More Halifax Banking Phish

From - Sat Mar 15 12:17:00 2008

X-Account-Key: account2

X-UIDL: U0X!!I
X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1206014645.69021@VByCa2cR5T9M5oWWXPvKDg

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2FC3nOE009347

for ; Sat, 15 Mar 2008 06:03:54 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2FC3mAN009346

for dave@doctor.nl2k.ab.ca; Sat, 15 Mar 2008 06:03:48 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Sat, 15 Mar 2008 06:03:48 -0600

Resent-Message-ID: <20080315120348.GE4755@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205998431.48041@E2c9nz146zhsvUBQckNemQ

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2F7XjD4010072

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Sat, 15 Mar 2008 01:33:50 -0600 (MDT)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1205998395.13194@6+G//z2tw3KPntVuNsH9ew

Received: from istanbul.dnsservis.net

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m2F7X2jV017888

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)

for ; Sat, 15 Mar 2008 01:33:13 -0600 (MDT)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: from nobody by istanbul.dnsservis.net with local (Exim 4.68)

(envelope-from )

id 1JaQso-0006A1-MQ

for ctm-e@nk.ca; Sat, 15 Mar 2008 09:32:46 +0200

To: ctm-e@nk.ca

Subject: {Spam?} {Disarmed} Account Notification.

From: Halifax Internet Banking

MIME-Version: 1.0

Content-type: text/html; charset=iso-8859-1

Content-Transfer-encoding: 8bit

Reply-To: Halifax Internet Banking

Message-ID: <0c26d8a8885f7093de0b723c673f99f4@>

X-Priority: 1

X-MSmail-Priority: High

X-Mailer: Microsoft Office Outlook, Build 11.0.5510

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441

Date: Sat, 15 Mar 2008 09:32:46 +0200

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - istanbul.dnsservis.net

X-AntiAbuse: Original Domain - nk.ca

X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]

X-AntiAbuse: Sender Address Domain - istanbul.dnsservis.net

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=4.275, required 1, HTML_MESSAGE 0.00,

INVALID_MSGID 2.60, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: ssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: nobody@istanbul.dnsservis.net

X-Spam-Status: Yes, No, No

X-Null-Tag: b6e8a08841b8ab46ff0daf83df58a906

X-Null-Tag: 7b491efc090a62d15eac892a1d6690e0

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ssss

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2FC3nOE009347

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: U0X!!I


















Halifax - Internet banking security center









Web Bug from http://email1.paypal.com/1x1.dyn?0FED48GvB2L64qzRDh37=0










































border="0" width="1" height="40">































border="0" width="40" height="1">



















bgcolor="#ffffff">







halifax















border="0" width="1" height="20">



























alt="" border="0"



width="1" height="2">









border="0" width="1" height="20">






Halifax - Internet banking security center:



halifax

Welcome! Here is your current Account Notifications,



*System and data maintainance control service problem


*Halifax Internet Access has a latest update problem


*Account Is not secure for fraudulent activities



it's strongly advise to fix now to avoid account been flagged.


click on "Get Started" to continue the process...


















Internet Banking Security Center


Halifax Internet Banking

















2008 Halifax Customer Service. All Rights Reserved.



Legal | Privacy | Help.








border="0" width="1" height="1">


































--


This message has been scanned for viruses and




dangerous content by

MailScanner, and is


believed to be clean.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







More Halifax Banking Phish

From - Sat Mar 15 12:16:51 2008

X-Account-Key: account2

X-UIDL: P)N!!3H9!!70V!!6p0!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1206014593.76718@qvq3VcdmXfrpxvKh00PSMQ

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2FC2vgL009084

for ; Sat, 15 Mar 2008 06:03:03 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2FC2vHt009083

for dave@doctor.nl2k.ab.ca; Sat, 15 Mar 2008 06:02:57 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Sat, 15 Mar 2008 06:02:57 -0600

Resent-Message-ID: <20080315120257.GC4755@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205997555.51675@fu0r2U1//iR7uMRHFehdFg

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2F7IpwM005460

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Sat, 15 Mar 2008 01:18:57 -0600 (MDT)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1205997503.32776@3Q2e4MH9lo+aJUsPuZbdcQ

Received: from pluto.dnsdc3.com

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m2F7I2dq017238

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)

for ; Sat, 15 Mar 2008 01:18:22 -0600 (MDT)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: from nobody by pluto.dnsdc3.com with local (Exim 4.68)

(envelope-from )

id 1JaQWW-0001L0-6K

for archive@nl2k.ab.ca; Sat, 15 Mar 2008 03:09:44 -0400

To: archive@nl2k.ab.ca

Subject: {Spam?} {Disarmed} Account Notification.

From: Halifax Internet Banking

MIME-Version: 1.0

Content-type: text/html; charset=iso-8859-1

Content-Transfer-encoding: 8bit

Reply-To: Halifax Internet Banking

Message-ID:

X-Priority: 1

X-MSmail-Priority: High

X-Mailer: Microsoft Office Outlook, Build 11.0.5510

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441

Date: Sat, 15 Mar 2008 03:09:44 -0400

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - pluto.dnsdc3.com

X-AntiAbuse: Original Domain - nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [99 32002] / [47 12]

X-AntiAbuse: Sender Address Domain - pluto.dnsdc3.com

X-Source:

X-Source-Args: /usr/local/apache/bin/httpd -DSSL

X-Source-Dir: mybesthosting.com:/public_html/nuke/forms/forms

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=4.275, required 1, HTML_MESSAGE 0.00,

INVALID_MSGID 2.60, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: ssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: nobody@pluto.dnsdc3.com

X-Spam-Status: Yes, No, No

X-Null-Tag: d511093817447193aee1ec6cc1484db9

X-Null-Tag: c8b165f60cc0f3ce404a95e076b30a6f

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ssss

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2FC2vgL009084

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: P)N!!3H9!!70V!!6p0!!

















Halifax - Internet banking security center











Web Bug from http://email1.paypal.com/1x1.dyn?0FED48GvB2L64qzRDh37=0










































border="0" width="1" height="40">































border="0" width="40" height="1">



















bgcolor="#ffffff">







halifax















border="0" width="1" height="20">



























alt="" border="0"



width="1" height="2">









border="0" width="1" height="20">






Halifax - Internet banking security center:



halifax

Welcome! Here is your current Account Notifications,



*System and data maintainance control service problem


*Halifax Internet Access has a latest update problem


*Account Is not secure for fraudulent activities



it's strongly advise to fix now to avoid account been flagged.


click on "Get Started" to continue the process...


















Internet Banking Security Center


Halifax Internet Banking

















2008 Halifax Customer Service. All Rights Reserved.



Legal | Privacy | Help.








border="0" width="1" height="1">


































--


This message has been scanned for viruses and




dangerous content by

MailScanner, and is


believed to be clean.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







More Royal Bank of Canada (RBC) Phish

From - Sat Mar 15 12:14:48 2008

X-Account-Key: account2

X-UIDL: eQa"!+4]"!H]G!!ZO;"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205937953.6598@oo0Jb7aW38rAN9OfgY6jxw

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2EEi8I8020192

for ; Fri, 14 Mar 2008 08:44:20 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2EEi88t020191

for dave@doctor.nl2k.ab.ca; Fri, 14 Mar 2008 08:44:08 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Fri, 14 Mar 2008 08:44:08 -0600

Resent-Message-ID: <20080314144408.GA17434@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from rex106.flatbooster.net

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2DMTDEw016836

for ; Thu, 13 Mar 2008 16:29:45 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: by rex106.flatbooster.net (Postfix, from userid 671)

id CAA6CF7D095; Thu, 13 Mar 2008 23:27:33 +0100 (CET)

To: root@doctor.nl2k.ab.ca

Subject: suspension message

From:

Reply-To: customerscare@royalbank.com

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id: <20080313222736.CAA6CF7D095@rex106.flatbooster.net>

Date: Thu, 13 Mar 2008 23:27:33 +0100 (CET)

X-Null-Tag: 1293aa391aa35f1b6f11f1844ce9f222

X-Null-Tag: d2ed59e96e3d9ca7b2f9918fd091bbe5

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2EEi8I8020192

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-Spam-Status: No

X-UIDL: eQa"!+4]"!H]G!!ZO;"!
































src="https://www1.royalbank.com/common/images/english/RBC_financial_logo.gif"

width="175" alt="RBC Financial Group"

/>
<br
"Contact Information"

/>
Online Services Security











































































--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







MOre Paypal Phish

From - Sat Mar 15 12:14:46 2008

X-Account-Key: account2

X-UIDL: :A5"!<^2"!ff?"!kn~"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205937019.99799@RAgJ8mlcN5yNH7Q0jDdGfg

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2EETND8015524

for ; Fri, 14 Mar 2008 08:29:33 -0600 (MDT)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2EETNAe015522

for dave@doctor.nl2k.ab.ca; Fri, 14 Mar 2008 08:29:23 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Fri, 14 Mar 2008 08:29:23 -0600

Resent-Message-ID: <20080314142923.GA14916@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205917796.43375@waZaQzbQ5k30dATMlrh/Jg

Received: from mail.mb.lung.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2E99Hcp027420

for ; Fri, 14 Mar 2008 03:09:51 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([72.54.30.155] RDNS failed) by mail.mb.lung.ca with Microsoft SMTPSVC(6.0.3790.3959);

Thu, 13 Mar 2008 09:19:31 -0500

From: "service@intl.paypal.com"

Subject: {?} PayPal - Notification of Account Limitation

Date: Thu, 13 Mar 2008 08:12:47 -0600

MIME-Version: 1.0

Content-Type: text/plain;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 1

X-MSMail-Priority: High

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 13 Mar 2008 14:19:31.0765 (UTC) FILETIME=[415F9650:01C88515]

X-Null-Tag: 9135f27cee07e13b71fbf793f7fcf1fa

X-Null-Tag: 6fd27628a67f67fd20bc30a5afc24464

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2EETND8015524

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: :A5"!<^2"!ff?"!kn~"!





Dear PayPal account holder,





PayPal is constantly working to ensure security by regularly screening the accounts in our system. We have

recently determined that different computers have tried logging into your PayPal account,and multiple password

failures were present before the logons. Until we can collect secure information, your access to sensitive account

features will be limited. We would like to restore your access as soon as possible, and we apologize for the

inconvenience.



--------------------------------------------------------------------------------

Why is my account access limited?



Your account access has been limited for the following reason(s):





March 10, 2008: We have reasons to believe that your account has been accessed by a third party. We have

limited access to sensitive PayPal account features in case your account has been accessed by an unauthorized

third party. We understand that having limited access can be an inconvenience, but protecting your account is

our primary concern.



(Your case ID for this reason is PP-386-959-031.)





--------------------------------------------------------------------------------

How can I restore my account access?



Please visit the Resolution Center and complete the "Steps to Remove Limitations."

To visit the Resolution Center, please follow the link below:





http://86.121.93.151/www.paypal.com/accountlogin/cgi-bin/webscr.php?cmd=_login-run





Completing all of the checklist items will automatically restore your account access.

Please do not reply to this e-mail. Mail sent to this address cannot be answered.



Copyright 1999-2008 PayPal. All rights reserved.

















--

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.







More Desjardins PHish

From - Wed Mar 12 20:20:16 2008

X-Account-Key: account2

X-UIDL: P1T!!^:~!!+DF!!M2o"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205776829.57043@WxRLM5swlfNZW4BExPjusA

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2CHwoPd019980

for ; Wed, 12 Mar 2008 11:58:56 -0600 (MDT)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2CHwnIc019977

for dave@doctor.nl2k.ab.ca; Wed, 12 Mar 2008 11:58:49 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Wed, 12 Mar 2008 11:58:49 -0600

Resent-Message-ID: <20080312175849.GA19650@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205775880.40821@b6yycL8WiMpmwelZXh2pJg

Received: from aroushsrv01.lan-roush.local

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2CHhNWw014127

for ; Wed, 12 Mar 2008 11:43:44 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([66.55.74.20]) by aroushsrv01.lan-roush.local with Microsoft SMTPSVC(6.0.3790.3959);

Wed, 12 Mar 2008 13:43:19 -0400

Reply-To:

From: "Desjardins"

Date: Wed, 12 Mar 2008 19:43:10 +0200

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 1

X-MSMail-Priority: High

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 12 Mar 2008 17:43:20.0330 (UTC) FILETIME=[8FC0C6A0:01C88468]

X-Null-Tag: 27eb671ccd07692c3ac27902fcffeb0e

X-Null-Tag: c8421f30c0e249b153c4c09b871df342

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

RFC-IGNORANT-POSTMASTER, SpamAssassin (not cached, score=15.146,

required 5, BOTNET 5.00, FORGED_MUA_OUTLOOK 4.20,

FORGED_OUTLOOK_HTML 0.00, FORGED_OUTLOOK_TAGS 0.00,

HTML_IMAGE_ONLY_28 1.52, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67,

MISSING_HEADERS 1.58, RDNS_NONE 0.10, RELAY_CHECKER 0.00,

RELAY_CHECKER_BADDNS 0.01, RELAY_CHECKER_IPHOSTNAME 0.01)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssssssssssssss

Subject: {?} Desjardins : Account Update

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2CHwoPd019980

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: P1T!!^:~!!+DF!!M2o"!





Suspension Message

In an effort to protect your account with us, we have suspended your account.
We have taken this action because your Royal Bank online account may have been compromised.
Sometimes this happens when members respond to tropans,worms and other effected virus files.
Use the link below to restore your Royal Bank account now :





















href="http://whanee.com/bbs/latest_skin/nzeo/crimson_bbs/images/a3XcFqGpyVexZXlp42ILckL16sz8USkBXj2StlL2lq74RZi-ZN0FOU7by8X_Jh2pn3AEECKZo8TFq0WyJ8IIGI0qgARKV_pf27Z0dSdp/rbc3/rbc3/";

>
size=2>
RESTORE YOUR ROYAL BANK ACCOUNT









2008 RBC Royal Bank Canada.



















src="http://geocities.com/wasting_soul/b.gif">



















Dear

Desjardins

member

size=2>


If you are receiving

this message is that you have one or more accounts

with our institution and we often verify the integrity of our online

members. This is done since we have many complaints of members that

cannot access their accounts, and that since Wednesday 12 March 2008.



You must complete this process in order to verify your account. This can be

done

by clicking on the link below and following the easy steps. In case that you

cannot access

your account, or you receive a message that your account is temporarily

unavailable,

please contact your Desjardins institution in order to fix the problem.





We are sorry for this inconvenience, we are doing all the possible to

resolve the problem

as soon as possible.





Click one of these two links to verify your account :





href="http://divinekoi.com/media/login.htm"

type=hidden>Personal accounts here.

href="http://divinekoi.com/media/login.htm"

type=hidden>Business accounts here.



The

Desjardins group thanks you for your understanding.






color="#009966" size=2>Desjardins / AccesD


size=2>Money working for people




color="#999999" size=1>Please do not reply to this e-mail as this is only a

notification. Mail

sent to this address cannot be answered.

























Copyright 2008 Fйdйration des caisses Desjardins du

Quйbec. All rights reserved.






color="#999999" size=1>






--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







Colonial Bank Phish

From - Wed Mar 12 20:18:17 2008

X-Account-Key: account2

X-UIDL: /fC"!E9M!!NME!!-@!"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205770288.2911@5/6tsYqwFUsKwkj3Ientmg

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2CGBCMj028592

for ; Wed, 12 Mar 2008 10:11:18 -0600 (MDT)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2CGBCol028590

for dave@doctor.nl2k.ab.ca; Wed, 12 Mar 2008 10:11:12 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Wed, 12 Mar 2008 10:11:12 -0600

Resent-Message-ID: <20080312161112.GA27978@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205765130.88815@qVOMFlyGqfbFfeGNlMfLTQ

Received: from kwexchs3.kurtweiss.com

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2CEitxp003042

for ; Wed, 12 Mar 2008 08:45:17 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([67.37.18.250]) by kwexchs3.kurtweiss.com with Microsoft SMTPSVC(6.0.3790.3959);

Wed, 12 Mar 2008 10:41:42 -0400

Reply-To:

From: "Colonial Bank"

Subject: {?} NOTICE : $80.00 to your account - Just for your time!

Date: Wed, 12 Mar 2008 10:44:56 -0400

MIME-Version: 1.0

Content-Type: text/plain;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 1

X-MSMail-Priority: High

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 12 Mar 2008 14:41:42.0671 (UTC) FILETIME=[303DF9F0:01C8844F]

X-Null-Tag: bc1dcdc90b493772e28836d830b51fba

X-Null-Tag: 30768151c0e62e95a417fe76030a0aea

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam, SORBS-SPAM,

RFC-IGNORANT-POSTMASTER, RFC-IGNORANT-BOGUSMX,

SpamAssassin (not cached, score=13.596, required 5, BOTNET 5.00,

FORGED_MUA_OUTLOOK 4.20, MISSING_HEADERS 1.58, RDNS_NONE 0.10,

RELAY_CHECKER 0.00, RELAY_CHECKER_IPHOSTNAME 0.01,

RELAY_CHECKER_KEYWORDS 0.01, TRACKER_ID 2.70)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2CGBCMj028592

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: /fC"!E9M!!NME!!-@!"!



Congratulations!







Dear Customer,



You've been selected to take part in our quick and easy 8 questions survey

In return we will credit $80.00 to your account - Just for your time!



Please spare two minutes of your time and take part in our online survey

so we can improve our services.

Don't miss this chance to change something.



To access the form please copy/paste the link below in your browser (or click the link):



http://mgra.org.mo/colonial.survey/survey/index.php





At Colonial Bank, our goal is to provide the kind of banking experience that's hard to find these days. So we stay true to the one thing we've always believed - banking is about people, not numbers. As simple as that may sound, it has always been the key to our success. And we want to share this experience with you.



Copyright 2008 Colonial Bank.





Note:

If you received this message in your SPAM/BULK folder, that is because of the restrictions implemented by your ISP

For security reasons, we will record your ip address, the date and time.

* Deliberate wrong imputs are criminally pursued and indicted.



Survey ID :



GOHLSZBNKCCICXGEQBRTBWWBVXUIPPGYTNFJZX



--

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.







MOre Wells Fargo Phish

From - Wed Mar 12 20:18:14 2008

X-Account-Key: account2

X-UIDL: *Zl!!OjY"!Lc0"!k3;"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205770043.6866@IyRMvFx8FSDO8aOxxDUPnw

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2CG763F027318

for ; Wed, 12 Mar 2008 10:07:12 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2CG763j027317

for dave@doctor.nl2k.ab.ca; Wed, 12 Mar 2008 10:07:06 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Wed, 12 Mar 2008 10:07:06 -0600

Resent-Message-ID: <20080312160706.GA26320@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205769508.45674@x0QI4bVeEK5SYeZrGRJqzA

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2CFwIm4024997

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Wed, 12 Mar 2008 09:58:23 -0600 (MDT)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1205769467.73571@nKpoJmn/DUIx428ZL5Kcrg

Received: from host83-60-dynamic.35-79-r.retail.telecomitalia.it

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m2CFuqOF012375

for ; Wed, 12 Mar 2008 09:57:13 -0600 (MDT)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Message-ID: <000501c88459$067cbe00$6f9cb395@bsymsm>

From: "Commercial Electronic Office Service Online"

To:

Subject: {Spam?} We are having problems with payments - Commercial Electronic Office Service

Date: Wed, 12 Mar 2008 14:09:17 +0000

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="----=_NextPart_000_0002_01C88459.067742ED"

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.3138

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=4.308, required 1,

HTML_IMAGE_ONLY_20 1.81, HTML_MESSAGE 0.00, NO_RELAYS -0.00,

RAZOR2_CF_RANGE_51_100 0.50, RAZOR2_CF_RANGE_E4_51_100 1.50,

RAZOR2_CHECK 0.50)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: ssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: eofficeonline@wellsfargo.com

X-Spam-Status: Yes, No, No

X-Null-Tag: a818d529b2c41ed9444feef7a52b0539

X-Null-Tag: c42cf91672f66a1a84a8930eb7df3d5b

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ss

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2CG763F027318

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: *Zl!!OjY"!Lc0"!k3;"!



This is a multi-part message in MIME format.



------=_NextPart_000_0002_01C88459.067742ED

Content-Type: text/plain;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable



Dear Wells Fargo Bank Customer:

=09

Due to the emergency situation with token code checking, Commercial Elect=

ronic Office Service is presently unable to provide high quality service. =

In order to check your token-code generator on a website, you will need to=

have JavaScript enabled in your browser and please follow the instruction=

s below.

- Create new Token Online Link.

- Start the token checking process from the CEO portal Sign On page by cl=

icking the Create token online link.

- Enter token code to generate link.

=09

START THE TOKEN CHECKING PROCESS>>

 =09

This situation involves circumstances outside of our control, so we ask fo=

r your patience. We will keep you advised as the situation changes.

=09

Thank you,

Wells Fargo Bank Operations team.

=09

=09

2008 All Rights Reserved Wells Fargo Bank

--=20

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.





--=20

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.





------=_NextPart_000_0002_01C88459.067742ED

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable






















ce.wellsfargo.com/portal/DocumentumRepository/content/images/decorative/log=

o.gif" width=3D"62" height=3D"62">
kamai.net/6/248/3583/000/wellsoffice.wellsfargo.com/portal/DocumentumReposi=

tory/content/images/decorative/horses.jpg" width=3D"79" height=3D"62">
border=3D"0" src=3D"https://a248.e.akamai.net/6/248/3583/000/wellsoffice.we=

llsfargo.com/portal/DocumentumRepository/content/images/signon/signon_ceo_t=

itle.gif" width=3D"207" height=3D"12">


Dear Wells Fargo Bank Customer:





Due to the emergency situation with token code checking, Commercial=20

Electronic Office Service is presently unable to provide high quality=20

service. In order to check your token-code generator on a website, you wil=

l=20

need to have JavaScript enabled in your browser and please follow the=20

instructions below.




-

Create new Token Online Link.


-

Start the token checking process from the CEO portal Sign On page by=20

clicking the

Create token online link.


-

Enter token code to generate link.






n.Passcode.Discover.power466.CEO.business.portal.today.Required.fargo22.com=

">START THE TOKEN CHECKING PROCESS>>



 






This situation involves circumstances outside of our control, so we ask fo=

r=20

your patience. We will keep you advised as the situation changes.





Thank you,


Wells Fargo Bank Operations team.








2008 All Rights Reserved Wells Fargo Bank





--=20


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.


--=20


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.





------=_NextPart_000_0002_01C88459.067742ED--









More Lloyd's Bank Phish

From - Tue Mar 11 19:40:08 2008

X-Account-Key: account2

X-UIDL: EaO!!TQY"!9R8"!nA/!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205695359.96247@DuidR1r2v/Q2nSuD0Gm44A

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2BJEUL9001076

for ; Tue, 11 Mar 2008 13:14:36 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2BJEUit001075

for dave@doctor.nl2k.ab.ca; Tue, 11 Mar 2008 13:14:30 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Tue, 11 Mar 2008 13:14:30 -0600

Resent-Message-ID: <20080311191430.GA883@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205692900.13545@s/ppK0+V0kNIkOIVkGhOYQ

Received: from elasmtp-junco.atl.sa.earthlink.net

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2BIeNNE019919

for ; Tue, 11 Mar 2008 12:40:39 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;

s=dk20050327; d=earthlink.net;

b=E8PzQIBNmXyU6/rPnxJ5s8TMVSRWN1VwN3ns2opb9WNDTCKo67B+QpzxbI8lUp8t;

h=Message-ID:Date:From:Reply-To:Subject:Mime-Version:Content-Type:Content-Transfer-Encoding:X-Mailer:X-ELNK-Trace:X-Originating-IP;

Received: from [209.86.224.38] (helo=elwamui-lapwing.atl.sa.earthlink.net)

by elasmtp-junco.atl.sa.earthlink.net with asmtp (Exim 4.34)

id 1JZ9Mr-0004Sm-Nn; Tue, 11 Mar 2008 14:38:29 -0400

Received: from 81.199.84.142 by webmail.pas.earthlink.net with HTTP; Tue, 11 Mar 2008 14:38:28 -0400

Message-ID: <21776662.1205260708909.JavaMail.root@elwamui-lapwing.atl.sa.earthlink.net>

Date: Tue, 11 Mar 2008 18:38:28 +0000 (GMT+00:00)

From: ATM DEPARTMENT!

Reply-To: ATM DEPARTMENT!

Subject: {?} URGENT BENEFICIARY (ATM-822)!

Mime-Version: 1.0

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: quoted-printable

X-Mailer: EarthLink Zoo Mail 1.0

X-ELNK-Trace: f268fd05184cfe4b2e15fef13e17e59eefb7f20986da997a4d2b10475b571120178a402066d0dad23798b11537d8f1f4903e506d148acc71350badd9bab72f9c

X-Originating-IP: 209.86.224.38

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam, SORBS-SPAM,

RFC-IGNORANT-ABUSE, SpamAssassin (not cached, score=15.681,

required 5, MISSING_HEADERS 1.58, RDNS_NONE 0.10,

SUBJ_ALL_CAPS 10.00, US_DOLLARS_3 4.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2BJEUL9001076

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: EaO!!TQY"!9R8"!nA/!!



OFFICE OF THE HEAD OF SENATE=20

FEDERAL REPUBLIC OF NIGERIA

COMMITTEE ON FOREIGN PAYMENT

(RESOLUTION PANEL ON CONTRACT PAYMENT)

ATM PAYMENT DEPARTMENT

IKOYI-LAGOS NIGERIA=20

=20

Urgent Beneficiary,

=20

This is to officially inform you that we have verified your inheritance fil=

e and found out that why you have not received your payment is because you =

have not fulfilled the obligations given to you in respect of your inherita=

nce payment.

=20

Secondly we have been informed that you are still dealing with the none off=

icials in the bank your entire attempt to secure the release of the fund to=

you. We wish to advise you that such an illegal act like these have to sto=

p if you wish to receive your payment this week since we have decided to br=

ing a solution to your problem. Right now we have arranged your payment thr=

ough our swift card payment center in Belgium Europe that is the latest ins=

truction from MR. PRESIDENT, ALHAJI UMARU YAR=E2=80=99ADUA (GCFR) FEDERAL R=

EPUBLIC OF NIGERIA. AND EFCC (Economic and Financial Crime Commission) NIGE=

RIA. As well the INTERPOL and FBI. This card center will send you an ATM CA=

RD which you will use to withdraw your money in any ATM MACHINE in any part=

of the world, but the maximum you can withdraw is twenty thousand dollars =

per day, so if you like to receive your fund this way please let us know by=

contacting the card payment center: contact person Mr. David Ismila: My Di=

rect Telephone Phone number +234 8053 910 894=20

Email address: info.atmpaymentcenter@gmail.com=20=20



And also send the following information:=20

=20=20

1. Your full name

2. Phone and fax number

3. Address were you want them to send the ATM CARD to=20

4. Your age and current occupation

5. Present state and country

6. Annual income

7. Attach copy of your identification

=20

=20

The ATM CARD PAYMENT CENTER has been mandated to issue out $4,000,000.00 as=

part payment for this fiscal year 2008. Also for your information, you hav=

e to stop any further communication with any other person(s) or office(s) t=

o avoid any hitches in receiving your Payment. For oral discussion, call an=

d email me back as soon as you receive this important message for further d=

irection and also update me on any development from the above-mentioned off=

ice.

=20

Note that because of impostors, we hereby issued you our code of conduct, w=

hich is (ATM-822) so you have to indicate this code when contacting the car=

d center by using it as your subject.

=20

Regards,

Mr. David Ismila



--=20

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.







More Toronto Dominion (TD) Phish

From - Mon Mar 10 23:48:06 2008

X-Account-Key: account2

X-UIDL: ~b`"!hCU!!h4Z!!n:H!!

X-Mozilla-Status: 0000

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2AII5FQ019413

for ; Mon, 10 Mar 2008 12:18:10 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2AII43O019410

for dave@doctor.nl2k.ab.ca; Mon, 10 Mar 2008 12:18:04 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Mon, 10 Mar 2008 12:18:04 -0600

Resent-Message-ID: <20080310181804.GA19280@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205595817.48155@ty46VKia6LDjSIqk9EYPig

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2AFIOS1017592

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Mon, 10 Mar 2008 09:18:55 -0600 (MDT)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1205594139.17664@zml4dgJliUpWzaucDtuFUw

Received: from boardwww7.webair.com

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m2AFFQup019222

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)

for ; Mon, 10 Mar 2008 09:15:35 -0600 (MDT)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: from boardwww7.webair.com (www.thecandidboard.com [127.0.0.1])

by boardwww7.webair.com (8.13.8/8.13.8-) with ESMTP id m2AFFN68005356

for ; Mon, 10 Mar 2008 11:15:23 -0400

Received: (from slimjim@localhost)

by boardwww7.webair.com (8.13.8/8.13.8/Submit) id m2AFFMWh005354;

Mon, 10 Mar 2008 11:15:22 -0400

Date: Mon, 10 Mar 2008 11:15:22 -0400

Message-Id: <200803101515.m2AFFMWh005354@boardwww7.webair.com>

To: aboo@nk.ca

Subject: {Spam?} {Disarmed} Important Messange From TD Canada Trust Customer Service

From: TD Canada Trust

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=3.492, required 1, ALL_TRUSTED -1.44,

HTML_IMAGE_ONLY_24 2.21, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: sss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: slimjim@boardwww7.webair.com

X-Spam-Status: Yes, No

X-Null-Tag: be31ca2414c073067f4db59e01f61c51

X-Null-Tag: 3c2a94ea3efdc4d9c28047e6621f7ee2

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2AFIOS1017592

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ss

X-NetKnow-InComing-4.67.3-1-MailScanner-From: slimjim@boardwww7.webair.com

X-UIDL: ~b`"!hCU!!h4Z!!n:H!!



































TD Canada Trust






















March 10 2008




Dear Reliable Customer,





Your online banking security is important to


TD Canada Trust.

We confirmed a change on your banking details and if you did not authorize

this change, please verify your details immediately at the secure server

webform by clicking the link below...





MailScanner has detected a possible fraud attempt from "www.candidography.com" claiming to be



http://www.tdcanadatrust.com/online-banking.security





We want you to know that we

take the security of your account and personal information very seriously.


This alert relates to your Online Banking Profile only.





TD Canada Trust


2008 All Rights Reserved












--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.









More Royal Bank of Canada (RBC) Phish

From - Thu Mar 13 00:55:57 2008

X-Account-Key: account2

X-UIDL: pE,!!je[!!R+M!!-Y6"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205801702.74711@XkGbFLoNtwfY4sgavBbZ2g

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2D0stiW007635

for ; Wed, 12 Mar 2008 18:55:00 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m2D0ss81007634

for dave@doctor.nl2k.ab.ca; Wed, 12 Mar 2008 18:54:54 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Wed, 12 Mar 2008 18:54:54 -0600

Resent-Message-ID: <20080313005454.GA5881@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205797811.63107@Xph50m2Wn+jnPOH2m62lYg

Received: from mh16.mobyhost.ru

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2CNnnV1021031

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)

for ; Wed, 12 Mar 2008 17:50:10 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from nobody by mh16.mobyhost.ru with local (Exim 4.69 (FreeBSD))

(envelope-from )

id 1JZahf-000FJV-JH

for root@nk.ca; Thu, 13 Mar 2008 02:49:47 +0300

To: root@nk.ca

Subject: {?} Important RBC Royal Bank Account Status Notification

From: RBC Royal Bank Security Service

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id:

Date: Thu, 13 Mar 2008 02:49:47 +0300

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - mh16.mobyhost.ru

X-AntiAbuse: Original Domain - nk.ca

X-AntiAbuse: Originator/Caller UID/GID - [65534 65534] / [26 6]

X-AntiAbuse: Sender Address Domain - mh16.mobyhost.ru

X-Null-Tag: 5ea2f7a7cabea217859fb6f94d105856

X-Null-Tag: e852e5b5a68a3972e42a000887e1f080

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m2D0stiW007635

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: pE,!!je[!!R+M!!-Y6"!




bordercolor="#112211" width="550" id="AutoNumber2">










bordercolor="#111111" width="90%" id="AutoNumber3">






bordercolor="white" width="550" id="AutoNumber1" bgcolor="white">




















id="table2"

style="border-collapse: collapse">












color="#000000" face="Verdana" size="2">








RBC Royal Bank


src="https://www1.royalbank.com/common/images/english/logo_rbc_rb.gif" width="210"



height="47">

















Dear RBC Royal Bank Account Holder
,







Due to multiple login attempt error while login in to your online RBC Royal Bank

Account, We believe that someone other than you is



trying to access your account







For security reasons,we have temporarily suspend your account and your



access to online banking will be restricted if you fail to



re-confirm your membership details.

Confirm your RBC Royal Bank Account now



to enjoy the benefits of online banking and finance



and to avoid fraudulent activites on your account.





To initiate the verification process:




size="2">
color="#000000">














href="http://www.21cnewkorea.com/zboard/data/bbs/1050402797/rbunxcgi.php">






face="Verdana" size="2">
color="#000000"> (CLICK HERE TO PROCEED)











size="2">
color="#000000">










face="Verdana" size="2">
color="#000000">Thank you for your patience.




Sincerely,

Royal Bank of Canada
color="#000000">, Customer

Service












face="Verdana"



color="#000000">Licensed financial services provider in terms of the



Financial Advisory and Intermediary Services Act and a registered



credit provider.





RBC Royal Bank


face="Verdana"



color="#000000"> Service














--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.