EliteBar manual removal:
Kill processes:
pokapoka[X].exe, elit[XR]32.exe, kalv[XR]32.exe, win[XR]32.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antiware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\etbrun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kalvsys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sys29
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system service[X]
HKEY_CLASSES_ROOT\CGBand.BHO
HKEY_CLASSES_ROOT\CGBand.BHO.1
HKEY_CLASSES_ROOT\CGBand.CGBandObj
HKEY_CLASSES_ROOT\CGBand.CGBandObj.1
HKEY_CLASSES_ROOT\CGBand.UICGBandObj
HKEY_CLASSES_ROOT\CGBand.UICGBandObj.1
HKEY_CLASSES_ROOT\PLOT.PlotCtrl.1
HKEY_CLASSES_ROOT\CLSID\{02C20140-76F8-4763-83D5-B660107BABCD}
HKEY_CLASSES_ROOT\CLSID\{0A1D22C3-37BE-470C-9C29-E3074EE0574B
HKEY_CLASSES_ROOT\CLSID\{28CAEFF3-0F18-4036-B504-51D73BD81ABC}
HKEY_CLASSES_ROOT\CLSID\{825CF5BD-8862-4430-B771-0C15C5CA8DEF}
HKEY_CLASSES_ROOT\CLSID\{A74CD7DD-EA6F-11D4-ABF3-000102378429}
HKEY_CLASSES_ROOT\CLSID\{BE8D0059-D24D-4919-B76F-99F4A2203647}
HKEY_CLASSES_ROOT\CLSID\{ED103D9F-3070-4580-AB1E-E5C179C1AE41}
HKEY_CLASSES_ROOT\Interface\{276B0903-EB4B-46FF-8304-F093DEF69DE7}
HKEY_CLASSES_ROOT\Interface\{4AFF987A-773B-48E4-AEE8-08EBDDBDADF8}
HKEY_CLASSES_ROOT\Interface\{A74CD7DE-EA6F-11D4-ABF3-000102378429}
HKEY_CLASSES_ROOT\Interface\{A9B28EF6-ABF3-463B-A3D8-4D0D0BADFADC}
HKEY_CLASSES_ROOT\Interface\{CAAB3B3F-E815-47D9-94FD-8BB9143C0077}
HKEY_CLASSES_ROOT\Interface\{ED646219-20BF-41E5-80FD-EE49021DA599}
HKEY_CLASSES_ROOT\Interface\{DBF33E89-1784-42AC-ADE4-A428F56550A3}
HKEY_CLASSES_ROOT\TypeLib\{8AA59E15-6E81-415C-B299-1ADFB50C8E1A}
HKEY_CLASSES_ROOT\TypeLib\{A74CD7DD-EA6F-11D4-ABF3-000102378429}
HKEY_CLASSES_ROOT\TypeLib\{CA9FC31A-6F35-4493-B629-E64BD6170A17}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{825CF5BD-8862-4430-B771-0C15C5CA8DEF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{825CF5BD-8862-4430-B771-0C15C5CA8DEF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28CAEFF3-0F18-4036-B504-51D73BD81ABC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED103D9F-3070-4580-AB1E-E5C179C1AE41}
HKEY_CURRENT_USER\Software\LQ
HKEY_CURRENT_USER\Software\ohbbackup\EliteToolBar
HKEY_CURRENT_USER\Software\Winrar\File List
HKEY_CURRENT_USER\Software\Winrar\Profiles
HKEY_LOCAL_MACHINE\SOFTWARE\Elitum\EliteSideBar
HKEY_LOCAL_MACHINE\SOFTWARE\Elitum\EliteToolBar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EliteBar Internet Explorer Toolbar
Unregister DLLs:elitebar version [XVS].dll, elitesidebar.dll, elitetoolbar.dll, nt_hide[X].dll, xud_[X].dll
Delete files:pokapoka[X].exe, elit[XR]32.exe, kalv[XR]32.exe, win[XR]32.exe, elitebar version [XVS].dll, elitesidebar.dll, elitetoolbar.dll, nt_hide[X].dll, xud_[X].dll
Delete directories:C:\Windows\etb
C:\Winnt\etb
C:\Windows\EliteBar
C:\Winnt\EliteBar
C:\Windows\EliteSideBar
C:\Winnt\EliteSideBar
C:\Windows\EliteToolBar
C:\Winnt\EliteToolBar
Misc:[X] is a certain double-digit number.
[XR] is a set of three random characters.
[XVS] is the version number.
Exact file location:
pokapoka[X].exe, nt_hide[X].dll, xud_[X].dll - C:\Windows\etb or C:\Winnt\etb
elit[XR]32.exe, kalv[XR]32.exe, win[XR]32.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
elitebar version [XVS].dll - C:\Windows\EliteBar or C:\Winnt\EliteBar
elitesidebar.dll - C:\Windows\EliteSideBar or C:\Winnt\EliteSideBar
elitetoolbar.dll - C:\Windows\EliteToolBar or C:\Winnt\EliteToolBar