Avoid getting scammed by fake "Donation To Charity Through You" emails
Phishing/ScamAlso Known As: "Donation To Charity Through You" spam email
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What kind of email is "Donation To Charity Through You"?
After reading this "Donation To Charity Through You" email, we determined that it is spam. This letter seeks aid from the recipient in distributing the sender's funds to charity. Supposedly, the recipient will be rewarded monetarily for their help. This spam mail most likely seeks to trick victims into disclosing their personal information and/or sending scammers money.

"Donation To Charity Through You" email scam overview
The spam email with the subject "Re:Gods Favoure," (may vary) is presented as a missive from a wealthy woman who had recently become pious. Supposedly, this imaginary sender inherited an exorbitant amount of money from her deceased husband. However, the widow was diagnosed with cancer, and the prognosis is not too promising.
The sender was gripped with religious fervor and decided to give her funds to charities for orphans, windows, and the underprivileged. With her health deteriorating, she sought assistance in this task from her relatives – but they embezzled the money. Hence, she decided to look for aid online, and thus she found the recipient.
Through her lawyer, the widow wants to distribute 10.5 million USD to charity with the recipient's help; it is implied that they will receive a commission for their assistance.
It must be stressed that all the information in this email is false. Typically, mail of this kind promotes phishing scams or seeks funds directly.
In case of the former, scammers can ask recipients to disclose their personally identifiable details, such as name, sex, age, nationality, occupation, address, contact information, ID/passport copy, etc. Data of this kind can be used for a variety of nefarious purposes, including identity theft.
Alternatively, victims of this scam can be requested to provide finance-related information for transferral of the charity-bound funds. Scammers may then use such data to facilitate fraudulent transactions or online purchases.
In the latter cases, cyber criminals ask victims to send them money for legitimate-sounding reasons like paying taxes or fees. Funds are usually obtained using difficult-to-trace methods like cash hidden in packages and shipped, gift cards, pre-paid vouchers, cryptocurrencies, etc. These methods decrease the chances of successful prosecution and fund retrieval for victims.
In summary, by trusting an email like "Donation To Charity Through You" – users can experience severe privacy issues, financial losses, and identity theft.
If you have already provided your personally identifiable or finance-related information to scammers – immediately contact the appropriate authorities.
And if you've disclosed your log-in credentials (e.g., by entering them into a phishing website/file, etc.) – change the passwords of all potentially compromised accounts and inform their official support without delay.
| Name | "Donation To Charity Through You" spam email |
| Threat Type | Phishing, Scam, Social Engineering, Fraud |
| Fake Claim | Sender seeks recipient's aid in distributing 10.5 million USD to charity. |
| Symptoms | Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer. |
| Distribution methods | Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains. |
| Damage | Loss of sensitive private information, monetary loss, identity theft. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Spam campaigns in general
Spam campaigns are used to promote various scams, such as phishing, sextortion, tech support, advance fee, refund, inheritance, lottery, and so forth. Deceptive emails/messages are also used to proliferate all kinds of malware.
While the widely held belief that spam mail is poorly written and riddled with grammatical/spelling errors is not untrue, it is not always the case. These emails can be competently crafted and even convincingly disguised as messages from legitimate entities (e.g., companies, organizations, service providers, authorities, etc.).
"New Policy For Salary, Bonuses And Overtime", "Security Token For Business Email Is Outdated", "Unclaimed Insurance", "Personal And Digital Security Has Been Breached", "Mailbox Security Maintenance", "DHL - Customs Clearance", "Payment Details", and "Camelot Lottery Solutions" are just some of our newest articles on spam campaigns.
How do spam campaigns infect computers?
Malware is commonly distributed via spam campaigns. These emails/messages include malicious files as attachments or download links. Infectious files come in various formats, e.g., documents (Microsoft Office, Microsoft OneNote, PDF, etc.), archives (RAR, ZIP, etc.), executables (.exe, .run, etc.), JavaScript, and so on.
Malware download/installation is initiated once such a file is opened. However, some formats require additional actions to trigger infection processes. For example, Microsoft Office files need users to enable macro commands (i.e., editing/content), while OneNote documents require them to click embedded links or files.
How to avoid installation of malware?
We strongly recommend exercising caution with incoming emails, DMs/PMs, SMSes, and other messages. Attachments or links found in suspect/irrelevant mail must not be opened, as they can be harmful.
However, malware is not proliferated exclusively through spam mail. Therefore, we advise vigilance when browsing since the Internet is full of well-disguised deceptive and malicious content.
Additionally, all downloads must be performed from official and verified channels. Another recommendation is to activate and update programs using functions/tools provided by legitimate developers, as illegal activation ("cracking") tools and third-party updaters can contain malware.
It is paramount for device integrity and user safety to have a dependable anti-virus installed and kept updated. This software must be used to run regular system scans and to remove threats and issues. If you've already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.
Text presented in the "Donation To Charity Through You" spam email letter:
Subject: Re:Gods Favoure,
Hello Friends,
My name is Mrs Sarah Kinr. I am a dying woman who has decided to donate what I have to charity through you.
You may be wondering why I chose you, since I don't know you and we have never met before. But the truth is that "someone has to be chosen". Let it be known to you that I am a little bit apprehensive, but I have the understanding that friends are discovered and friends are made. I have come to accept the fact that I cannot achieve success in this Project without trusting someone. This brings us to the need for both of us to have absolute trust and believe in one another as we can only fail if we divide in interests. Let trust and Honesty be our watchword throughout this Project.
Though, this medium (the Internet) has been greatly abused, I choose to reach you through it because, it still remains the fastest, surest and most secured medium of communication. However, this correspondence is purely private & confidential, and it should be treated as such. I wish to inform you once again that this Project is absolutely legitimate and all the operations will be performed without the breach of any international law(s).
I am 56 years old and was diagnosed of cancer about 2 years ago immediately after the death of my husband who had left me everything he had worked for. I have been touched by the LORD to donate from what I have inherited from my late husband to charity through you for the good work of humanity, rather than allow my greedy relatives to use my late husband's hard earned funds inappropriately.
I have not particularly lived my life so well, as I never really cared for anyone. Though I married a very rich man, I was never generous, I was always hostile to people and only focused on myself as that was the only thing I cared for since I don't have any child. But now, I regret all this as I now know that there is more to life than just wanting to have all the money in the world. I have asked the lord to forgive me all my sins and I believe he has, because He is merciful. I will be going in for an operation very soon, and I pray that I survive the operation.
I believe that if I have a second chance to come to this world again, I would live my life a different way from how I have lived it. Now that I may not live longer, I want mercy to be shown on my soul, so I have decided to give alms to the poor & charity organizations and to help the motherless children & orphans, the less privileged, and also for the assistance of widows, as I want this to be one of the last good deeds I do on earth before I pass on. Now that my health has deteriorated so badly, I cannot do this myself anymore. I once asked members of my family to close one of my accounts and distribute the money which I have there to charity organizations in Indian, Sudan, Bulgaria and Pakistan; but they refused and kept the money to themselves. Hence, I do not trust them anymore, as they seem not to be contented with what I have left for them.
I have decided to Donate & give the sum of US$10.5 Million (Ten Million Five Hundred Thousand United States Dollars) to charity through you. Presently, I have informed my lawyer about my decision in WILLING this fund to charity through any God-fearing and reliable person. I wish you all the best and may the good Lord bless you abundantly, and please use the funds well and always extend the good work to others. If you are interested in carrying out this task, I will inform my Lawyer so that he can arrange for the release of the funds to you. I know I have never met you before but my mind tells me to do this, and I hope you act sincerely. Now my questions are:-
1. Can you handle this project?
2. Can I give you this trust?
3. What will be your commission?
At the moment I cannot take any telephone calls, because I have a throat infection and have been restricted by my doctors who has advised that I deserve all the rest I can get as I am now too weak and fragile to do things myself because of my health condition.
I will appreciate your utmost confidentiality in this matter until the task at hand is accomplished, as I don't want anything that will Jeopardize my last wish, due to the fact that I do not want my relatives or family members standing in the way of my last wish. Send your urgent response to my private email address at: sarhkinlkin192@gmail.com
With Love & Personal Regards, .......,
Appearance of the "Donation To Charity Through You" spam email (GIF):

Other examples of emails from "Donation To Charity Through You" spam campaign:
Sample 1:

Text presented within:
Subject: RE: You can help
Mrs. Lisa Milner
Co-Founder, Weigold & Bohm Oil Retired
Thьnefeldstrasse 5. D-82299 Tьrkenfeld
Germany.I am Mrs. Lisa Milner, 67yrs old from Mцnchengladbach, Germany and I am diagnosed of Chronic Myelogenous Leukemia (CML) and my Doctor
told me that my Life is now short-lived due to the damage the cancer has done to me. I am presently in Luxembourg receiving treatment in a
private hospital. I am contacting you to entrust my fixed deposit income values (US$15,000,000.00) with a financial institution abroad to
you, so that through you this fund can be made available to reputable charity organizations around the world. Please get back to me for
more details.
Yours Sincerely
Mrs. Lisa Milner.
Sample 2:

Text presented within:
Subject: Bequest from Mrs. Betty Wilson
Dear,
Please I am Sorry for intruding upon your privacy. My name is Mrs. Betty Wilson, I am married to Mr. Campbell Wilson, from the Netherlands. Please I am writing to you in good faith and hope that you will understand the importance of my email. I have been recently diagnosed with Cancer and the doctor said I have less than 8 weeks to live. Since this sudden news was announced to me, I have been reflecting over my life in the past. It is painful that after over 24 years of peaceful marriage with my late husband, we had no child of our own that will inherit our wealth. In the past, I have made reasonable donations to the victims of earthquakes in Haiti and Japan, Now that my health is gradually deteriorating, I cannot continue to do all these by myself any more. I strongly desire to reach out to the poor and needy people in your country, but I would prefer to continue this with the assistance of a kind person like you.
Please I want to donate this money to you so that you will utilize the money to establish business investments that will create job opportunities for the jobless population and less privileged, and open a charity foundation in the name of my late husband. I will give you more details only if you are willing and ready to handle this project for me. Thank you.
Yours Faithfully
Mrs. Betty Wilson
Sample 3:

Text presented within:
Subject: Good day,
Good day and God bless you.
I feel quite safe and satisfy dealing with you in this charity project.My name is MRS PATRICIA WAGNER , a merchant in Dubai, in the U.A.E. I have been diagnosed with Esophageal cancer . It has defiled all forms of medical treatment, and right now I have only about a few months to live, according to medical experts.
I have decided to give aims to charity organizations, as I want this to be one of the last good deeds I do on earth. So far, I have distributed money to some charity organizations in the U.A.E, Algeria and Malaysia. Now that my health has deteriorated so badly, I cannot do this myself anymore.
The last of my money which no one knows of is the huge cash deposit of TWELVE MILLION DOLLARS $12,000,000,that I have with a finance/Security Company abroad. I will want you to help me collect this deposit and dispatched it to charity organizations.
I have set aside 25% for you and for your time if you want to help me to collect this Funds and also invest this money.
Email:bode3@mail.com
Remain blessed in the name of the Lord.
Yours in Christ,
Mrs PATRICIA WAGNER
Sample 4:

Text presented within:
Subject: Assistance Needed for a Charitable Purpose.
Hello,
I'm Kate James, originally from Germany, now residing in Houston, TX.
After losing my husband, James Kim Jae-hwi, in 2020, we left behind USD 5.5m in safekeeping with a security firm.
As I now battle a serious illness at MD Anderson Cancer Centre, my wish is to see this fund used to uplift widows, orphans, and charities in need.
Unfortunately, I can't entrust this to family. I'm seeking a sincere, trustworthy individual to help carry out this mission.
Given my condition, communication may be limited. Please feel free to reach out to me via my email or my attorney below, and kindly share your WhatsApp number if you're willing to assist me.
I appreciate your understanding.
Warm regards,Kate James
?? Email: katejamkim@daum.net
Attorney Contact InformationCaroline Clark
?? WhatsApp: +1 707 637 6427?? Email: clark.caroline29@gmail.com
Sample 5:

Text presented within:
Subject: Mrs. Helen Jaden
MY NAME IS Mrs. Helen Jaden from London UK , I asked for your help in the most gentle language.
I am a dying woman who has decided to donate what I have for charities. I am 79 years old and have been diagnosed with Lung, Cervical & Throat Cancer four years ago. Immediately after the death of my husband, life for me in this world is not so important, as we are spending our lives in this world to be able to have a place in heaven.
My husband died many years ago and also had a fixed deposit with Bank the sum of (US$4,500,000) four Million five hundred thousand United States Dollars Only].
I was touched by God to donate this fund that I inherited from my late husband to the good work for humanity, instead of allowing his relatives to ruthlessly use my husband's funds. While lying on my sickbed, I want you to help me realize my last wish on earth, which will be very beneficial to you.
These are the wishes of a dying widow. As the only survival in my family this are the desires of my heart, hence my decision as I do not have a child to take over my late husband's inheritance as I want you to Stand-in for this charity project ; I need a person with honest and dignity to handle this charity project ,Presently I am very sick as I was told by my doctor that I have [Cancer of blood] I have few months to live on this earth.
I will send you the necessary documents related to these funds immediately I receive your response and also furnish urgently the following information's :
1. Your full name:
2. Your private telephone number:
3. Your age:
4. Your occupation:
5. Your country of origin:
Remain blessed in the name of the Lord.
Yours mrs. Helen Jaden,
Sample 6:

Text presented within:
Subject: Good Afternoon
Warmest greetings to you dear,
I know you will be surprised reading from me today but consider this a divine intervention. My name is Mrs.Elizabeth Graham, a widow from the United States battling with cancer.born in the state of Ohio USA.I am legally married to Mr.BARRY GRAHAM a south Africa citizen born brought up in Switzerland,Am with my husband for 32 years before we move down to south Africa in 1985 after my husband retirement in 1974,I am 80 years old by the grace of god,I am a new Christian suffering from long time cancer of the breast
I came across your email in my search for someone that can assist and use my money for charity, helping the poor and needy because my days are numbered according to the doctors.
I desire to entrust USD25,000,000 Million United States Dollars in your care. It is my last wish to use this money for charity hence I seek a person who shares the same views to actualize this because my health no longer permits me.
Please reply for further details about this charity project.
Remain blessed in the name of the Lord.
Mrs. Elizabeth!
my email (mrselizabethgrahamawidow@gmail.com)
Sample 7:

Text presented within:
Subject: Looking for Trusted Guidance on a Charitable Matter
Dear Friend,
My name is Ms. Kusatake Kyoko, originally from Hiroshima, Japan. I lost my beloved husband, Mr. Alexander Paul and my only son in a tragic car accident in 2023 after 25 years of marriage. and since his passing, I have been living alone.
I am now facing advanced cancer, and my doctors have informed me that my time is limited. This reality has compelled me to make careful arrangements for what I consider my final legacy. Before the passing, my husband deposited USD 1.7 million in a reputable offshore bank in the United State. It is my sincere wish that these funds be used to support charitable causes, especially to bring hope and relief to orphans and underprivileged children.For this reason, I am seeking a trustworthy and compassionate individual to help me carry out this wish. My proposal is that 70% of the funds be directed toward charitable initiatives, while 30% may remain with you as a token of my gratitude for your assistance in executing this responsibility.
Should you kindly accept, I will provide all necessary legal documentation, including a formal letter of authority naming you as the beneficiary and custodian of these funds. Time is of the essence, and I would be deeply grateful for your confirmation at your earliest convenience so that the process can be carried out without delay.
This is not merely a financial arrangement, it is my heartfelt attempt to leave behind something meaningful in the time I have left. I trust that your acceptance will bring comfort to me and hope to those who are in need.With warm regards,
Ms. Kusatake Kyoko
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Types of malicious emails:
If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.
Credential theft Phishing emails
Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.
Common subject lines
- "Action required: confirm your account"
- "Your password expires today"
- "Unusual sign-in attempt detected"
- "Verify your billing information"
Malware delivery Emails with malicious attachments
Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.
Common subject lines
- "Invoice INV-2026-XXXX attached"
- "Fax received - 3 pages"
- "Your shipping document is ready"
- "Voicemail from +1-XXX-XXX-XXXX"
Extortion Sextortion emails
Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.
Common subject lines
- "I know your password is XXXX"
- "Your account has been hacked"
- "I have recorded you - 48 hours to pay"
- "You have been compromised"
Callback fraud Refund & callback scams
"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.
Common subject lines
- "Norton subscription auto-renewed - $499.99"
- "McAfee Total Protection invoice"
- "Geek Squad order confirmation"
- "Your PayPal payment is being processed"
Credential theft Account suspension & verification scams
"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.
Common subject lines
- "Your account will be deleted in 24 hours"
- "Suspicious activity detected - verify now"
- "Final warning: account closure"
- "Action required to keep your account active"
Mixed payload Delivery & package scams
Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.
Common subject lines
- "Your DHL package is held at customs"
- "USPS - delivery attempt failed"
- "FedEx tracking update - action required"
- "Pay $2.99 redelivery fee to release your parcel"
Remote access Tech support scams
Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.
Common subject lines
- "Microsoft Defender expired - renew now"
- "Apple ID security alert"
- "Critical: virus detected on your PC"
- "Windows license expired - call now"
Wire fraud Advance-fee scams
Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.
Common subject lines
- "Inheritance from a relative you didn't know about"
- "You won the international lottery"
- "URGENT - business proposal worth $XX million"
- "Compensation fund release for fraud victims"
Wire fraud Business email compromise (BEC)
CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.
Common subject lines
- "Quick task - need you to buy gift cards"
- "Updated banking details for invoice payment"
- "Wire transfer request - urgent"
- "Are you available?" (CEO impersonation opener)
How to spot a malicious email?
Check the sender's actual address, not the display name
The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:
- Domain mismatch -
service@paypa1.com,support@micros0ft-help.com, look-alike domains using digits or extra hyphens - Free-email impersonation - any "official" message from a bank, courier, or platform sent from a
@gmail.com,@outlook.com, or@yahoo.comaddress - Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.
Watch for urgency, threats, and generic greetings
Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:
- "Your account will be deleted in 24 hours"
- "Final notice" / "Immediate action required"
- "Dear Customer" or "Dear User" instead of your real name
- Threats of fines, account closure, legal action, or arrest
- Promises of refunds, prizes, or money you didn't earn
- Spelling and grammar mistakes in messages claiming to come from a major brand
Hover over every link before clicking
On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.
- Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
- Shortened URLs (
bit.ly,tinyurl,t.co) hide the real destination - never click them in unsolicited mail - The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.
Treat unexpected attachments as hostile
If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:
.exe,.scr,.iso,.img,.vbs,.bat- executables, never legitimate attachments.docx,.xlsx,.pptxwith "Enable macros" prompts - the macros run the malware.pdfwith "Click here to view" buttons - usually a phishing redirect, not a real document.zip,.rar,.7zarchives, especially password-protected ones - the password defeats the email scanner
If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.
Don't reply, don't click "unsubscribe"
Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.
Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.
Report the scam to your email provider and authorities
Inside your email client:
- Gmail: open the message → ⋮ menu → Report phishing
- Outlook / Outlook.com: ⋯ menu → Report → Report phishing
- Apple Mail / iCloud: Move to Junk, then forward to
reportphishing@apple.com
Forward or report to authorities:
After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.
Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.
You only clicked a link (didn't enter anything or download anything)
Close the page right away. Don't enter any information, even if the page looks legitimate.
- Clear your browser cache and cookies for the last hour - → Last hour → check Cookies and Cached files
- Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
- Update your browser to the latest version - most drive-by exploits target outdated browsers
- Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.
You opened an attachment or downloaded a file - run a full malware scan
Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:
Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.
Windows 11: → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.
Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.
Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.
Reboot to normal Windows. Open . Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.
VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.
Download Combo CleanerInstall Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.
Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.
Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:
Chrome: chrome://settings/reset → Restore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.
Edge: edge://settings/reset. Then edge://settings/content/notifications.
Firefox: about:support → Refresh Firefox.
Open and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run and update browsers and applications.
If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).
You entered credentials on a fake login page
Assume the attacker has your password and is using it right now. Speed matters.
- Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
- Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
- Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
- Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
- Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
- Update security questions - the attacker may have seen the answers in your account profile.
If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.
You sent money or shared bank, card, or ID details
Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.
- Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
- If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
- If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
- File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
- File with the right authority for your country:
- US: ic3.gov + reportfraud.ftc.gov
- UK: reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
- Canada: antifraudcentre.ca
- Australia: scamwatch.gov.au
- EU: your national CERT or police cybercrime unit
- Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
- Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Final scan and startup-app check
Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.
Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.
Monitor accounts and credit for 30 days
Most fraud follow-ups land in the first month. Until that window closes, keep watching:
- Bank and card statements - daily for the first week, then weekly
- Email - watch for password-reset confirmations or login alerts you didn't trigger
- Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
- Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks
If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.
Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.
Frequently Asked Questions (FAQ)
Why did I receive this email?
Regardless of any relevant information that spam emails may include, they are not personal. This mail is sent out in large-scale campaigns – therefore, thousands of users receive identical (or incredibly similar) emails.
I have provided my personal information when tricked by this spam email, what should I do?
If you have provided your log-in credentials – change the passwords of all possibly exposed accounts and inform their official support. However, if the disclosed information was of a different personal nature (e.g., ID card details, passport photos/scans, credit/debit card numbers, etc.) – contact the appropriate authorities without delay.
I have read a spam email but didn't open the attachment, is my computer infected?
Reading an email poses no infection threat; devices are compromised when malicious attachments or links are opened/clicked.
I have downloaded and opened a file attached to a spam email, is my computer infected?
Whether the device was infected might depend on the format of the opened file. Once launched, executables (.exe, .run, etc.) cause infections almost without fail. However, some formats – like documents (.doc, .xls, .pdf, etc.) – might need additional actions to initiate malware download/installation. Hence, the infection can only be triggered after macro commands are enabled, embedded content is clicked, or other actions are performed.
Will Combo Cleaner remove malware infections present in email attachments?
Yes, Combo Cleaner can detect and eliminate almost all known malware infections. It must be stressed that performing a complete system scan is essential since sophisticated malicious software tends to hide deep within systems.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion