This worm is partially encrypted with a simple encryption.
When it is executed, it first creates to the Windows directory a file
named "3k.exe". This file is a backdoor detected by FSAV as
Psychward.G.
Then the worm executes the backdoor.
Next the script uses Outlook to send itself to every recipient listed
in each address book. The message looks as follows:
Subject: New Year !
Body: Wow Happy New Year!
Attachment: happynewyear.txt.vbs
The attachment might be named differently.
VBS/Tqll.A uses the BCC area of the mail to send, so the receiver does
not see other recipients.
[Analysis: Katrin Tocheva and Sami Rautiainen, F-Secure; December 2000]