Avoid getting scammed by fake "Unclaimed Funds" emails
Phishing/ScamAlso Known As: "Unclaimed Funds" spam email
Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What kind of email is "Unclaimed Funds"?
Upon reading the "Unclaimed Funds" email, we determined that it is spam. This scam message is a supposed business proposal wherein the recipient will be presented as the relative of a deceased person in order to claim their significant bank holdings.
Typically, spam campaigns of this kind aim to trick users into disclosing private information or to scam them out of their money.

"Unclaimed Funds" email scam overview
The spam email with the subject "URGENT BUSINESS PROPOSITION" (may vary) claims to be a confidential business proposal from an "accountant and auditor manager" of the South African branch of the Absa Bank.
The recipient is presented with the opportunity to pretend to be a relative of a deceased client of the Absa bank in order to claim their holdings. The customer had passed away during the COVID-19 pandemic, and their funds held by the bank – fifteen million USD – have not been claimed.
Hence, the proposed scheme is for the recipient to claim the money and share it with the sender. If the proposal interests the recipient, they are to write to the sender for more information on how to pull it off.
As mentioned in the introduction, the information in this email is false, and it is in no way associated with any employees of the Absa Group Limited.
This type of spam mail often seeks to trick users into revealing sensitive information, either directly to scammers or through phishing websites/files.
Targeted information can include log-in credentials (e.g., emails, social media/ networking, messengers, etc.), personally identifiable details (e.g., ID card details, passport scans/photos, etc.), and finance-related information (e.g., bank account log-in credentials, credit/debit card numbers, etc.).
Alternatively, scammers can ask to be sent money for legitimate-sounding reasons like paying taxes or fees. Difficult-to-trace methods may be used by cyber criminals to acquire the funds; thus, they diminish the chances of successful prosecution and of money retrieval by victims.
To summarize, victims of scam mail like "Unclaimed Funds" can experience severe privacy issues, financial losses, and identity theft.
If you have disclosed your log-in credentials – change the passwords of all potentially exposed accounts and inform their official support without delay. However, if you've provided personally identifiable or finance-related information to scammers – immediately contact the appropriate authorities.
| Name | "Unclaimed Funds" spam email |
| Threat Type | Phishing, Scam, Social Engineering, Fraud |
| Fake Claim | Sender proposes presenting the recipient as a relative of a deceased bank client in order to claim their 15 million USD holdings. |
| Symptoms | Unauthorized online purchases, changed online account passwords, identity theft, illegal access of the computer. |
| Distribution methods | Deceptive emails, rogue online pop-up ads, search engine poisoning techniques, misspelled domains. |
| Damage | Loss of sensitive private information, monetary loss, identity theft. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Spam campaigns in general
Spam campaigns are used to promote various scams and to proliferate malware. These emails rely on various lures to gain recipients' interest and trust, e.g., business proposals, inheritances, lotteries, purchases/invoices, refunds, account issues, undelivered messages, expired passwords, suspicious activity detections, security upgrades, etc.
While the widely held belief that spam emails are poorly written and full of spelling/grammatical mistakes is not untrue, it is not always the case. This mail can be competently put together and even convincingly disguised as messages from legitimate entities (e.g., companies, organizations, institutions, authorities, etc.).
"Intuit QuickBooks - Negative Comments From A Consumer", "Capital One - Unrecognized Purchase", "FedEx Delivery Address Confirmation", "Bittrex Inc Bankruptcy Notice", "Request For Quotation Plan", "Secure Your Trust Wallet Account", "DHL - Customs Clearance", "Sign-in Attempt Was Blocked", "Claim Inheritance Money", and "Product Specification For Korean Market" are just some of our newest articles on spam campaigns.
How do spam campaigns infect computers?
Malware is commonly distributed via spam campaigns. These deceptive emails/messages have virulent files attached to or linked inside them. Malicious files come in various formats, e.g., archives (RAR, ZIP, etc.), executables (.exe, .run, etc.), documents (Microsoft Office, Microsoft OneNote, PDF, etc.), JavaScript, and so forth.
Opening such a file can be enough to trigger an infection chain. However, some formats need additional user interaction to begin malware download/installation processes. For example, Microsoft Office files require users to enable macro commands (i.e., editing/content), while OneNote documents need them to click on embedded links or files.
How to avoid installation of malware?
We recommend exercising caution with incoming emails, PMs/DMs, SMSes, and other messages. Attachments or links present in suspect/irrelevant mail must not be opened, as they can be malicious.
