How to recognize fraudulent emails like "Business Proposal"
Phishing/ScamAlso Known As: Business Proposal advance-fee scam
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What kind of scam is "Business Proposal"?
Upon reviewing the email, we have determined that it is a fraudulent message masquerading as a business proposal. The scammers intend to entice recipients into participating in an advance-fee scheme. Furthermore, it is imperative to exercise caution and refrain from disclosing any information in response to such deceptive communications or sending money.

More about the "Business Proposal" scam email
The email begins with an attempt to establish credibility by claiming to be from a specific bank in South Africa. The sender alleges to have discovered an unclaimed sum of USD 16 million belonging to a deceased client who supposedly passed away during the COVID-19 pandemic. They propose that the recipient pose as the deceased client's next of kin in order to facilitate the release of the funds.
The promise of a 50% share of the funds is used as bait to entice the recipient into participating in the scam. The urgency of the matter and the request for confidentiality are common tactics employed to pressure the victim into responding quickly without seeking verification or advice.
Finally, the email provides a contact email address for further communication, indicating a desire to move the scam into a more private setting. Overall, the email is designed to manipulate the recipient into providing personal and financial information or making payments upfront, with the false promise of a lucrative reward.
Recovery of lost funds can be extremely difficult, if not impossible, and victims may also become targets for future scams as their information is circulated within criminal networks. Falling for such scams can have devastating consequences for victims, impacting their financial stability and sense of security.
| Name | Business Proposal Email Scam |
| Threat Type | Phishing, Scam, Social Engineering, Fraud |
| Fake Claim | Recipients are promised a significant sum of money in exchange for their assistance |
| Disguise | Letter from a person named Ibrahim Mustafa regarding a business proposal |
| Symptoms | Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer. |
| Distribution methods | Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains. |
| Damage | Loss of sensitive private information, monetary loss, identity theft. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Similar scams in general
Emails of this kind typically have an urgent or enticing subject line, aiming to grab the recipient's attention. The body of the email usually contains a fabricated story or proposal, often involving a large sum of money and a sense of urgency. Scammers frequently request personal or financial information and emphasize the need for confidentiality.
Grammatical errors, spelling mistakes, and inconsistencies in language or formatting are other common indicators of fraudulent activity. These emails exploit human vulnerabilities such as greed, curiosity, and urgency to deceive recipients into providing sensitive information or making payments.
Examples of similar scams are "Western Union Money Transfer", "Publishers Clearing House", and "Scam Relief Fund Initiative". It is important to be aware that cybercriminals often employ email as a tool to trick users into infecting their computers.
How do spam campaigns infect computers?
Cybercriminals behind emails intended to deliver malware aim to lure recipients into causing computer infections through malicious attachments or links. These attachments, such as documents or images, may appear harmless but contain malware and infect systems once opened.
Similarly, clicking on links within the email can lead users to fake websites or download pages that distribute malware onto their devices. Not every file received via email can infect computers upon opening. Certain files may necessitate further actions from users to trigger the embedded malware.
For instance, malicious MS Office documents cannot introduce malware unless users enable macros commands. Some examples of types of files used to distribute malware are executable files (.exe), script files (.js or .vbs), document files (.docx or .pdf), compressed files (.zip or .rar), and shortcut files (.lnk).
How to avoid installation of malware?
Exercise caution when encountering links or attachments from unknown addresses, particularly if emails appear unexpected or irrelevant. Obtain files and applications from reputable sources such as official websites or trusted app stores. Avoid clicking on dubious links, pop-ups, or ads.
Regularly update your software and operating system to mitigate potential vulnerabilities. Refrain from downloading pirated software or using cracking tools to activate software. Employ dependable antivirus or anti-malware software as an added layer of protection.
If you have already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.
Text presented in the "Business Proposal" email letter:
Subject: Urgent Business Proposal.
Below is My Business Proposal to you.
