This is some very stubborn malware…
[*] Please download BlitzBlank by emsisoft and save it to your desktop.
[*] Open Blitzblank.exe by double click on it.
[*] Click OK at the warning (and take note of it, this is a VERY powerful tool!).
[*] Click the Script tab and copy/paste the following text there:
DeleteRegValue:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\COOL
DeleteFile:
c:\users\Carlos\AppData\Roaming\COOL.vbs
c:\users\Carlos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\COOL.vbs
[*] Click Execute Now. Your computer will need to reboot in order to replace the files.
[*] When done, post me the report created by Blitzblank. you can find it at the root of the drive C:\