However, malware is not proliferated exclusively via spam mail. Therefore, we advise vigilance when browsing since the Internet is full of deceptive and dangerous content.
Additionally, all downloads must be made from official and verified channels. Another recommendation is to activate and update programs using legitimate functions/tools, as those acquired from third-parties can contain malware.
We must stress the importance of having a dependable anti-virus installed and kept up-to-date. Security software must be used to run regular system scans and to remove detected threats and issues. If you've already opened malicious attachments, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.
Text presented in the "Unclaimed Funds" email letter:
Subject: URGENT BUSINESS PROPOSITION
URGENT BUSINESS PROPOSITION.
FROM THE DESK OF:MR.NORM ASHER.
ACCOUNTANT AND AUDITOR MANAGER
ABSA BANK OF REPUBLIC OF SOUTH AFRICA.
TELEPHONE:+27 61 058 3275.
PRIVATE E-MAIL ADDRESS: ashernorm94@gmail.com
ATTENTION:
I work as the Accountant and Auditor Manager at Absa bank Republic of South Africa. I have a very confidential business proposition for you.
There are unclaimed huge funds amounting to the sum of (USA$15 MILLION) lying in our bank that belongs to a foreign customer who died of the covid-19 pandemic.
However, I am seeking for your good collaboration to transfer the funds to you as the immediate relative for our both benefit during these difficult times.
Kindly reply to me through my above E-Mail Address once you have read this letter and declare your interest to enable me to send to you more relevant information for us to archive this transaction and meet in person to enable both of us share the funds accordingly.
Thank You.
Yours Sincerely.
Mr.Norm Asher.
Other examples of unclaimed funds-themed spam emails:
Sample 1:

Text presented within:
Subject: Greetings,Please accept my apologies
Greetings,
How are you? Please accept my apologies if my email does not meet your personal ethical standards. I would like to introduce myself and this business opportunity to you.
My name is Barrister Sergen Ecesoy of Integrity Law Firm London, I am the personal lawyer of my deceased client who bears the same surname as you.
I am contacting you regarding an unclaimed financial inheritance claim related to your surname. I want to know if we can work together as a team.
I want you to act as the next of kin of my deceased client who has an account worth $40.7 Million USD at a financial institution.
My deceased client died without any registered next of kin and therefore the funds now have an open beneficiary mandate. The board of his bank passed a resolution and I have been mandated to nominate his next of kin to pay this fund or the fund will be forfeited to the bank as unclaimed property.
Fortunately, since you share the same surname as my deceased client, it will be very easy for me to make you his official next of kin.
If you are interested, please let me know so I can give you full details on what we are to do.
Thanks,
Best Regards,
Barrister Sergen Ecesoy
180 Tottenham Court Road London, W1T 7PD.United Kingdom
The Law is Our Business.
Sample 2:

Text presented within:
Subject: Private Banking Notification – Important Beneficiary Inquiry
Good Morning,
I hope this email finds you well. Please accept my sincere apologies for this unsolicited message. I understand this is not a conventional way to establish communication, but I believe you will appreciate the necessity of my reaching out. I have made several unsuccessful attempts to contact you through other means.
I work with Astrobank Ltd Cyprus (formerly Piraeus Bank Cyprus Ltd). Your contact information was obtained from public records while searching for potential relatives of a deceased client, The client happens to share your last name.
In June 2011, this individual, a Cyprus resident and client of our bank, invested €21.4 million in a high-yielding financial product. By the time of maturity, this investment had grown to €25.5 million, inclusive of accrued interest. Unfortunately, despite multiple notices requesting instructions on handling the proceeds, no response was received.
Upon further inquiry, I discovered that the client had tragically passed away in a car accident in France during the summer of 2012. They were unmarried, had no children, and, based on our records, did not designate a next-of-kin. Due to the sensitive nature of private banking, Cyprus banks do not require foreign customers to furnish next-of-kin details, nor do they actively seek out relatives of deceased foreign clients unless instructed otherwise.
As per Cyprus banking regulations, unclaimed funds remain dormant for a specific period. After 13 years, they are transferred to the Cyprus Banking Ombudsman. If no claims are made within 15 years, the Cyprus government assumes full ownership of the funds.
