Amirecivel.h, also known as Amircivil.h, is a worm that spreads by e-mail through messages with infected attachments, and via file sharing networks using popular peer-to-peer clients. Once executed, the parasite installs itself to the system and runs a spreading routine. Amirecivel.h searches local hard drives for text and web files and gathers e-mail addresses from them. Then it sends a malicious letter to each of those addresses. It also creates multiple copies of itself and shares infected files with users of file sharing networks. Amirecivel.h terminates running office applications, antiviruses, firewalls, and other security-related programs. It also blocks access to popular Internet search engines, security web sites and some other resources. Furthermore, the worm may open a back door providing the attacker with unauthorized remote access to the compromised computer. Amirecivel.h runs on every Windows startup. It requires Microsoft .NET Framework 2.0 in order to work as intended.