Alrite great, let's begin by uninstalling anything in the Add/Remove Programs list having to do with "QBU"
Next, follow by downloading Ewido Security Suite . Install ewido security suite
When installing, under "Additional Options" uncheck.. Install background guard
Install scan via context menu
Launch ewido, there should be an icon on your desktop, double-click it.
The program will now open to the main screen.
When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
You will need to update ewido to the latest definition files. On the left hand side of the main screen click Update.
Then click on Start Update.
The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display "Update successful"
-=-=-=-=-=-=-==-==-=-= End here to download but not scan -=-=-=-=-=-=-==-==-=-=
Click on Scanner
Click on Complete System Scan and the scan will begin.
You will be prompted to clean the first infection.
Select "Perform action on all infections", then proceed.
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Click Save report.
Save the report .txt file to your desktop or a location where you can find it easily.
Next, fix the following with HJT:
O4 - HKLM\..\Run: [QkOnBtn] C:\Program Files\QBU\QkOnBtn.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O14 - IERESET.INF: START_PAGE_URL=http://www.westnet.com.au
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
After this, reboot into safe mode, and delete the following folder:
C:\Program Files\QBU
Reboot into normal mode again, run HJT, and post a new log here, along with the Ewido scan log.
Thanks.