Consider: http://www.backgroundtask.eu/Systeemtaken/taakinfo/73791/HC2Setup.exe/ and http://www.prevx.com/filenames/19523802881579542-X1/HC2SETUP.EXE.html and http://support.clean-mx.de/clean-mx/viruses.php?virusname=Adware.Somoto.8&sort=first%20desc The threat in there = http://systemexplorer.net/file-database/file/biclient-exe and http://processchecker.com/file/biclient.exe.html → https://www.virustotal.com/et/file/f613d98031efc7359c708b9d8a11573526c49e4b60d2614e56747927fa6c2d7b/analysis/
polonus