This worm propagates by dropping copies of itself in shared folders with Read or Read/Write access in the root and Windows directory. It uses file names that can trick users into thinking they are crack programs for certain software.It also attempts to modify the registry settings of popular file-sharing services.This worm also attempts to connect to an mIRC server to notify a remote user and listen for further commands.It runs on Windows 95, 98, ME, NT, 2000, and XP.