5. When your computer restarts, close "AdwCleaner" information (readme) window and continue to the next step.

Step 4: Remove malicious running processes.

1. Download TDSSKiller Anti-rootkit utility from Kaspersky's website on your computer (e.g. Desktop).*

Notice*: Click to expand the option: 1. How to disinfect a compromised system.




2. When the download process is complete, go to your desktop and double click on "tdsskiller.exe" to run it.


3. At Kaspersky's Anti-rootkit utility program, press "Start scan".


When the scan process is complete, a new window opens with the scanning results.

4. Choose "Cure" and let the program finish the cure operation of the infected files.

5. When the "curing" operation is complete, reboot your computer.

6. After rebooting, run TDSSKiller again to scan one more time for Rootkits. If the previous curing job was completed successfully, the program now will inform you that "No Threats found".

TDSSKiller log

8. Close TDSSKiller and proceed to next step.

Step 5. Clean your computer from remaining malicious threats.

Download and install one of the most reliable FREE anti malware programs today to clean your computer from remaining malicious threats. If you want to stay constantly protected from malware threats, existing and future ones, we recommend that you install Malwarebytes Anti-Malware PRO:

Malwarebytes™ Protection
Removes Spyware, Adware & Malware.
Start Your Free Download Now!

*If you don’t know how to install and use “MalwareBytes Anti-Malware“, read these instructions.

Advice: To ensure your computer is clean and safe, perform a Malwarebytes’ Anti-Malware full scan in windows “Safe mode“.*

*To get into Windows Safe mode, press the “F8” key as your computer is booting up, before the appearance of the Windows logo. When the “Windows Advanced Options Menu” appears on your screen, use your keyboard arrows keys to move to the Safe Mode option and then press “ENTER“.

Step 6. Clean unwanted files and entries.

Use “CCleaner” program and proceed to clean your system from temporary internet files and invalid registry entries.*

*If you don’t know how to install and use “CCleaner”, read these instructions.

Step 7. Restart your computer for changes to take effect and perform a full scan with your antivirus program.

If this article was useful for you, please consider supporting us by making a donation. Even $1 can a make a huge difference for us in our effort to continue to help others while keeping this site free: