I am a new user and am running Spybot S&D v1.4 and it finds Virumonde in registry key:
HKLC\software\microsoft\mssmgr. It will clean out this key, then a minute later I get an SAV pop up and the key is re-created.
SAV pop message
Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Downloader
File: C:\Documents and Settings\Dan\Local Settings\Temporary Internet Files\Content.IE5\0V2FUL2P\text[1].dat
Location: Quarantine
Computer: THODES4
User: Dan
Action taken: Quarantine succeeded : Access denied
Date found: Monday, September 10, 2007 4:50:53 PM