DOS/Rovnix.W is a malicious Volume Boot Record (VBR), which is loaded at boot time. It tries to tamper with some Windows kernel data to load its own malicious driver. This might bypass the Driver Signature Enforcement on a 64-bit system.
The malicious driver injects other malware components, for example Trojan:Win32/Claretore.L, into the explorer.exe process.
To hide its presence on your PC, the loaded driver intercepts the hard disk I/O (input/output) operation, and returns the original clean copy if the VBR is accessed.