Well, this folder appear like twice every month and I don't remember how I got it. I just delete the folder, run CCleaner registry fix, run Malwarebytes, run AdwCleaner, run HitmanPro and somehow the problem is still there.
AdwCleaner logs:
# AdwCleaner v5.007 - Logfile created 10/09/2015 at 23:43:13
# Updated 08/09/2015 by Xplode
# Database : 2015-09-08.2 [Server]
# Operating system : Windows 10 Pro (x64)
# Username : Manh Duc - COMPUTER
# Running from : C:\Users\Cua\Desktop\adwcleaner_5.007.exe
# Option : Scan
# Support :
http://toolslib.net/forum***** [ Services ] *****
Service Found : PrivoxyService
***** [ Folders ] *****
***** [ Files ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\SecureWebChannel
***** [ Web browsers ] *****
########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [618 bytes] ##########
# AdwCleaner v5.007 - Logfile created 11/09/2015 at 00:03:19
# Updated 08/09/2015 by Xplode
# Database : 2015-09-08.2 [Server]
# Operating system : Windows 10 Pro (x64)
# Username : Manh Duc - COMPUTER
# Running from : C:\Users\Cua\Desktop\adwcleaner_5.007.exe
# Option : Cleaning
# Support :
http://toolslib.net/forum***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\SecureWebChannel
***** [ Web browsers ] *****
[-] [C:\Users\Cua\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : uk.ask.com
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [770 bytes] ##########
Malwarebytes logs:
Malwarebytes Anti-Malware
www.malwarebytes.orgError, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Update, Bad md5 or size: akadomains, 11,
Error, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Update, Bad md5 or size: akaips, 11,
Update, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Manual, Remediation Database, 2015.5.13.1, 2015.8.28.2,
Update, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Manual, Rootkit Database, 2015.6.2.1, 2015.8.16.1,
Update, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Manual, IP Database, 0.0.0.0, 2015.9.9.1,
Update, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Manual, AKA IP Database, 0.0.0.0, 2015.9.10.1,
Update, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Manual, Domain Database, 0.0.0.0, 2015.9.10.6,
Update, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Manual, AKA Domain Database, 0.0.0.0, 2015.9.10.3,
Update, 10/09/2015 11:24 PM, SYSTEM, COMPUTER, Manual, Malware Database, 2015.6.3.3, 2015.9.10.6,
Scan, 10/09/2015 11:48 PM, SYSTEM, COMPUTER, Manual, Start:10/09/2015 11:24 PM, Duration:23 min 32 sec, Threat Scan, Completed, 1 Malware Detection, 2 Non-Malware Detections,
Error, 10/09/2015 11:56 PM, SYSTEM, COMPUTER, Protection, IsLicensed, 13,
Protection, 10/09/2015 11:56 PM, SYSTEM, COMPUTER, Protection, Malware Protection, Stopping,
Protection, 10/09/2015 11:56 PM, SYSTEM, COMPUTER, Protection, Malware Protection, Stopped,
(end)
Malwarebytes Anti-Malware
www.malwarebytes.orgScan Date: 10/09/2015
Scan Time: 11:24 PM
Logfile:
Administrator: Yes
Version: 2.1.8.1057
Malware Database: v2015.09.10.06
Rootkit Database: v2015.08.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: Manh Duc
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 376613
Time Elapsed: 23 min, 32 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.Privoxy.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PRIVOXYSERVICE, Quarantined, [df5feb4317742c0a3ac1b4739d66a55b],
Registry Values: 1
PUP.Optional.Privoxy.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PRIVOXYSERVICE|ImagePath, "C:\Program Files (x86)\Alfasistem Memory\privoxy.exe" --service, Quarantined, [df5feb4317742c0a3ac1b4739d66a55b]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
Backdoor.Agent.WD, C:\Users\Cua\AppData\Local\Temp\hp_up_53523222.exe, Quarantined, [eb538aa4bad1fc3a2fcd8abc0af643bd],
Physical Sectors: 0
(No malicious items detected)
(end)