See this bulletin from Microsoft for complete details:
As posted the Microsoft advisory, below is a concise, practical checklist that fills the gap between "read the bulletin" and actually protecting or recovering machines. These steps are deliberately general — they apply to Sober-family worms and other email-spreading executables — and avoid vendor-specific instructions the original post already links to.
Immediate steps to contain infection:
Cleaning and verification:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\...\Run) and the Hosts file for tampering. Prevention and follow-up:
Cautions: avoid manual registry edits unless confident, and when in doubt prefer restoring a clean image. The Microsoft advisory linked by is a useful technical reference — follow vendor removal tools and guidance where available.
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.