Given this situation, I am reaching out to explore the possibility of presenting you as the legally designated family representative of the late client. This would allow us to process and transfer the investment proceeds accordingly. Please rest assured that this will be executed under a completely legitimate arrangement in full compliance with Cyprus financial laws.
If you are open to discussing this matter further, kindly respond at your earliest convenience. I am happy to provide any necessary clarifications. You may reach me via email at; gregoriahad@cyprusboxsmail.net
Looking forward to your response.
Best regards,
Gregoria H.
Sample 3:

Text presented within:
Subject: FOLLOW UP TODAY.
Attention, This message is coming to you because you are a linked beneficiary to some unclaimed funds/properties. Please kindly respond back to get more details on this. This is no hoax letter so be guided by that and observe the available protocol.
NOTE: YOU ARE TO RESPOND ONLY TO THE OFFICIAL EMAIL PROVIDED BELOW.
Regards,
Zachary Hoffman.
Mandate Official.
Mandate Email: zachary.hoffman@procurementfdtredeptdus.com
Sample 4:

Text presented within:
Hello,
How has your day been? I am sure you will receive me in good faith, I am contacting you to see how you can help me and you too.
My name is Zeynep Basturk. I am an employee of a Turkish bank employee. I have been looking for someone from your country who has the same nationality as you. I believe it was God's will for us to meet to share some important information. I am sure you will be interested. I believe God wants me to meet you now. I have an important business discussion that I would like to share with you and I believe you will be interested in what is related to your nationality and you will also benefit from it.
A citizen of your country who died in the recent earthquake in Turkey. He had in our bank fixed deposits worth 11.5 million dollars. Unfortunately, he was not married and no next of kin was mentioned in the fixed deposit account as he never believed that he could die in his prime; He was engaged in exporting fabric-made materials.
My bank management is not yet aware of his death. If my bank executive finds out about his death, they will receive the funds for themselves and become richer and I would like to prevent that from happening only if I get your cooperation. I knew this because I was his account manager.
Last week my bank management had a meeting with the aim of conducting a bank audit to check the dormant and abandoned deposit accounts. I know this will happen and that is why I am looking for a solution to deal with this situation because if my bank management accidentally discovers his death, they will divert the funds to the top management board. So I do not want that to happen.
I am now requesting your cooperation to introduce you as the next of kin of the account as you are of the same nationality as him and my banking centre will issue the account to you through my help. There is no risk; the transaction is carried out under a legal agreement that protects you from infringements. It is better to demand the money than to let the bank managers siphon it off and divide it amongst themselves. I am not a greedy person so I suggest we split the funds, 60/40 and 40 for me. Please note that I am in dire need of my share of this money because I have a sick daughter who requires very expensive surgical treatment. Please let me know what you think about this and please keep this information confidential. I will provide more details as soon as I receive your reply.
Best Regards,
Zeynep Basturk.
Sample 5:

Text presented within:
Subject: TOTAL PAY OFF $12,642,857.99
(UNIDO) Address: Bd du R§аgent 37, 1000 Bruxelles, Belgium
(UNDP) Address: Bd du R§аgent 37, 1000 Bruxelles, Belgium
(UNRIC) Address: Rue de la Loi 155, 1040 Bruxelles, BelgiumThis message is for the owner of this email.
For the purpose of introduction My name is Ms. Camilla Bruckner - I am The Director of the UN/UNDP Office in Brussels and Representative of the UN System in the European Union, leading the UN's efforts in Belgium. I know this might come as a surprise to you considering the amount of junk emails we all receive on a daily basis. I would appreciate it if the content of these messages is kept strictly confidential. The United Nations Organization has ordered and signed for the release of all pending and unclaimed funds in any bank or any financial department all over the world in which your email appears as one of the selected victims.
But unfortunately we received a counter email from one Mr. Kim Richard Lee. who is claiming that you are incapacitated due to an accident you encountered and as a result you won't be able to claim your compensated/inheritance funds Valued the sum of $12,642,857.99 and thereby he is acting on your behalf as Your Next Of Kin.. Moreover, in furtherance to claim the payment, he has sent us his full banking information to be processed with Online Wire Transfer or ATM CARD delivery being the mode of payment as approved by the United Nations Secretary-General Antonio Guterres and Federal Ministers of Finance:
But To ensure transparency in our services to individuals, therefore do us a favor to confirm immediately if this is the true state of things that you instructed Mr. Kim Lee to claim your funds on your behalf otherwise You won't blame us by approving your funds To Him. Please we need your urgent response before it is too late. Meanwhile I want to inform you that this operation has been undertaken with the cooperation and support of several major international bodies, including the Organization of IMF, and the Federal Bureau of Investigation (FBI) If Mr. Kim Lee is trying to claim your funds without your permission then he will face the law. I wait for your urgent response. NOTE: Do not reply to the sender's email. Kindly copy the email below and get back to me to prove that you are still alive.
