Consider: http://www.backgroundtask.eu/Systeemtaken/taakinfo/73791/HC2Setup.exe/
and
http://www.prevx.com/filenames/19523802881579542-X1/HC2SETUP.EXE.html
and
http://support.clean-mx.de/clean-mx/viruses.php?virusname=Adware.Somoto.8&sort=first%20desc
The threat in there = http://systemexplorer.net/file-database/file/biclient-exe
and
http://processchecker.com/file/biclient.exe.htmlhttps://www.virustotal.com/et/file/f613d98031efc7359c708b9d8a11573526c49e4b60d2614e56747927fa6c2d7b/analysis/

polonus