Had situation on Grandson's machine earlier today with spybot showing virtumonde on nppbho.dll. File was in C:\ProgFiles\Syman..Shared\coshared\browser\1.0\ directory with 2006 date and same date on parent directory. Properties showed signature from Symantec same as the other files in the directory along with same dates.

Right clicking the file in explorer and selecting the "check with Spybot" resulted in a negative on malware and a positive on heuristics.

I am assuming this is a false hit - but... two questions...

1. Any way to disable heuristics? help file did not even contain the word.

2. Would like to confirm the file is clean.

p.s. Disabling the file resulted in a machine that took over 20 mins to boot and 10-20 seconds between key/mouse strokes. Finally got it reactivated after 2 hours of waiting. This is the first false hit that resulted in a problem I have ever had with Spybot in more than a few years working on many computers. The Main "check for problems" screen gave no indication that it was only a heuristics hit and I came very close to toasting the O/S believing the file was malware.