This is some very stubborn malware…

[*] Please download BlitzBlank by emsisoft and save it to your desktop.

[*] Open Blitzblank.exe by double click on it.

[*] Click OK at the warning (and take note of it, this is a VERY powerful tool!).

[*] Click the Script tab and copy/paste the following text there:

DeleteRegValue:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\COOL
DeleteFile:
c:\users\Carlos\AppData\Roaming\COOL.vbs
c:\users\Carlos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\COOL.vbs

[*] Click Execute Now. Your computer will need to reboot in order to replace the files.
[*] When done, post me the report created by Blitzblank. you can find it at the root of the drive C:\