Regards,
Ms. Camilla Bruckner
Private Email:
Whats-app Number: +44-7861-988061
ZANGI Number: 71-5325-4870
Sample 6:

Text presented within:
Subject: RE: URGENT PLEASE 8/29/2026 11:55:26 p.m.
Greetings,
I have a friend who works with your country's embassy who I told I need a partner to partner with and invest in and he gave me a list of companies and individuals I can contact to partner with and invest with. I am Daniel Kelvin. (Esq.), Solicitor and personal lawyer to Mrs. Grace Maria Khan, a client of mine, who has a servicing firm affiliated with the National Port Authority in the Republic of Seychelles.She was awarded a contract worth (US$28,850,000.00). Immediately this contract was signed, an initial amount of (US$11.850,000.00) was paid to her as mobilization fee to kick off the contract. She duly completed this contract pending when her remaining balance of (US$17,000,000.00) will be paid to her.
On the 7th June 2008, my client, her husband and their two kids were involved in a ghastly boat capsize at Labadi Beach. Unfortunately, all the occupants in the boat lost their lives. Not too long after her untimely death, her outstanding balance of S$17,000,000.00 was approved.
Right now the funds are still floating unclaimed in the suspense account of the offshore correspondence payment centre. I have reasoned very professionally and I feel it will be legally proper to present you as the next of kin of my deceased client, so that we can be paid the remaining balance of her contract funds left in the Bank, hence I contacted you.I have discussed with the bank that I will be getting the next of kin soon and I will want the bank to process and send by courier delivery the funds by ATM CARD to the next of kin which I will pay for the delivery fee and I will pay for the affidavit of claim to change the name on deposit to your name. All arrangements have been made for a stress free transaction. The delivery company will deliver the ATM CARD to your doorstep which I will pay for.
ATM CARD is the best option to redraw money to avoid huge international bank transfer tax fees. Please consider this transaction so I will ask the bank to prepare the ATM CARD on your name.
We will share the money accordingly 50% for you and 50% for me. Every legal formality will be handled by our law firm.
Send to me the below:
Full names:
Address:
Telephone Number:
I will be using your information to apply to get an affidavit of claim. Note I already have the death certificate of my client. The affidavit of claim will be ready immediately I have the above information.Best personal regards,
Mr. Daniel Kelvin (Esq.)
Tel:+1 404596532.
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Types of malicious emails:
If you opened an attachment or downloaded a file from a suspicious email, run a full system scan with Combo Cleaner. If you only received the email and didn't engage with it, you don't need to scan anything - just identify the scam and delete it. The full procedure below covers both situations and what to do if you already clicked, replied, or sent money.
Credential theft Phishing emails
Fake login pages disguised as PayPal, Microsoft, Apple, banks, or social networks. The email pushes a link to a near-perfect copy of the real login screen. The moment you type your username and password, the attacker has them.
Common subject lines
- "Action required: confirm your account"
- "Your password expires today"
- "Unusual sign-in attempt detected"
- "Verify your billing information"
Malware delivery Emails with malicious attachments
Trojans hidden inside fake invoices, faxes, shipping confirmations, or Office documents. Opening the attachment runs the payload and infects the system - often with an info-stealer or remote-access trojan.
Common subject lines
- "Invoice INV-2026-XXXX attached"
- "Fax received - 3 pages"
- "Your shipping document is ready"
- "Voicemail from +1-XXX-XXX-XXXX"
Extortion Sextortion emails
Fake claims of webcam recordings demanding cryptocurrency. Almost always a bluff: the attacker pulls a real password from an old data breach to make the threat look credible, then claims to have video of you. They have no recording and no access.
Common subject lines
- "I know your password is XXXX"
- "Your account has been hacked"
- "I have recorded you - 48 hours to pay"
- "You have been compromised"
Callback fraud Refund & callback scams
"Your subscription was renewed for $499 - call to cancel." Norton, McAfee, Geek Squad, PayPal, and Wells Fargo variants are all common. There's no real subscription. The phone number in the email connects directly to the scammer, who walks you through "refunding" yourself - which is actually them stealing money from your bank.
