More paypal Phish

From srvce@notification.fi Wed Sep 17 06:30:54 2008

Return-Path: srvce@notification.fi

Received: from vms169131pub.verizon.net

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8HCTUD7002357

for ; Wed, 17 Sep 2008 06:29:36 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([76.192.77.246]) by vms169131.mailsrvcs.net

(Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006))

with ESMTPA id <0K7C006WUAOX56N2@vms169131.mailsrvcs.net> for

root@nk.ca; Wed, 17 Sep 2008 07:29:25 -0500 (CDT)

Date: Wed, 17 Sep 2008 05:29:25 -0700

From: PayPal Security

Subject: {?} Security NOTIFICATION !!!

X-Originating-IP: [76.192.77.246]

To: Undisclosed recipients: ;

Message-id: <0K7C006WXAOX56N2@vms169131.mailsrvcs.net>

MIME-version: 1.0

X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

Content-type: text/plain; charset=Windows-1251

Content-transfer-encoding: QUOTED-PRINTABLE

X-Priority: 3

X-MSMail-priority: Normal

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP

for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8HCTUD7002357

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=6.736, required 5, BAYES_99 3.50,

FORGED_MUA_OUTLOOK 3.12, RDNS_NONE 0.10, RELAY_CHECKER 0.00,

RELAY_CHECKER_IPHOSTNAME 0.01, RELAY_CHECKER_KEYWORDS 0.01)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: ssssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: srvce@notification.fi

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark:

1222086583.60953@o32+RZdkr7ur0deZd5bzkg

X-Spam-Status: Yes





As part of our security measures, we regularly screen activity in the

PayPal system. During a recent screening, we noticed an issue

regarding your account.



For your protection, we have limited access to your account until

additional security measures can be completed. We apologize for any

inconvenience this may cause.





Please update and verify your information by checking the link below:

(if you can't open it just copy the link in your internet browser)





http://www1ppo9678071115.9k.com/users/admin/connection/ssl128/index.htm



We thank you for your prompt attention to this matter. Please

understand that this is a security measure intended to help protect you and

your account. We apologize for any inconvenience.





Sincerely,

PayPal Account Review Department

------------------------------------

Copyright 1999-2008 PayPal. All rights reserved.





--

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.

More paypal Phish

From srvs@notification.no Tue Sep 16 03:43:39 2008

Received: from techtonix.com

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8G9gRSR013661

for ; Tue, 16 Sep 2008 03:42:32 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([67.95.121.2]) by techtonix.com with Microsoft

SMTPSVC(6.0.3790.3959); Tue, 16 Sep 2008 05:28:34 -0400

From: "service@paypal.com"

Subject: {?} You Have 1 New Security Message Alert!

Date: Tue, 16 Sep 2008 04:13:11 -0500

MIME-Version: 1.0

Content-Type: text/plain;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 16 Sep 2008 09:28:34.0140 (UTC)

FILETIME=[9710A9C0:01C917DE]

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP

for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8G9gRSR013661

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, spamhaus-ZEN,

spamhaus-XBL, SBL+XBL, CBL, SpamAssassin (not cached, score=21.219,

required 5, autolearn=spam, BAYES_99 3.50, BOTNET 5.00,

FORGED_MUA_OUTLOOK 3.12, MISSING_HEADERS 1.29,

NORMAL_HTTP_TO_IP 0.00, RCVD_IN_XBL 3.20, RDNS_NONE 0.10,

RELAY_CHECKER 0.00, RELAY_CHECKER_IPHOSTNAME 0.01,

URIBL_PH_SURBL 5.00)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssssssssssssssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: srvs@notification.no

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark:

1221990155.9603@oiBuVPiGkLuvW7GcVxugsQ

X-Spam-Status: Yes



Dear PayPal customer,



As part of our security measures, we regularly screen activity in the PayPal

+system. We recently contacted you after noticing an issue on your account.



Our system detected unusual attempts to log in to your PayPal account from

+diffrent ip locations.



In accordance with PayPal's User Agreement, your account access will remain

+limited until the issue has been resolved. Unfortunately, if access to your

+account remains limited for an extended period of time, it may result in

+further limitations or eventual account closure. We encourage you to log in to

+your PayPal account as soon as possible to help avoid this.



