OK it is a mess the main problem is the VBE file on the phone
Run this programme with the phone connected
Download Anti VBS/VBE to your desktop
[]download the appropriate version (32 bit or 64 bit) and double click the file to run it.
[]After a couple of seconds (might also take a whole minute if the machine is heavily infected and/or slow) a report will open in Notepad.
[*]Post that report
Be aware this is a very new programme and as such is not recognised by any Antivirus or Windows, it is safe so allow it to run
THEN
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]
:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&q={searchTerms}&installDate=18/09/2013
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&q={searchTerms}&installDate=18/09/2013
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&q={searchTerms}&installDate=18/09/2013
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=hp&installDate=18/09/2013
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&q={searchTerms}&installDate=18/09/2013
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&q={searchTerms}&installDate=18/09/2013
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&q={searchTerms}&installDate=18/09/2013
IE - HKU\S-1-5-21-2104657585-1371390912-4140370265-1001\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&q={searchTerms}&installDate=18/09/2013
FF - prefs.js..keyword.URL: "http://feed.snapdo.com/?publisher=TightropeYB&dpid=TightropeYB&co=ES&userid=c3d7b72b-02db-73ce-110a-1283139a1138&searchtype=ds&installDate=18/09/2013&q="
FF - prefs.js..network.proxy.http: "213.0.88.86"
FF - prefs.js..network.proxy.http_port: 8080
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [iTunesHelper] wscript.exe //B "C:\Users\Usuario\AppData\Local\Temp\iTunesHelper.vbe" File not found
O4 - HKU\S-1-5-21-2104657585-1371390912-4140370265-1001..\Run: [iTunesHelper] wscript.exe //B "C:\Users\Usuario\AppData\Local\Temp\iTunesHelper.vbe" File not found
O4 - Startup: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe ()
[2014/02/02 17:45:54 | 033,349,632 | -HS- | C] () -- C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?????) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\?????
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
FINALLY
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.