Common subject lines
- "Norton subscription auto-renewed - $499.99"
- "McAfee Total Protection invoice"
- "Geek Squad order confirmation"
- "Your PayPal payment is being processed"
Credential theft Account suspension & verification scams
"Your account will be deleted in 24 hours - verify now." The artificial deadline is the whole point: it pressures you to click before checking details. The "verify" link goes to a phishing page styled to look like the real provider.
Common subject lines
- "Your account will be deleted in 24 hours"
- "Suspicious activity detected - verify now"
- "Final warning: account closure"
- "Action required to keep your account active"
Mixed payload Delivery & package scams
Fake DHL, USPS, UPS, or FedEx tracking, customs fees, or "package undeliverable" notices. Targets anyone expecting a parcel - the timing alone catches many people. The link hides either phishing (asking for card details to "release" the package) or a malware download.
Common subject lines
- "Your DHL package is held at customs"
- "USPS - delivery attempt failed"
- "FedEx tracking update - action required"
- "Pay $2.99 redelivery fee to release your parcel"
Remote access Tech support scams
Fake Microsoft, Apple, or "Windows Defender" security alerts pushing a phone number. Real Microsoft and Apple never email a phone number to call. The number connects you to a scammer who asks for remote access to "fix" the imaginary problem and then demands payment.
Common subject lines
- "Microsoft Defender expired - renew now"
- "Apple ID security alert"
- "Critical: virus detected on your PC"
- "Windows license expired - call now"
Wire fraud Advance-fee scams
Inheritance, lottery wins, romance, or business deals that ask for a small fee to release a much larger sum. The classic "Nigerian prince" 419 family of frauds. Once you pay the first fee, more fees appear (taxes, lawyer, transfer charges) until you stop paying. The promised money never exists.
Common subject lines
- "Inheritance from a relative you didn't know about"
- "You won the international lottery"
- "URGENT - business proposal worth $XX million"
- "Compensation fund release for fraud victims"
Wire fraud Business email compromise (BEC)
CEO impersonation asking employees to wire money or buy gift cards, or fake supplier invoices with newly "updated" bank details for payment redirection. The email often spoofs a real internal executive's display name and uses an external lookalike domain.
Common subject lines
- "Quick task - need you to buy gift cards"
- "Updated banking details for invoice payment"
- "Wire transfer request - urgent"
- "Are you available?" (CEO impersonation opener)
How to spot a malicious email?
Check the sender's actual address, not the display name
The display name (the human-readable part) is trivial to fake. Always check the full address that comes after it. Common red flags:
- Domain mismatch -
service@paypa1.com,support@micros0ft-help.com, look-alike domains using digits or extra hyphens - Free-email impersonation - any "official" message from a bank, courier, or platform sent from a
@gmail.com,@outlook.com, or@yahoo.comaddress - Reply-To mismatch - the From address looks legitimate but Reply-To points somewhere completely different
Real companies own their domains and send mail from them. A "DHL" message from a Gmail address is never legitimate, regardless of how convincing the body looks.
Watch for urgency, threats, and generic greetings
Scams almost always rush you. The point is to make you act before you think. Treat any of the following as a strong signal:
- "Your account will be deleted in 24 hours"
- "Final notice" / "Immediate action required"
- "Dear Customer" or "Dear User" instead of your real name
- Threats of fines, account closure, legal action, or arrest
- Promises of refunds, prizes, or money you didn't earn
- Spelling and grammar mistakes in messages claiming to come from a major brand
Hover over every link before clicking
On a desktop, hover the mouse over the link without clicking. The real destination shows in the bottom-left status bar of your browser or email client. On a phone, long-press the link to preview the URL.
- Real Microsoft, PayPal, or bank links go to those exact domains, not redirects through unrelated sites
- Shortened URLs (
bit.ly,tinyurl,t.co) hide the real destination - never click them in unsolicited mail - The visible link text and the actual URL must match - mismatches are the single biggest phishing red flag
When in doubt, don't click the link. Open a new browser tab and type the company's address yourself, then log in normally. If there really is an issue with your account, you'll see it there.
