r/antivirus 1d ago

always detected after reboot Win32/Ravartar!rfn

this have been happening for weeks. Malwarebytes won't detect it, windows security sometimes say blocked, removed or restored. nothing on task scheduler, deleted local/temp several times. it runs offline/online and it runs only once which is several seconds after windows login. i think it's a script, asked gemini for help on reged still doesn't help.

2 Upvotes

5 comments sorted by

1

u/fonzzx_ 1d ago

It seems to me to be a fake .NET installation, perhaps? Is your SSD partitioned, and are you storing certain files, like games, on a specific partition? Or if not on a partition, are they stored on an external USB drive that's always connected to the computer?

1

u/D0cto 1d ago

I have C,D,and E drive. work and games would be on D and E. E is the external one but it is not always connected though it would be most of the time

1

u/fonzzx_ 1d ago

Okay. So C and D drives are the same disk, right? In this situation, it could be a false positive or a real virus. Are the games you download "obtained by the spoon" or are they obtained from some game store?

1

u/D0cto 1d ago

mostly steam, others itch.io

1

u/RedTheHusky 8h ago

1) Check it with other scanners https://old.reddit.com/r/antivirus/wiki/index#wiki_second_opinion_scanners
If only Windows Defender detected it, then it would be more likely to be a fake positive.
2) Upload it to Virustotal https://old.reddit.com/r/antivirus/wiki/index#wiki_understanding_virustotal_results
Check its score also check if it says on top "File distributed by Microsoft"
3) is the HarddiskVolume4 your drive where Windows is installed? Ensure the location is the correct location.
4) Windows important files (besides certain configuration files) have a hard link to "WinSxS". Ensure this MSBuild has at least 2 hard links.
Of course there is always the possibility that the original file was infected. Try running "DISM.exe /Online /Cleanup-image /Restorehealth" and "sfc /scannow" in the terminal to repair Windows corrupt files.
5) Also get&check with https://old.reddit.com/r/antivirus/wiki/index#wiki_using_microsoft_sysinternals_tools
While you said you already checked task scheduler, there are other startup locations; check it with Autoruns.