Please update and verify your information by checking the link below:

If you can't open this link from email just copy to your internet browser.



http://66.49.165.226/users/alex/update/account/login.php



Once you log in, you will be provided with steps to restore your account access.+We appreciate your understanding as we work to ensure account safety.



To review your account and some or all of the information that PayPal used to

+make its decision to limit your account access, please visit the Resolution

+Center. If, after reviewing your account information, you seek further

+clarification regarding your account access, please contact PayPal by visiting

+the Help Center and clicking "Contact Us".



We thank you for your prompt attention to this matter. Please understand that

+this is a security measure intended to help protect you and your account. We

+apologize for any inconvenience.



Sincerely,

PayPal Account Review Department



PayPal Email ID PP638





--

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.

Verizon-based Paypal phish

From srvs@notification.no Mon Sep 15 05:15:22 2008

Return-Path: srvs@notification.no

Received: from vms172065pub.verizon.net

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8FBEH43020116

for ; Mon, 15 Sep 2008 05:14:23 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([67.95.121.2]) by vms172065.mailsrvcs.net

(Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006))

with ESMTPA id <0K78002ROHVL8XRF@vms172065.mailsrvcs.net> for

root@nk.ca; Mon, 15 Sep 2008 06:14:12 -0500 (CDT)

Date: Mon, 15 Sep 2008 08:12:10 -0500

From: "service@paypal.com"

Subject: {?} You Have 1 New Security Message Alert!

X-Originating-IP: [67.95.121.2]

To: Undisclosed recipients: ;

Message-id: <0K78002RSHVL8XRF@vms172065.mailsrvcs.net>

MIME-version: 1.0

X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

Content-type: text/plain; charset=Windows-1251

Content-transfer-encoding: 7bit

X-Priority: 3

X-MSMail-priority: Normal

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP

for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8FBEH43020116

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, spamhaus-ZEN,

spamhaus-XBL, SBL+XBL, CBL, SpamAssassin (not cached, score=9.927,

required 5, BAYES_99 3.50, FORGED_MUA_OUTLOOK 3.12,

NORMAL_HTTP_TO_IP 0.00, RCVD_IN_XBL 3.20, RDNS_NONE 0.10,

RELAY_CHECKER 0.00, RELAY_CHECKER_IPHOSTNAME 0.01)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: srvs@notification.no

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark:

1221909269.73737@MAj7E7DsOIKWeuEL/O1ulw

X-Spam-Status: Yes



Dear PayPal customer,



As part of our security measures, we regularly screen activity in the PayPal

+system. We recently contacted you after noticing an issue on your account.



Our system detected unusual attempts to log in to your PayPal account from

+diffrent ip locations.



In accordance with PayPal's User Agreement, your account access will remain

+limited until the issue has been resolved. Unfortunately, if access to your

+account remains limited for an extended period of time, it may result in

+further limitations or eventual account closure. We encourage you to log in to

+your PayPal account as soon as possible to help avoid this.



Please update and verify your information by checking the link below:

If you can't open this link from email just copy to your internet browser.



http://66.49.165.226/users/alex/update/account/login.php



Once you log in, you will be provided with steps to restore your account access.+We appreciate your understanding as we work to ensure account safety.



To review your account and some or all of the information that PayPal used to

+make its decision to limit your account access, please visit the Resolution

+Center. If, after reviewing your account information, you seek further

+clarification regarding your account access, please contact PayPal by visiting

+the Help Center and clicking "Contact Us".



We thank you for your prompt attention to this matter. Please understand that

+this is a security measure intended to help protect you and your account. We

+apologize for any inconvenience.



Sincerely,

PayPal Account Review Department



PayPal Email ID PP638





--

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.

