Virus Alert – RVHOST.EXE
Rvhost.exe and ntt0509.exe will be found in your Windows and Windows\System or System32 folder. You may see these files described as 'Yahoo Messenger". In reality, these files install with the W32/SillyFDC-G worm. This worm sets itself to run on system startup and may also appear in your Scheduled tasks. It may try to download other unwanted files. You'll find more information at http://www.sophos.com/security/analyses/w32sillyfdcg.html.
We'd recommend removing these files using WinPatrol. First, kill them under Active Tasks then remove them from your Startup Programs and scheduled tasks (if present). If running WinPatrol 8.x or later; right click each file then select "Delete file on reboot". Finally, reboot your system.
Virus
Remove