Threat Search: 

ThreatExpert's Statistics for HideRun [McAfee]:

HideRun [McAfee] is also known as:
Threat AliasNumber of Incidents
not-a-virus:RiskTool.Win32.HideWindows [Kaspersky Lab]168
Hacktool.HideWindow [Symantec]159
Trojan.DR.KillFiles.HW [PC Tools]81
VirTool:Win32/HiddenRun.B [Microsoft]48
Win-Trojan/Hidewnd.28672 [AhnLab]45
not-a-virus:RiskTool.Win32.HideWindows [Ikarus]43
HackTool.HideWindows [PC Tools]40
Virtool.HideRun.B [PC Tools]36
Win32/IRCBot.worm.variant [AhnLab]26
Hacktool.HideWindows [PC Tools]23
Trojan.Win32.KillFiles [Ikarus]18
not-a-virus:RiskTool.Win32.HideExec.e [Kaspersky Lab]16
Email-Worm.Win32.Alcaul.bq [Kaspersky Lab]10
TROJ_HIDERUN.AD [Trend Micro]10
Mal/Generic-A [Sophos]7
Mal/Generic-E [Sophos]5
not-a-virus:RiskTool.Win32.HideExec [Ikarus]5
not-a-virus:RiskTool.Win32.HideExec.e [Ikarus]5
Trojan:Win32/Bumat!rts [Microsoft]5
not-a-virus:RiskTool.Win32.HideRun [Kaspersky Lab]4
Adware.SlimFTP [PC Tools]1

HideRun [McAfee] is known to be created as:
%ProgramFiles%\dfsdfsd\repcale.exe
%ProgramFiles%\killsh\repcale.exe
%ProgramFiles%\kjhkjhjk\repcale.exe
%System%\dk\lam4.exe
%System%\drive\lam4.exe
%System%\mansor.exe
%System%\mnut\lam4.exe
%System%\of.exe
%System%\programs\hiderun.exe
%System%\repcale.exe
%System%\system dr\mansr.exe
%System%\ttt\lam4.exe
%System%\txp\empavms.exe
%Windir%\java\update.exe
%Windir%\nic\sox\start.exe
%Windir%\system\data\hiderun.exe
%Windir%\system\dcache\data\scan\hiderun.exe
%Windir%\system\programas\hiderun.exe
%Windir%\tsco.exe
c:\recycled\msn\hiderun.exe
c:\winnt\system32\drivers\etc\config\hidden32.exe
c:\winnt\system32\microsoft\user\hidden32.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.