Credit Card Phish

From - Mon Sep 08 13:52:44 2008

X-Account-Key: account2

X-UIDL: >~/"!:p@"!ohn!!`;m"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 10000000

X-Mozilla-Keys:

Return-Path:

Received: from adke172.neoplus.adsl.tpnet.pl

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m886SRDc017063

for ; Mon, 8 Sep 2008 00:28:37 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from [79.184.238.172] by mail.eqm.com; Mon, 8 Sep 2008 07:28:38 +0100

From: "Darrell Acosta"

To:

Subject: {?} {Filename?} Credit card transaction report

Date: Mon, 8 Sep 2008 07:28:38 +0100

Message-ID: <01c91184$8286d700$aceeb84f@tengel>

MIME-Version: 1.0

Content-Type: multipart/mixed;

boundary="----=_NextPart_000_000E_01C91184.8286D700"

X-Priority: 3 (Normal)

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook, Build 10.0.2627

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2741.2600

Importance: Normal

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m886SRDc017063

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be infected

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, spamhaus-ZEN,

spamhaus-PBL, SpamAssassin (not cached, score=11.81, required 5,

BAYES_99 3.50, BOTNET 5.00, RCVD_IN_PBL 3.20, RDNS_NONE 0.10,

RELAY_CHECKER 0.00, RELAY_CHECKER_KEYWORDS 0.01)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: tengel@eqm.com

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221287338.51498@KCinV+xji7IY9jgFVcYlQQ

X-Spam-Status: Yes

X-UIDL: >~/"!:p@"!ohn!!`;m"!



This is a multi-part message in MIME format.



------=_NextPart_000_000E_01C91184.8286D700

Content-Type: text/plain;

charset="iso-8859-1"

Content-Transfer-Encoding: 7bit



Warning: This message has had one or more attachments removed

Warning: (report.doc.exe, Report.zip).

Warning: Please read the "NetKnow-InComing-4-71-10-1-Attachment-Warning.txt" attachment(s) for more information.



Credit card transaction report (Visa, MC)



Dear Valued Customer:



As requested, we are sending you this report on transactions with your credit card completed between 1/1/2008 and 9/1/2008.



The report containing your account details is attached to this message. Please download the attached document to view or print it.



Respectfully,

Darrell Acosta



Manager of Visa / MasterCard

Credit Card Services



________________________________



If you believe this message has reached you by mistake, please forward the document identification number provided on the enclosed report to our customer service department.



------=_NextPart_000_000E_01C91184.8286D700

Content-Type: text/plain;

charset="ISO-8859-1";

name="NetKnow-InComing-4-71-10-1-Attachment-Warning.txt"

Content-Disposition: attachment;

filename="NetKnow-InComing-4-71-10-1-Attachment-Warning.txt"

Content-Transfer-Encoding: quoted-printable



This is a message from the MailScanner E-Mail Virus Protection Service

----------------------------------------------------------------------

The original e-mail attachment "Report.zip"

is on the list of unacceptable attachments for this site and has been

replaced by this warning message.



If you wish to receive a copy of the original attachment, please

e-mail helpdesk and include the whole of this message

in your request. Alternatively, you can call them, with

the contents of this message to hand when you call.



At Mon Sep 8 00:28:58 2008 the virus scanner said:

MailScanner: Windows/DOS Executable (report.doc.exe)

No programs allowed (report.doc.exe)



Note to Help Desk: Look on the NetKnow-InComing-4-71-10-1 (doctor.nl2k.ab.c=

a) MailScanner in /var/spool/MailScanner/quarantine/20080908 (message m886S=

RDc017063).

--=20

Postmaster

NetKnow

www.nk.ca



For all your IT requirements visit: http://www.transtec.co.uk



------=_NextPart_000_000E_01C91184.8286D700--









Western Union Phish

From - Mon Sep 08 13:53:33 2008

X-Account-Key: account2

X-UIDL: @a=!!KS6"!^,i!!^o="!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from jupiter.forumsville.com

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m889Jh2B026643

for ; Mon, 8 Sep 2008 03:19:49 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from nobody by jupiter.forumsville.com with local (Exim 4.69)

(envelope-from )

id 1KccFH-0007iN-0l

for dave@nk.ca; Mon, 08 Sep 2008 04:37:15 -0400

To: dave@nk.ca

Subject: {?} Important Message From Western Union

From: Western Union <>

MIME-Version: 1.0

Content-type: text/html; charset=iso-8859-1

Content-Transfer-encoding: 8bit

Reply-To: Western Union <>

Message-ID:

X-Priority: 1

X-MSmail-Priority: High

X-Mailer: Microsoft Office Outlook, Build 11.0.5510

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441

Date: Mon, 08 Sep 2008 04:37:15 -0400

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - jupiter.forumsville.com

X-AntiAbuse: Original Domain - nk.ca

X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]

X-AntiAbuse: Sender Address Domain - jupiter.forumsville.com

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m889Jh2B026643

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, SORBS-SPAM,

SpamAssassin (not cached, score=15.524, required 5, autolearn=spam,

ADVANCE_FEE_2 1.23, BAYES_99 3.50, DEAR_SOMETHING 1.60,

FH_FROMEML_NOTLD 2.70, FROM_NO_USER 1.48, HTML_IMAGE_ONLY_24 1.55,

HTML_MESSAGE 0.00, HTML_MIME_NO_HTML_TAG 0.10, INVALID_MSGID 1.90,

MIME_HTML_ONLY 1.46, NO_RELAYS -0.00)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssssssssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: nobody@jupiter.forumsville.com

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221297590.60567@PUzfE0V9c0xdt+lub9IWiA

X-Spam-Status: Yes

X-UIDL: @a=!!KS6"!^,i!!^o="!


















>Dear Sir/Madam,



There is an issue with the Western Union Money Transfer in the



amount of $500.000.00(Five Hundred Thousand United State Dollar)



directed in automated teller machine (ATM Card) at the owner of this



email address. The International Monetary Fund contacted us for your



compesation a couple of hours ago


due to your allocated security code.They said that they choose to send



it to an email address instead of a name. We are unable to complete



your ATM delivery to an email
address, so we require some more



information in order to complete this


Delivery .






>Full Name:
Full Contact Address:
Mobile Phone Number:






Occupation:
Sex:
Marital Status:
Age:



p>


In order to effect this delivery, please email via Western



Union
Automated Teller Machine(ATM)Department:


>westernunion@siffinancialsecurity.com


As soon as this information is received,your ATM card Will be



deliver to your doorstep through a Diplomatic Courier Company and the



tracking number will be send to you to enable you to track it down



before it arrival in your country.



NOTE:You are required to reconfirm your full name,house address



where the automated teller machine will be sent.Your valid telephone



number is also needed for easy communication.

The Management Of



Western Union Money Transfer, .


Dispatched This Day
Sincerely,
Mr. Mark Greg.




="return top.js.OpenExtLink(window,event,this)" href="http://www.



westernunion.com/" target="_blank">www.westernunion.com

Western



Union
Welcome to Western Union


Send Money Worldwide
Registered 2008 - 2009 Western Union



Money Transfer All Right Reserved












--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.











More Paypal Phish

From - Sun Sep 07 13:40:52 2008

X-Account-Key: account2

X-UIDL: ]&C!!S~/"!:aa"!iiJ"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with ESMTP id m87DF2xP008049

for ; Sun, 7 Sep 2008 07:15:15 -0600 (MDT)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.3/8.14.3/Submit) id m87CJpk2002637

for dave@doctor.nl2k.ab.ca; Sun, 7 Sep 2008 06:19:51 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Sun, 7 Sep 2008 06:19:51 -0600

Resent-Message-ID: <20080907121951.GA2407@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from backup.art-data.com

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m878wXUo014732

for ; Sun, 7 Sep 2008 02:58:39 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: (qmail 28969 invoked from network); 7 Sep 2008 08:58:30 -0000

Received: from node4.art-data.com (HELO www.pavelduba.cz) (77.93.206.130)

by backup.art-data.com with SMTP; 7 Sep 2008 08:58:30 -0000

Date: Sun, 7 Sep 2008 10:58:30 +0200

To: doctor@doctor.nl2k.ab.ca

From: PayPal

Subject: PayPal Account Verification Needed (Sept. 07, 2008) Issue No.2810831

Message-ID:

X-Priority: 3

X-Mailer: PHPMailer [version 1.73]

Reply-To: , ,

?=

=?iso-8859-1?Q?President,

_COO_and_Director@doctor.nl2k.ab.ca,

"_PayPal_Inc.

?=

=?iso-8859-1?Q?

=C2=A9_Copyright_PayPal_Group_Inc._2008.
"?=

=?iso-8859-1?Q?PayPal_Inc.,

_Registered_in_U.S._No.2468070.

?=

=?iso-8859-1?Q?X-PHP-Script:/font

MIME-Version: 1.0

X-UIDL: ]&C!!S~/"!:aa"!iiJ"!



















Paypal Phish

From srvs@notification.no Sun Sep 14 04:51:24 2008

Return-Path: srvs@notification.no

Received: from vms169131pub.verizon.net

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8EAolcH022922

for ; Sun, 14 Sep 2008 04:50:53 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([67.95.121.2]) by vms169131.mailsrvcs.net

(Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006))

with ESMTPA id <0K760063RM4B5EAE@vms169131.mailsrvcs.net> for

root@nk.ca; Sun, 14 Sep 2008 05:50:42 -0500 (CDT)

Date: Sun, 14 Sep 2008 05:48:45 -0500

From: "service@paypal.com"

Subject: {?} You Have 1 New Security Message Alert!

X-Originating-IP: [67.95.121.2]

To: Undisclosed recipients: ;

Message-id: <0K760063TM4B5EAE@vms169131.mailsrvcs.net>

MIME-version: 1.0

X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

Content-type: text/plain; charset=Windows-1251

Content-transfer-encoding: 7bit

X-Priority: 3

X-MSMail-priority: Normal

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP

for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8EAolcH022922

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, spamhaus-ZEN,

spamhaus-XBL, SBL+XBL, CBL, SpamAssassin (not cached, score=9.927,

required 5, BAYES_99 3.50, FORGED_MUA_OUTLOOK 3.12,

NORMAL_HTTP_TO_IP 0.00, RCVD_IN_XBL 3.20, RDNS_NONE 0.10,

RELAY_CHECKER 0.00, RELAY_CHECKER_IPHOSTNAME 0.01)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: srvs@notification.no

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark:

1221821458.17004@fi6i/EDZ/rEqT4YmsbLW0w

X-Spam-Status: Yes



Dear PayPal customer,



As part of our security measures, we regularly screen activity in the PayPal

+system. We recently contacted you after noticing an issue on your account.



Our system detected unusual attempts to log in to your PayPal account from

+diffrent ip locations.



In accordance with PayPal's User Agreement, your account access will remain

+limited until the issue has been resolved. Unfortunately, if access to your

+account remains limited for an extended period of time, it may result in

+further limitations or eventual account closure. We encourage you to log in to

+your PayPal account as soon as possible to help avoid this.



Please update and verify your information by checking the link below:

If you can't open this link from email just copy to your internet browser.



http://0102.061.0213.017/users/tanner/ssl128/secure24/connection/index.htm



Once you log in, you will be provided with steps to restore your account access.+We appreciate your understanding as we work to ensure account safety.



To review your account and some or all of the information that PayPal used to

+make its decision to limit your account access, please visit the Resolution

+Center. If, after reviewing your account information, you seek further

+clarification regarding your account access, please contact PayPal by visiting

+the Help Center and clicking "Contact Us".



We thank you for your prompt attention to this matter. Please understand that

+this is a security measure intended to help protect you and your account. We

+apologize for any inconvenience.



Sincerely,

PayPal Account Review Department



PayPal Email ID PP638





--

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.

More Paypal Phish

From - Thu Sep 11 16:15:09 2008

X-Account-Key: account2

X-UIDL: N/7"!ghA"!n01"!"[V"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with ESMTP id m8BG8Jmo022256

for ; Thu, 11 Sep 2008 10:08:25 -0600 (MDT)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.3/8.14.3/Submit) id m8BG8J4M022254

for dave@doctor.nl2k.ab.ca; Thu, 11 Sep 2008 10:08:19 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Thu, 11 Sep 2008 10:08:19 -0600

Resent-Message-ID: <20080911160819.GA22127@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from techtonix.com

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8BEKZQi025849

for ; Thu, 11 Sep 2008 08:20:41 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([67.95.121.2]) by techtonix.com with Microsoft SMTPSVC(6.0.3790.3959);

Thu, 11 Sep 2008 08:56:42 -0400

From: "service@paypal.com"

