This worm virus spreads via the Internet being attached to infected emails as files: netbiospatch10.exe or secpatch10.exe
The worm then displays a fake error message:
Couldn't execute frame buffer!
To send infected messages the worm gets email addresses from WAB database and connects to default SMTP server.
The worm also sends notification message with empty body to its author:
Subject: Slave Message
Please, go to the key in the system registry: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
and delete the value: netpatch = netbiospatch10.exe or secpatch = secpatch10.exe (depending from version of virus)