Treat unexpected attachments as hostile
If you didn't ask for the file, don't open it - even if it appears to come from someone you know. Categories that should never be opened from email without verification through another channel:
.exe,.scr,.iso,.img,.vbs,.bat- executables, never legitimate attachments.docx,.xlsx,.pptxwith "Enable macros" prompts - the macros run the malware.pdfwith "Click here to view" buttons - usually a phishing redirect, not a real document.zip,.rar,.7zarchives, especially password-protected ones - the password defeats the email scanner
If you only received the email and didn't reply, click, or open anything, the steps below are all you need. Your computer is not infected.
Don't reply, don't click "unsubscribe"
Replying confirms your address is real and monitored, which gets you added to higher-value scam lists. The "unsubscribe" link in a scam message is rarely a real opt-out - it usually leads to a phishing page or downloads a tracking pixel.
Instead, mark the message as junk or phishing inside your email client (this trains the spam filter), then block the sender.
Report the scam to your email provider and authorities
Inside your email client:
- Gmail: open the message → ⋮ menu → Report phishing
- Outlook / Outlook.com: ⋯ menu → Report → Report phishing
- Apple Mail / iCloud: Move to Junk, then forward to
reportphishing@apple.com
Forward or report to authorities:
After reporting, delete the email and empty the Trash folder so you don't accidentally open it later.
Pick the step below that matches what you did. If multiple apply, work through them in the order they appear - the steps are arranged from lowest to highest risk.
You only clicked a link (didn't enter anything or download anything)
Close the page right away. Don't enter any information, even if the page looks legitimate.
- Clear your browser cache and cookies for the last hour - → Last hour → check Cookies and Cached files
- Run a quick scan with Combo Cleaner in case the page tried to drop a file silently (drive-by download)
- Update your browser to the latest version - most drive-by exploits target outdated browsers
- Watch for new browser pop-ups, redirects, or unfamiliar notifications over the next few days
Modern browsers block most drive-by attacks, but a single click on a phishing page can still be enough on an outdated browser or unpatched plugin. A quick scan catches anything that landed silently.
You opened an attachment or downloaded a file - run a full malware scan
Opening an attachment is the most common path to actual infection. Treat the system as compromised until the scans below come back clean. Work through these sub-steps in order:
Unplug Ethernet and turn off Wi-Fi. If the attachment was an info-stealer or remote-access trojan, this stops it from sending data out or receiving commands. Keep the network off until you've booted into Safe Mode (next step) - you'll reconnect there briefly to download the scanners.
Windows 11: → Troubleshoot → Advanced options → Startup Settings → Restart → press 5 or F5.
Windows 10: hold Shift, click Power → Restart → Troubleshoot → Advanced options → Startup Settings → Restart → press F5.
Once Safe Mode has loaded, turn Wi-Fi back on and download Combo Cleaner (used in 8.4) and Microsoft Safety Scanner (used in 8.5). Safe Mode loads only minimal drivers, so most malware can't auto-run while you're getting the tools. Save both installers to your Desktop.
Reboot to normal Windows. Open . Select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts into a stripped-down environment and scans the disk before Windows fully loads - this is what catches rootkits and bootkits.
VB100 certified. Includes anti-trojan, registry/persistence scanning, and anti-spyware in one pass. The 7-day free trial is available.
Download Combo CleanerInstall Combo Cleaner and run a full system scan (not the quick scan). Let it complete fully, review what it found, and apply the recommended actions. Combo Cleaner will quarantine known trojans and remove their persistence in the registry.
Download Microsoft Safety Scanner (MSERT.exe). The binary expires every 10 days, which means every download has the latest signatures. Run a full scan after Combo Cleaner to catch anything one engine alone might miss.
Many email-borne trojans drop adware that hijacks browsers. Reset each browser you use:
Chrome: chrome://settings/reset → Restore settings to their original defaults. Then chrome://settings/content/notifications - remove unfamiliar sites.
Edge: edge://settings/reset. Then edge://settings/content/notifications.
Firefox: about:support → Refresh Firefox.
Open and confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are all on. Then run and update browsers and applications.
If the scans keep finding new threats on each run, or files reappear after deletion, you may have a deeper compromise that needs a clean Windows reinstall. See pcrisk's full manual malware removal guide for the extended procedure (Process Explorer, Autoruns, hosts file inspection).
You entered credentials on a fake login page
Assume the attacker has your password and is using it right now. Speed matters.
- Change the password from a different, known-clean device (your phone is fine if it's not infected). Don't reuse the old password anywhere else.
- Enable two-factor authentication if you haven't already. Prefer an authenticator app or hardware key over SMS.
