SpyBot detected the Virtumonde trojan and eliminated the offspring files. But it kept being alive.
I got suspicious about a file named qoMffGab.dll in C:\Windows\system32, which could not be renamed nor deleted in the normal way.

Eventually in WinXP Pro (SP2) Safe mode, this file could be deleted (in command line window!) and as a result the infection was over.

This might be helpfull for you.

Martin