SpyBot detected the Virtumonde trojan and eliminated the offspring files. But it kept being alive.
I got suspicious about a file named qoMffGab.dll in C:\Windows\system32, which could not be renamed nor deleted in the normal way.
Eventually in WinXP Pro (SP2) Safe mode, this file could be deleted (in command line window!) and as a result the infection was over.
This might be helpfull for you.
Martin