I will like to discuss this business with you and it has nothing to do with someone in my country, only someone outside South Africa can handle this deal. i got your contact details from when I was searching for a friend Information On-line Service on my personal programmed search on the internet for an individual to assist with sincerely & confidential which your information & profiles were very satisfactory, so I decided to contact you immediately. It is my great pleasure to write you this letter.
Within the bank where I work as an account officer, I want to tell you that I work with Absa bank of South Africa, And here in our bank I discovered that a customer deposited the sum of USD16 Million Dollars in our bank On my finding out i discovered that he passed away on the covid-19 Pandemic and since then none of his relative came for the funds claim and I don’t think anyone knows about this funds only me that is his account officer knows about it.
So I am writing to you as I will want you to stand as his next of kin so that the funds will be released to you. It is pure deal transaction between me and you. I am seeking your assistance to front as the next of kin to the unclaimed deceased funds
I have to propose that should you be willing to assist me in this transaction your share as compensation will be (50%) and I will then take (50%) .
The business is completely safe and secure provided you treat it with Utmost confidentiality.
Your urgent response is needed.
Please kindly contact me back on my private email:
ibrahimmustafa6655@gmail.com
Thanks best regards
Mr. Ibrahim Mustafa
Other examples of business proposal-themed spam emails:
Sample 1:

Text presented within:
Subject: Business Proposal
Hello. I hope that this email finds you and your family in good health.
I know we are unfamiliar with each other but it takes a day for people
to know each other. I would like to propose a legitimate business to you and please take this seriously. I am proposing a deal that will make us richer and you are very important to this deal as you will find out. I am a Senior Accountant with WesBanco. I have worked here for a little more than 12 years now in a vital position at my bank. I was the
personal accountant to one Engineer (Nicolas Otto), a corporate
contractor who has an investment account with my bank.Unfortunately, my client died along with his nuclear family in France
while on a family vacation in the summer of 2008, may their soul rest in peace. He died without leaving a will. Several efforts were made to find his extended family through your embassy without success. I received a notice last week to provide the next of kin of being his accountant or the account risk being transferred to the government (es-cheat) in 21 days. I am contacting you to assist me in repatriating the funds left behind by my late client since you both share the same last name.This claim will be executed without breaching US laws, and success is
guaranteed if we cooperate. The bank will release the account to you
because of your last name and my recommendation of you as the next of
kin. I am a very religious person, and I cannot lie, and I expect the
same from you. If interested, I will tell you what to do as time goes on when I get your response. The amount involved is $12,649,400(USD). I
propose we share the proceeds 50:50; I think this is fair. I will give
you all the necessary information about this deal when I get your
response. I look forward to working with you. Treat this proposal with
utmost confidentiality and urgency for 100% success.If you are not interested, please delete this message and you will never hear from me again.
God bless you.
Best Regards
Craig Wagner
Sample 2:

Text presented within:
Greetings,
How are you? Please accept my apologies if my email does not meet your personal ethical standards. I would like to introduce myself and this business opportunity to you.
My name is Barrister Sergen Ecesoy of Integrity Law Firm London, I am the personal lawyer of my deceased client who bears the same surname as you.
I am contacting you regarding an unclaimed financial inheritance claim related to your surname. I want to know if we can work together as a team.
I want you to act as the next of kin of my deceased client who has an account worth $40.7 Million USD at a financial institution.
My deceased client died without any registered next of kin and therefore the funds now have an open beneficiary mandate. The board of his bank passed a resolution and I have been mandated to nominate his next of kin to pay this fund or the fund will be forfeited to the bank as unclaimed property.
Fortunately, since you share the same surname as my deceased client, it will be very easy for me to make you his official next of kin.
If you are interested, please let me know so I can give you full details on what we are to do.
Thanks,
Best Regards,
Barrister Sergen Ecesoy
180 Tottenham Court Road London, W1T 7PD.United Kingdom
The Law is Our Business.
