From the Trend Micro link above....
quote:
Using REGEDIT.EXE, locate the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run\bymer.scanner = %virus path and filename%
Where %virus path and filename% is the complete path of the Trojan.
Note the %virus path and filename%.
Reboot in MS-DOS mode.
Delete the file where the name is specified by %virus path and filename%.
Reboot.
Remove reference to the Trojan file in the system registry.