
As this is the worm that auto-executes and comes from different means we may need to be cautious while clicking on any link on the internet and in instant messaging.
Removal Steps:
Disable System Restore
Use process explorer to find the files loaded by WORM_SOHAND.MY that are running as processes kill their processes.
Enable registry Editor, Task Manager, and Folder options
Delete the registry value
HKEY_CURRENT_USER>Software>Microsoft>Windows>CurrentVersion>Run
...