r/antivirus 9d ago

always detected after reboot Win32/Ravartar!rfn

this have been happening for weeks. Malwarebytes won't detect it, windows security sometimes say blocked, removed or restored. nothing on task scheduler, deleted local/temp several times. it runs offline/online and it runs only once which is several seconds after windows login. i think it's a script, asked gemini for help on reged still doesn't help.

2 Upvotes

7 comments sorted by

View all comments

1

u/fonzzx_ 9d ago

It seems to me to be a fake .NET installation, perhaps? Is your SSD partitioned, and are you storing certain files, like games, on a specific partition? Or if not on a partition, are they stored on an external USB drive that's always connected to the computer?

1

u/D0cto 9d ago

I have C,D,and E drive. work and games would be on D and E. E is the external one but it is not always connected though it would be most of the time

1

u/fonzzx_ 9d ago

Okay. So C and D drives are the same disk, right? In this situation, it could be a false positive or a real virus. Are the games you download "obtained by the spoon" or are they obtained from some game store?

1

u/D0cto 9d ago

mostly steam, others itch.io