Sample 3:

Text presented within:
Subject: 2025 BUSINESS PROPOSAL FOR YOU
Hi,I am Philip Roger, I work as a research director at reputable company in United Kingdom.
I would like to share with you some business insights/business proposal which will yield profit this 2025.
Please Kindly reply me on my email below.
Note: You have the right to quit by the end of my detailed explanation if you don't feel like moving forward with my proposal. But Trust me, you won't regret it.
Best Regards
Phil Roger
philip.r@med-pharmaceutical.com
Sample 4:

Text presented within:
Subject: My Proposal
Good Day,How are you doing today? My name is Walsh Philip, I live in the United Kingdom and work with NatWest Bank UK.
I am glad to be connected with you. I have a business proposal I would like to discuss with you in private. It involves a business opportunity that will be of huge financial benefit to both of us.
Further details will be shared after I receive your response.Kindly reply (wphilip@natwbkuk.com ) with your full name and your country of Origin/residence.
Yours Truly,
Walsh Philip.
Operational Manager.
Sample 5:

Text presented within:
Subject: INQUIRY - PARTNERSHIP
Dear Sir/Madam
Thank you for taking your time to read this Proposal.
I am a Pharmacovigilance Specialist in a leading pharmaceutical company. I am contacting you
to explore a potential business opportunity. This genuine business could be
mutually beneficial to you. I need your assistance in the supplying of Raw
Material to our company. We will be making a profit of $750,000 or more every
two months from our company.This may not be your area of specialization, but it will be another income generating
business out of your specialty.I can provide further details once I receive your response.
Best regards,
Ms. Singh
Pharmacovigilance Specialist
contact@singhz-mail.com
Sample 6:

Text presented within:
Subject: MedPharma Business Proposal
Greetings,
MedPharma Business Proposal
Dear Sir/Madam
I work with one of the leading Laboratories here in the UK as a Senior consultant.
Our company is one of the UK's most respected indigenous multi-million pound pharma companies,manufacturing over hundreds of various life saving bio pharmaceutical products and medical consumables.
I have a business proposal that would interest you,and I shall explain in detail if I get a response from you in this regard.
Feel free to message me through my official email address: purchase@medpharmarceutical.com
Note: You have the right to quit by the end of my detailed explanation if you don't feel like moving forward with me. But Trust me, you won't regret it.
Regards
Joe Allen
Sample 7:
Text presented within:
Subject: Confidential Opportunity Private Business Matter
Urgent and Confidential Business Proposal
Dear -
I hope this message finds you in good health and spirits. My name is Bharat Masrani, and I am an Account Manager at Finx Trust Bank, headquartered in Canada. I am contacting you regarding a sensitive and confidential matter that offers a significant opportunity for mutual benefit, requiring your immediate attention.
In 2008, a valued client of our bank, who shares your last name and is associated with your country, deposited US$38,000,000 (thirty-eight million U.S. dollars) into a fixed-term account. Regrettably, this client perished in the catastrophic earthquake that struck Indonesia in September 2009. Despite extensive efforts following the deposit's maturity on September 22, 2010, we have been unable to contact the account holder or any listed relatives, leaving the funds unclaimed.
Under banking regulations, unclaimed funds are at risk of being transferred to the state if no legitimate claimant is identified. After thorough consideration, I am proposing a discreet partnership with you to act as the next of kin to the deceased, utilizing the shared last name to facilitate this process. Should you agree to collaborate, the funds will be distributed as follows:
60% (US$22,800,000) allocated to you.
40% (US$15,200,000) retained by me to cover facilitation and administrative costs.
I have taken preliminary measures to ensure this process is smooth, secure, and fully compliant with banking protocols. Upon receiving your consent, I will update our internal records, enabling the transfer of funds to your designated account within approximately one week.
I recognize the importance of trust in such a significant proposal. I am fully prepared to address any questions or concerns you may have to ensure your confidence in this arrangement. The potential benefits of this opportunity are substantial, and I urge you to consider it carefully.
To proceed or seek further clarification, please contact me directly at my personal email: bharatmasrani51@mail.com
For reasons of security and confidentiality, I kindly request your response within five business days.
Thank you for your time and careful consideration. I look forward to your prompt reply and the prospect of working together on this exceptional opportunity.
Sincerely,
Bharat Masrani
Account Manager
Finx Trust Bank, Canada
Sample 8:

Text presented within:
Subject: I WILL NEED YOUR URGENT SUPPORT AND ASSISTANCE.
Attn: My Friend
First of all, let me introduce myself to you. I am Tony Maxwell, working with CAIXA BANK, here in Madrid - Spain. I have a confidential business proposal I want to present to you. I am contacting you in regards to a deceased client of our bank who had a ghastly accident in Mainland China on March 12TH, 2019. He was an expatriate engineer who worked in Spain for Twenty years.
Before His death, he deposited the sum of (US$22, 500,000.00), Twenty-Two Million, Five Hundred Thousand United States Dollars here in our bank vault. Documentations show that these funds can only be claimed by his next of kin/relative. Unfortunately, he died without leaving any will or outstanding instructions regarding this deposit before his death.
We have carried out several efforts to locate any family member, but this has been futile. However, because of the International Financial problems here in Spain, a lot of reforms have been made within the Spanish Financial system. This includes the new law on succession claims which indicates a duration in which such inheritance could be tolerated. For this reason, I searched for you and decided to contact you and present you as the next of kin to the deceased customer.
I have put in place all necessary documentation concerning the release of this deposit and it is my intention to introduce this opportunity to you based on the fact that you can assist with the transfer and investment plans of my share of the funds. Since nobody is coming for this deposit and I am one hundred percent sure this is no known relative. I have all the proper documentation to instill you as the next of kin. All I require is your honest cooperation to enable us to achieve this transaction.
Upon your acceptance to cooperate, I want you to know that 40% of this deposited fund will be yours as our foreign partner, while 60% will be for me and my partner here in the office.
If you are interested, please contact me via email: ( ttonymaxwell@gmail.com )
Upon your response, I shall then provide you with more details and relevant documents that will help you understand this transaction properly.
However, if this business proposal offends your moral ethics, do accept my sincere apology, or if on the contrary, you wish to achieve this goal with me, kindly get back to me with your interest for further explanations.
Kindest Regards,
Tony Maxwell.
Sample 9:

Text presented within:
Subject: BUSINESS PROPOSAL
Hello dear friend,
I have been in search of someone with this information, so when Isaw your profile through my search on the internet I decided toadd you and write to you this message to see how best we canassist each other. I am Mrs. Nazan Baykara, a Bank Officer herein Istanbul Turkey with Turkey Vakifbank ( TÜRKİYE VAKIF BANKASI
). I am the Audit Manager / Chief Analyst, Asset Management ofthe Vakifbank. First, I want to thank you for this opportunity toshare this proposal with you. I believe it is the wish of God forme to come across your email. I am having an important businessdiscussion I wish to share with you which I believe will interestyou because it is in connection with your last name/nationalityand you are going to benefit from it.I am writing to you concerning a man named Allen, who is acitizen of your country. He owns a gold mining company here inTurkey and is also one of the biggest shareholders in our bank,Vakifbank, Istanbul Turkey. On the 2nd of February 2015, Mr.Allen had a Fixed deposit private account in our bank anddeposited the sum of $15,500,000.00 (Fifteen Million Five HundredThousand United States Dollars) into the account for the purposeof establishing a car manufacturing company there in yourcountry. The due date for this deposit was last year. SadlyAllen was among the death victims in the recent EARTHQUAKEoutbreak that happened on the 6th of February 2023 here inTurkey.
