Worm.Nhatq is a computer infection that is classified as worm so it means that it does not infect system files, but it can replicate and spread on its own accord. The best indicator of the infection is the process file that appears in Task Manager once Worm.Nhtaq settles in your system. The file is called rvhost.exe and it is added into the registry together with a new value “Yahoo Messengger”. Please note the typo in the new value added by Worm.Nhtaq. It obviously tries to camouflage itself under a familiar name although keen users will notice the fraud immediately. It also goes without saying that Worm.Nhtaq is configured to run automatically with the Windows system once the computer is turned on.
Usually this worm spreads through logical and removable drives. The most common symptom of the infection is the inability to load Task Manager, not to mention that Worm.Nhtaq also changes a few system settings. It orders the system to run the malicious file every day at 9am. After that the worm connects to the Internet without your permission in order to download configuration data files from nhatquanglan2.0catch.com.
Like most of the worms, in order spread itself Worm.Nhtaq drops a copy of itself into a removable drive under a title of “newfolder.exe”. The user needs to run the file only once by accident and it installs the worm into the system. Apart from disabling the Task Manager Worm.Nhtaq can also tamper with the Folder options settings, so even though it does not damage the system files directly, it can cause turmoil that is hard to take care of, especially if the worm is allowed to stay in the system for a longer period of time.
Thus, you need to remove Worm.Nhatq from your computer before it is too late. Although some experienced computer users prefer deleting malware on their own, you are not advised to do so if you have limited knowledge in computers. It would be a lot better and faster to terminate Worm.Nhatq using a trustworthy antimalware application, because that way you would also protect your machine from similar future infections.
- Block exe files from running
- Connects to the internet without permission
- Installs itself without permissions
- Slow Computer
- Slow internet connection
- System crashes