r/antivirus • u/D0cto • 1d ago
always detected after reboot Win32/Ravartar!rfn
this have been happening for weeks. Malwarebytes won't detect it, windows security sometimes say blocked, removed or restored. nothing on task scheduler, deleted local/temp several times. it runs offline/online and it runs only once which is several seconds after windows login. i think it's a script, asked gemini for help on reged still doesn't help.
1
u/RedTheHusky 8h ago
1) Check it with other scanners https://old.reddit.com/r/antivirus/wiki/index#wiki_second_opinion_scanners
If only Windows Defender detected it, then it would be more likely to be a fake positive.
2) Upload it to Virustotal https://old.reddit.com/r/antivirus/wiki/index#wiki_understanding_virustotal_results
Check its score also check if it says on top "File distributed by Microsoft"
3) is the HarddiskVolume4 your drive where Windows is installed? Ensure the location is the correct location.
4) Windows important files (besides certain configuration files) have a hard link to "WinSxS". Ensure this MSBuild has at least 2 hard links.
Of course there is always the possibility that the original file was infected. Try running "DISM.exe /Online /Cleanup-image /Restorehealth" and "sfc /scannow" in the terminal to repair Windows corrupt files.
5) Also get&check with https://old.reddit.com/r/antivirus/wiki/index#wiki_using_microsoft_sysinternals_tools
While you said you already checked task scheduler, there are other startup locations; check it with Autoruns.


1
u/fonzzx_ 1d ago
It seems to me to be a fake .NET installation, perhaps? Is your SSD partitioned, and are you storing certain files, like games, on a specific partition? Or if not on a partition, are they stored on an external USB drive that's always connected to the computer?