1. Did you confirm the detection was correct, by using either VirusTotal or Jotti, multi-engine AV scanners ?
2. If it is a correct detection by Norman cleanup, did you send a sample to avast so they can update the VPS ?
3. W32.Spybot.worm is different to what you quoted, there are many different aliases as there is no standard naming convention. So you would also need to confirm that although the names are different it is the same virus/malware.
Not only that but the worm detected by Norman cleanup is also different to that listed by Dwarden, so that would also indicate it is a different malware sample.
Norman 5.90.23 08.30.2006 W32/Spybot.AXEH