My bank management is yet to know about his death, I knew aboutthis because I was his personal account officer and also as theAudit / Asset Manager of the bank, every transaction of such mustbe confirmed by my office to be completed. He did not mention anyNext of Kin/Heir when the account was opened, He was a widower,His wife was late, they had no child and he didn't mention anyrelatives as a successor. Last week my Bank Management had ameeting for a bank verification exercise to note dormant andabandoned deposit accounts. I knew this would happen, that waswhy I have been looking for a means to handle the situationbefore my bank board of directors got the news of his death. Insuch a case, if they find out about his death, the fund will bedeclared unclaimed, and request for the money to be shared amongthem which I can't stop and I don't want such to happen. That waswhy when I saw your details, I was happy.
I am seeking your cooperation to present you as the Next ofKin/Heir to the account since you have the same last name and thesame nationality as Mr. Allen. My bank headquarters will releasethe account to you through my help, There is no risk involved,the transaction will be executed under a legitimate arrangementthat will protect you from any breach of law. It is better thatwe claim the money than allowing the Bank Directors to share itamong themselves. I'm not a greedy person, Therefore, I amsuggesting we share the funds 50/50% for you and me respectively.I hope the sharing is fair, and my own share of the money willassist me to start my new investment plan. Let me know youropinion on this and please do treat this information asconfidential. I shall give you more details once I receive yoururgent response through my private email address below.
Email: nazanbaykara0@gmail.com
Best RegardsMrs. Nazan Baykara.
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Types of malicious emails:
If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.
Credential theft Phishing emails
Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.
Common subject lines
- "Action required: confirm your account"
- "Your password expires today"
- "Unusual sign-in attempt detected"
- "Verify your billing information"
Malware delivery Emails with malicious attachments
Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.
Common subject lines
- "Invoice INV-2026-XXXX attached"
- "Fax received - 3 pages"
- "Your shipping document is ready"
- "Voicemail from +1-XXX-XXX-XXXX"
Extortion Sextortion emails
Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.
Common subject lines
- "I know your password is XXXX"
- "Your account has been hacked"
- "I have recorded you - 48 hours to pay"
- "You have been compromised"
Callback fraud Refund & callback scams
"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.
Common subject lines
- "Norton subscription auto-renewed - $499.99"
- "McAfee Total Protection invoice"
- "Geek Squad order confirmation"
- "Your PayPal payment is being processed"
Credential theft Account suspension & verification scams
"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.
Common subject lines
- "Your account will be deleted in 24 hours"
- "Suspicious activity detected - verify now"
- "Final warning: account closure"
- "Action required to keep your account active"
Mixed payload Delivery & package scams
Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.
Common subject lines
- "Your DHL package is held at customs"
- "USPS - delivery attempt failed"
- "FedEx tracking update - action required"
- "Pay $2.99 redelivery fee to release your parcel"
Remote access Tech support scams
Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.
Common subject lines
- "Microsoft Defender expired - renew now"
- "Apple ID security alert"
- "Critical: virus detected on your PC"
- "Windows license expired - call now"
Wire fraud Advance-fee scams
Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.
Common subject lines
- "Inheritance from a relative you didn't know about"
- "You won the international lottery"
- "URGENT - business proposal worth $XX million"
- "Compensation fund release for fraud victims"
Wire fraud Business email compromise (BEC)
CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.
Common subject lines
- "Quick task - need you to buy gift cards"
- "Updated banking details for invoice payment"
- "Wire transfer request - urgent"
- "Are you available?" (CEO impersonation opener)
How to spot a malicious email?
Check the sender's actual address, not the display name
The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:
- Domain mismatch -
service@paypa1.com,support@micros0ft-help.com, look-alike domains using digits or extra hyphens - Free-email impersonation - any "official" message from a bank, courier, or platform sent from a
@gmail.com,@outlook.com, or@yahoo.comaddress - Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.
Watch for urgency, threats, and generic greetings
Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:
- "Your account will be deleted in 24 hours"
- "Final notice" / "Immediate action required"
- "Dear Customer" or "Dear User" instead of your real name
- Threats of fines, account closure, legal action, or arrest
- Promises of refunds, prizes, or money you didn't earn
- Spelling and grammar mistakes in messages claiming to come from a major brand
Hover over every link before clicking
On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.
- Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
- Shortened URLs (
bit.ly,tinyurl,t.co) hide the real destination - never click them in unsolicited mail - The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.
Treat unexpected attachments as hostile
If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:
.exe,.scr,.iso,.img,.vbs,.bat- executables, never legitimate attachments.docx,.xlsx,.pptxwith "Enable macros" prompts - the macros run the malware.pdfwith "Click here to view" buttons - usually a phishing redirect, not a real document.zip,.rar,.7zarchives, especially password-protected ones - the password defeats the email scanner
If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.
Don't reply, don't click "unsubscribe"
Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.
Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.
Report the scam to your email provider and authorities
Inside your email client:
- Gmail: open the message → ⋮ menu → Report phishing
- Outlook / Outlook.com: ⋯ menu → Report → Report phishing
- Apple Mail / iCloud: Move to Junk, then forward to
reportphishing@apple.com
Forward or report to authorities:
After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.
Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.
You only clicked a link (didn't enter anything or download anything)
Close the page right away. Don't enter any information, even if the page looks legitimate.
- Clear your browser cache and cookies for the last hour - → Last hour → check Cookies and Cached files
- Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
- Update your browser to the latest version - most drive-by exploits target outdated browsers
- Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.
You opened an attachment or downloaded a file - run a full malware scan
Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:
Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.
Windows 11: → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.
Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.
Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.
Reboot to normal Windows. Open . Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.
VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.
Download Combo CleanerInstall Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.
Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.
Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:
Chrome: chrome://settings/reset → Restore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.
Edge: edge://settings/reset. Then edge://settings/content/notifications.
Firefox: about:support → Refresh Firefox.
Open and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run and update browsers and applications.
If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).
You entered credentials on a fake login page
Assume the attacker has your password and is using it right now. Speed matters.
- Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
- Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
- Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
- Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
- Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
- Update security questions - the attacker may have seen the answers in your account profile.
If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.
You sent money or shared bank, card, or ID details
Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.
- Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
- If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
- If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
- File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
- File with the right authority for your country:
- US: ic3.gov + reportfraud.ftc.gov
- UK: reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
- Canada: antifraudcentre.ca
- Australia: scamwatch.gov.au
- EU: your national CERT or police cybercrime unit
- Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
- Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Final scan and startup-app check
Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.
Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.
Monitor accounts and credit for 30 days
Most fraud follow-ups land in the first month. Until that window closes, keep watching:
- Bank and card statements - daily for the first week, then weekly
- Email - watch for password-reset confirmations or login alerts you didn't trigger
- Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
- Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks
If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.
Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.
Frequently Asked Questions (FAQ)
Why did I receive this email?
Phishing attacks typically entail the mass distribution of emails to a wide array of recipients, with the aim of ensnaring unsuspecting individuals in the scam. These emails are often sent out indiscriminately, utilizing email addresses sourced from public platforms, leaked databases, or prior data breaches.
I have provided my personal information when tricked by this email, what should I do?
If you have shared banking or credit card details, notify your bank or credit card provider. For ID card disclosures, inform the local government agency handling identity theft. Also, mark the email as spam or phishing with your service provider.
I have downloaded and opened a malicious file attached to an email, is my computer infected?
The risk level differs based on the file type. For example, executing an executable file poses a significant risk of infection, while document files like .pdf or .doc are less likely to cause immediate harm.
I have sent cryptocurrency to the address presented in such email, can I get my money back?
Cryptocurrency transactions are fundamentally untraceable, rendering their reversal nearly impossible.
I have read the email but did not open the attachment, is my computer infected?
Simply opening an email does not pose a risk. However, clicking on links or opening attached files can lead to computer infections.
Will Combo Cleaner remove malware infections that were present in email attachment?
Combo Cleaner is capable of detecting and removing the majority of known malware infections. Advanced malware often hides deeply within the system. Therefore, conducting a thorough system scan is essential to eradicate hidden threats.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion