Skip to main content
Microsoft Security Intelligence
Published Jun 18, 2008 | Updated Sep 15, 2017


Detected by Microsoft Defender Antivirus

Aliases: Worm/Autoit.UY (AVG) Worm.AutoRun.DGM (BitDefender) Win32/SillyAutorun.GD (CA) Worm.Autorun-853 (Clam AV) Win32/AutoRun.KK (ESET) Worm.Win32.AutoRun.dbi (Kaspersky) AutoRun.CJQ (Norman) W32.SillyDC (Symantec) Trojan-Spy.Win32.Agent.bbq (other)


Worm:Win32/Ahkarun.A is an AutoHotKey compiled script worm that spreads through removable drives and send the user's IP address to a remote server.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner ( For more information, see
Follow us