- Sign out of all sessions - most platforms have a "sign out everywhere" option in security settings, which kicks the attacker out.
- Review recent activity - look for unfamiliar logins, new devices, forwarding rules, or app permissions. Remove anything you don't recognize.
- Check your other accounts - if you reused that password anywhere else, change it there too. Check your exposure at haveibeenpwned.com.
- Update security questions - the attacker may have seen the answers in your account profile.
If you only have time to change one password, change your primary email password - it's the recovery hub for every other account. An attacker who controls your email can reset everything else.
You sent money or shared bank, card, or ID details
Time is the single biggest factor in recovering money. Banks can sometimes recall a wire or reverse a card transaction within the first few hours.
- Call your bank or card issuer immediately. Use the number on the back of the card, not any number from the scam email. Ask them to freeze the card, reverse the transaction if possible, and flag the account for fraud monitoring.
- If you sent a wire transfer or used a money-transfer service (Western Union, MoneyGram, Zelle, Wise), call them directly and request a recall. Some can be reversed within minutes if reported fast.
- If you sent cryptocurrency or gift cards, recovery is unlikely - but report it anyway, since law enforcement tracks these patterns.
- File a police report. You'll need the report number for any insurance, bank, or credit-bureau claim. Save the report number.
- File with the right authority for your country:
- US: ic3.gov + reportfraud.ftc.gov
- UK: reportfraud.police.uk (Report Fraud, the successor to Action Fraud; 0300 123 2040)
- Canada: antifraudcentre.ca
- Australia: scamwatch.gov.au
- EU: your national CERT or police cybercrime unit
- Set fraud alerts on all major credit bureaus if you shared any ID details. US: Equifax, Experian, TransUnion. UK: Experian, Equifax, TransUnion (Cifas Protective Registration is a stronger option).
- Save all evidence - the original email (with full headers), screenshots of the fake site, transaction records, any phone numbers or chat logs.
Final scan and startup-app check
Reconnect to the network and run one final full scan with Combo Cleaner, followed by a Windows Defender quick scan. Then open Task Manager (Ctrl + Shift + Esc) and switch to Startup apps - disable anything unfamiliar.
Make sure Windows, browsers, and any applications you use are fully up to date. The infection vector that worked on you once usually involves outdated software.
Monitor accounts and credit for 30 days
Most fraud follow-ups land in the first month. Until that window closes, keep watching:
- Bank and card statements - daily for the first week, then weekly
- Email - watch for password-reset confirmations or login alerts you didn't trigger
- Credit report - US: free at annualcreditreport.com; UK: Experian, Equifax, TransUnion all have free tiers
- Breach alerts - sign up at haveibeenpwned.com to be notified when your email appears in new leaks
If anything new appears in any of those, treat it as a continuing compromise: change passwords again, contact the bank again, and update the police report.
Important: If you didn't click anything, didn't reply, and didn't open any attachment, your computer is not infected - just delete the email and move on. If you opened an attachment or downloaded a file, run an automated scan with Combo Cleaner and Windows Defender and stop there. That path catches the vast majority of email-borne malware without the risk of breaking Windows by deleting the wrong file.
Frequently Asked Questions (FAQ)
Why did I receive this email?
Spam emails are not personal, even if they include information relevant to the recipients. This mail is distributed in mass-scale campaigns – therefore, thousands of users receive identical (or incredibly similar) emails.
I have provided my personal information when tricked by this spam email, what should I do?
If you have disclosed your log-in credentials – change the passwords of all potentially exposed accounts and inform their official support. However, if you've provided other private information (e.g., ID card details, credit card numbers, etc.) – immediately contact relevant authorities.
I have read a spam email but didn't open the attachment, is my computer infected?
No, merely reading an email poses no infection threat. Devices are infected when malicious attachments or links are opened/clicked.
I have downloaded and opened a file attached to a spam email, is my computer infected?
If the file was an executable – most likely, yes – since these files cause infections almost without fail upon being opened. However, some formats require additional actions. Hence, you might have avoided the infection if it was a document. These formats jumpstart malware download/installation after macro commands are enabled, embedded content is clicked, or other actions are performed.
Will Combo Cleaner remove malware infections present in email attachments?
Yes, Combo Cleaner is designed to scan computers and eliminate all manner of threats. It can detect and remove most of the known malware infections. Note that high-end malware tends to hide deep within systems – hence, performing a full system scan is paramount.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion