I ran a SpyBot scan again to see if it does the same detection as before. It found Virtumonde.sdn. There is a registry key in HKLM. It is a trojan-VM-007 rule D5A89F9E. I can't let it delete it again obviously.