Red circle with white cross in taskbar tray - saying 'Your computer is infected'


My computer was infected a while ago with Spysheriff and I got rid of it. But I discovered a red circle with a white cross in my taskbar. When I move my mouse over it, it says 'Your computer is infected':


This one is easy to get rid off.
  1. Open the task manager (press Control+Alt+Del)
  2. Select Processes and look for a process named 13242.exe or similar (a pattern of numbers) and kill this process.
    Look for a process named Archive.exe and kill it as well.
    Note that the name of this other program may be different in your case - a known other name is tool2.exe .

  3. Search your hard disk for the file name 13242.exe (or whatever number it may have been in your case). In my case this was in:
    \Documents and Settings\user1\Lokale Einstellungen\Temp
    Other users reported to have found these files in c:\Windows.

    As you can see in the screenshot, I found a LOT of executable files there, most of them the length 0. I could not delete those files until I had killed process 'Archive.exe'.

    The file archive.exe was entered as an auto-start in the registry here:

    I deleted the file Archive.exe from C:\Program Files\Archive:

     Directory of C:\Program Files\Archive
    11/24/2004  04:21p      <DIR>          .
    11/24/2004  04:21p      <DIR>          ..
    11/24/2004  04:21p             106,496 archive.exe
                   1 File(s)        106,496 bytes
                   2 Dir(s)   3,235,689,984 bytes free

2006-11-12, 07:57:16
anonymous from United States  
I had both the n.exe and winstall in my task manager. deleted them and the x went away. then found that it came back when i rebooted. found a file called winstall on my C: drive. deleted it. problem solved
2006-11-18, 09:25:40
anonymous from United States  
Hi could anyone please help a total tecnophobe with the same problem. I have downloaded the main spyware programs I think and have run all of them. Here is my Hijack This log

2006-11-30, 20:04:09
zach from United States  
Just go to and download the windows defender, and run a full system scan and it will take the spyware, and the annoying circle with the white x off.
2006-12-21, 11:01:29
anonymous from United States  
winstall.exe was definately it. i deleted it and computer back to normal, tnks a 1000
2007-01-22, 08:19:41
anonymous from France  
I have the same problem but I do not see any file of the sort mentioned above
2007-01-23, 03:07:06   (updated: 2007-01-23, 03:07:50)
anonymous from Belgium  
Got the same.
With me it was the file ctpmon.exe and it was loaded twice (seen in TaskManager). When you 'End the task' of one, the other will load another version of it. That way, you don't manage to close it. Though I managed to do it so quickly, bothaof them after eachother, that once it worked and I could delete the file from windows\system32 too then (which I couldn't before).
Good luck :-)
2007-01-23, 03:25:58
anonymous from France  
Yes, It was ctpmon.exe. Now it is gone. Thanks
2007-01-27, 04:55:01
anonymous from Thailand  
GREAT!! I had the ctpmon.exe extension and it was quite a nimble finger-moving procedure to get rid of it. Like the Belgian said above, you have to delete both files under the ctl/alt/delete list. AND then delete the same file under the system 32 folder. I almost gave up when I decided to move the file from the sys 32 folder to my desktop and get it ready for deletion with only the 'yes' button needed to be pushed......... then, QUICKLY delete the two ctpmon (NOT the ctfmon!!!) and then hit 'yes' for the sys32 file.......if you do it quick enough, it works!! Thanks!
2007-02-02, 20:17:40
Thanks guys, it was that ctpmom.exe here also. That thing was very irritating, and im glad its gone! Once again, this was a very good thread and well, now i can get back to Guild Wars. Thanks
2007-02-04, 19:33:30
anonymous from United States  
thanks zach defender system scan did the job this really truley works
2007-02-11, 13:50:54
I had the white x in the red circle, and the program 'Winstall.exe' in my root folder (C;)
Using msconfig to stop startup of winstall allowed me to reboot and delete winstall.exe.
switch back to normal startup with msconfig, and no more trouble. Thanks for the help.

p.s. Hindsight :: porn sites are BAD =D
2007-06-02, 07:47:43
misseng from United States  
Oh that was genius. It worked and I didn't have to purchase new virus software.
It deleted bikini and ctfmon off window task manager and my system 32 folder and that got rid of the annoy red circle with the X. It was driving me nuts. thank you!
2007-07-10, 00:21:50
anonymous from United States  
i get a pop up window that says:application error, exception GIFException in module avi and i get two pop ups at a time about every 4 to 6 minutes.pls help im not comp. expert. thanks a lot
2007-08-13, 18:37:11
i cant get on to task manager... what else can yoou do...?!
2007-08-14, 14:30:32
anonymous from United States  
Thanks for all the good information here. What a bunch of great people. . Zep

photo Add a picture: