Alias:W32.Aphex@mm, Bloodhound.VBS.Worm, I-Worm.Aphex,
Size:319,488 Bytes, variable. 
Damage:Spreads over Outlook Express, Mirc, Xirc, AIM, MSN, WebServer. 
DistributionThe email sent has the following structure:
From: the name of the infected computer.
The subject and body contain only ".".
Attachment: psecure20x-cgi-install.version6.01.bin.hx.com

Technical DetailsThe worm is a mass mailer, which spreads using its own webserver on port 8180.
When activated, the worm creates a VBScript in C:\%SystemDir%\Email.vbs.
This file is sent to all addresses found in Windows Address Book. Then the worm closes Outlook Express and deletes the file.
It copies itself in C:\%SystemDIR%, usually as -psecure20x-cgi-install6.01.bin.hx.com
It also makes the following registry entries, for automatic start:
-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Explorer ="%SystemDIR%\[filename]" -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ResourceMonitor = "%SystemDIR%\[filename]"
