Manual removal instructions:

It is installs itself as an Internet Explorer toolbar and redirects search requests.
It downloads and executes two files from, and saves them as C:\Winupdate.exe and C:\Ed.exe.
Creates multiple files in C:\WINNT\EliteBar.
Depending on the response the adware receives from the server, it may change the Internet Explorer home and search pages, add links to the Internet Explorer Favorites, or modify the system hosts file.

Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value: "Sys29"="%System%\winoko32.exe"

Delete the following registry keys:

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial of UnHackMe.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.