I found some info at the Kaspersky forum:
delete the subkeys of this key in the registry and reboot: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
this should take care of the autorun problem
have you restored task manager, run, folder options & command prompt, that worm should also disable those
Info about it:
W32/Hakaglan.worm is a worm written in AutoIT that spreads via Yahoo Messenger, removable drives and network sharesAliases IM-Worm.Win32.Sohanad.t (Kaspersky) W32.Yautoit (Symantec) W32/Sohana-R (Sophos) Win32/YahLover.AO (CA) Worm/Sohanad.NAK (Avira...
my pc is infected by IM-Worm.Win32.Sohanad.t, though my zonealarm internet security suite is running and real time scanning is enabled for both virus and spyware. it comes from my pen drive. each time i scan my pc with the antivirus, it detects the virus is loaded into ram and sets a flag "delete on reboot." but actually the file is not deleted even though i reboot my system. after infection the virus disabled task manager, msconfig and regedit.
how can i get ride of this virus? please help.