Subject: {?} ** Your account has been flagged! **

Date: Thu, 11 Sep 2008 07:42:14 -0500

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 11 Sep 2008 12:56:42.0625 (UTC) FILETIME=[D6B77F10:01C9140D]

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, spamhaus-ZEN,

spamhaus-XBL, SBL+XBL, CBL, SpamAssassin (not cached, score=19.72,

required 5, autolearn=spam, BAYES_99 3.50, BOTNET 5.00,

FORGED_MUA_OUTLOOK 3.12, FORGED_OUTLOOK_HTML 0.00,

FORGED_OUTLOOK_TAGS 0.00, HTML_IMAGE_ONLY_04 2.04, HTML_MESSAGE 0.00,

MIME_HTML_ONLY 1.46, MISSING_HEADERS 1.29, NORMAL_HTTP_TO_IP 0.00,

RCVD_IN_XBL 3.20, RDNS_NONE 0.10, RELAY_CHECKER 0.00,

RELAY_CHECKER_IPHOSTNAME 0.01)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8BG8Jmo022256

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221581307.47602@GC7b1VglrOPeSUYIleay9Q

X-UIDL: N/7"!ghA"!n01"!"[V"!














--


This message has been scanned for viruses and


dangerous content by



MailScanner, and is


believed to be clean.













FedEx {Hish

From - Tue Sep 09 23:45:05 2008

X-Account-Key: account2

X-UIDL: _+"!k?A!!~mN"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from mail25.svc.cra.dublin.eircom.net

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m89NhHda004748

for ; Tue, 9 Sep 2008 17:43:23 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: (qmail 80323 messnum 16676392 invoked from network[86.43.60.60/webmailbox100.eircom.net]); 9 Sep 2008 23:43:15 -0000

Received: from webmailbox100.eircom.net (86.43.60.60)

by mail25.svc.cra.dublin.eircom.net (qp 80323) with SMTP; 9 Sep 2008 23:43:15 -0000

Date: Wed, 10 Sep 2008 00:43:15 +0100 (IST)

From: FedEx Courier Services

Reply-To: "fedexcourier@mail4me.com"

Message-ID: <28167211.942791221003795904.JavaMail.root@webmailbox100.eircom.net>

Subject: {?} YOUR PENDING PARCEL

MIME-Version: 1.0

Content-Type: text/plain; charset=utf-8

Content-Transfer-Encoding: 7bit

X-Originating-IP: [41.205.166.27]

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m89NhHda004748

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, SORBS-SPAM,

RFC-IGNORANT-ABUSE, SpamAssassin (not cached, score=19.587,

required 5, autolearn=spam, BAYES_99 3.50, MISSING_HEADERS 1.29,

RCVD_IN_SBL 3.20, RELAY_CHECKER 0.00, RELAY_CHECKER_NORDNS 0.01,

SUBJ_ALL_CAPS 10.00, URG_BIZ 1.58)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssssssssssssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: maryoshea03@eircom.net

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221435805.17132@GLHYWQ99STye7zpEeETReA

X-Spam-Status: Yes

X-UIDL: _+"!k?A!!~mN"!



FedEx COURIER SERVICE

No 23 Akpakpava Road,

Edo State. Nigeria.

Fax: +23477598989

Email: fedexcourier@mail4me.com

P.O.Box: 1774, Nigeria. West Africa.



Dear Esteemed Customer:



Greetings from the management of FEDEX COURIER SERIVCES. It pleases us to inform you that we are in possession of your parcel containing $65,000 USD (Sixty Five Thousand United State Dollars) bank draft and a confidential letter.



Your Parcel Identity Number: FID/10/7250D.



The mistake made on the parcel form was that the delivery address was not stated. Your email was extracted from the confidential letter. To verify your personal information and get your full contact address for delivery, you are required to fill the following information below and forward to our dispatch officer as soon as possible to verify and process

the transfer of your parcel:



FULL NAME:

CONTACT ADDRESS:

COUNTRY:

ZIPCODE

GENDER:

AGE:

MARITAL STATUS:

PHONE NUMBER:



NOTE: The sender of this parcel paid the delivery charges but the VAT and insurance fee of $200 USD for security purpose will be paid by you. Do call your dispatch officer

for delivery and also endeavour to quote your parcel identity number for confirmation.



DISPATCH OFFICER:

Name: Mr. Matthew Nkem

Tel: 2347028611344



Thanks for your kind cooperation and expecting your urgent response to this effect.



Note this this email is not monitored.

Get back to us with the contact details provided above.



Yours in Service,

Mrs. Vivian Morhal

Admin Secretary.





--

This message has been scanned for viruses and

dangerous content by MailScanner, and is

believed to be clean.









Laurentian Bank Spam

From - Tue Sep 09 23:55:15 2008

X-Account-Key: account2

X-UIDL: !8R!!]U\!!@9U!!1&,!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with ESMTP id m89NpZFU006411

for ; Tue, 9 Sep 2008 17:51:40 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.3/8.14.3/Submit) id m89NpZph006408

for dave@doctor.nl2k.ab.ca; Tue, 9 Sep 2008 17:51:35 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Tue, 9 Sep 2008 17:51:35 -0600

Resent-Message-ID: <20080909235135.GB6042@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from VEtrasporti.eu

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m89Na4gj003355

for ; Tue, 9 Sep 2008 17:36:11 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([68.213.98.155]) by VEtrasporti.eu with Microsoft SMTPSVC(6.0.3790.3959);

Wed, 10 Sep 2008 01:36:13 +0200

Reply-To:

From: "service@laurentianbank.ca"

Subject: {?} {Disarmed} Security Measure

Date: Tue, 9 Sep 2008 18:32:12 -0500

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 09 Sep 2008 23:36:13.0875 (UTC) FILETIME=[D8F01830:01C912D4]

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=14.487, required 5, autolearn=spam,

BAYES_99 3.50, BOTNET 5.00, FORGED_MUA_OUTLOOK 3.12,

FORGED_OUTLOOK_HTML 0.00, HTML_MESSAGE 0.00, MIME_HTML_ONLY 1.46,

MISSING_HEADERS 1.29, RDNS_NONE 0.10, RELAY_CHECKER 0.00,

RELAY_CHECKER_IPHOSTNAME 0.01, RELAY_CHECKER_KEYWORDS 0.01)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: ssssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m89NpZFU006411

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221436301.21712@j+KzCIKMzRujGlQvl6VCKw

X-UIDL: !8R!!]U\!!@9U!!1&,!!







LBCDirect













function getfocus(){

document.form1.NIdent1.focus();

}



function open_win(theURL,winName,features) {

window.open(theURL,winName,features);

}



function CheckCookies( sLang ) {

var cookiesEnabled = false;

document.cookie = "Enabled=true";

var cookieValid = document.cookie;



if (cookieValid.indexOf("Enabled=true") != -1) {

cookiesEnabled = true;

} else {

cookiesEnabled = false;

}



if (cookiesEnabled) {

return true;

} else {

sUrl1 = "https://www.lbcdirect.laurentianbank.ca/popup_retail/erreur_cookies_";

sUrl2 = ".html";

sUrl = sUrl1 + sLang + sUrl2;

open_win( sUrl,'Error','scrollbars=yes,width=710,height=480,screenX=10,screenY=10,top=10,left=10');

return false;

}

}



















































 





































      
































Dear Laurentian Bank Customer,



It is the last time there is increasing on the Internet phenomenon of "Phishing" which called upon, illegally users

to provide their personal data and confidential.


Is necessary as a security measure to set your "Phone Number" and "E-mail Address" in order to prevent possible fraud.



Sign in branch service via the Internet: MailScanner has detected a possible fraud attempt from "www.psgpoland.com" claiming to be https://www.laurentianbank.ca/





Thank you for using our services.


Regards,


Laurentian Bank of Canada






Contact us at 1 877 522-3863 for more information.

























© Laurentian Bank of Canada, 2000. All Rights Reserved.


Legal Notice, Security and Privacy






























--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.











Llyod's Bank Phish

From - Wed Sep 10 17:58:22 2008

X-Account-Key: account2

X-UIDL: ;KL"!^c)!!O%E!!G11"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from www.mingdaw.com

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8AD1irT001122

for ; Wed, 10 Sep 2008 07:01:51 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from www.mingdaw.com (localhost.mingdaw.com [127.0.0.1])

by www.mingdaw.com (8.13.8/8.13.8-) with ESMTP id m8AD1b6M010633

for ; Wed, 10 Sep 2008 21:01:37 +0800 (CST)

Received: (from www@localhost)

by www.mingdaw.com (8.13.8/8.13.6/Submit) id m8AD1aWO010627;

Wed, 10 Sep 2008 21:01:36 +0800 (CST)

(envelope-from www)

Date: Wed, 10 Sep 2008 21:01:36 +0800 (CST)

To: dave@doctor.nl2k.ab.ca

Subject: {?} Warning Notification

From: Lloyds TSB

MIME-Version: 1.0

Content-type: text/html; charset=iso-8859-1

Reply-To: Lloyds TSB

Message-ID: <4e42a6ff7c547b0454851874eac8ce99@>

X-Priority: 1

X-MSmail-Priority: High

X-Mailer: Microsoft Office Outlook, Build 11.0.5510

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441

X-Spam-Status: No, Yes

Content-Transfer-Encoding: quoted-printable

X-MIME-Autoconverted: from 8bit to quoted-printable by www.mingdaw.com id m8AD1b6M010633

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8AD1irT001122

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=5.058, required 5, ALL_TRUSTED -1.80,

BAYES_99 3.50, HTML_MESSAGE 0.00, INVALID_MSGID 1.90,

MIME_HTML_ONLY 1.46)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssss

X-NetKnow-InComing-4-71-10-1-MailScanner-From: www@mingdaw.com

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221483713.46734@FBngxT+k0p8T6tTs5Hw5xg

X-UIDL: ;KL"!^c)!!O%E!!G11"!




w3.org/TR/html4/loose.dtd">





Lloyds Tsb Alert
















mary=3D"Email Body Layout">































































































































=09=09=09=09





































=09=09=09=09












































ydstsb2004/logos/logo_lloydstsb.gif" alt=3D"Lloyds TSB home">



ages/client/bankofamerica/em_photo.jpg" alt=3D"Customer using a laptop for =

Online Banking">



ages/client/bankofamerica/em_title_red.gif" alt=3D"Online Banking Alert">
td>











=09=09=09=09=09=09

=09=09=09=09=09=09







Account Suspension Notice







g=3D"0">

=09=09=09=09=09=09







Date: 09/10/2008
















Your account have been placed on hold due to errors dectected with yo=

ur memorable information







Your security is important to us. We therefore require you to update y=

our account information on file







Kindly click on the Re-activate Account >> link below to start the upd=

ate process.








" style=3D"color: #d4001a; text-decoration: none; background: #f0f0f0;" tit=

le=3D"Sign in to Lloyds TSB Bank plc Online Banking." target=3D"_blank">Re-=

activate Account










This alert relates to your Online Banking profile, rather than a particu=

lar account. The account listed here is for verification purposes only.=20







=09=09=09=09=09







Want to confirm this email is from Lloyds =

TSB? Sign in to Online Banking and select Alerts History to verify this ale=

rt.










idth=3D"99.6%" height=3D"50px" align=3Dright>















Want to get more alerts? Sign in to your online banking account at Lloyds T=

SB and within the Accounts Overview page select the "Alerts" tab.












width=3D"99.6%" align=3Dright>

















Because email is not a secure form of communication, please =

do not reply to this email.











=09=09=09=09=09=09

Lloyds TSB Bank plc and Lloyds TSB Scotland plc are authorised and re=

gulated by the Financial Services Authority and signatories to the Banking =

Codes. FSA authorisation can be checked on the FSA=E2=80=99s Register. Lloy=

ds TSB Bank plc and Lloyds TSB Scotland plc are members of the Financial Se=

rvices Compensation Scheme and the Financial Ombudsman Service. Lloyds TSB =

Group plc.


=C2=A9 2008 Lloyds TSB. All Rights Reserved.





=09






--=20


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.




--=20


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.













More AOL Phish

From - Fri Sep 12 12:26:36 2008

X-Account-Key: account2

X-UIDL: d%c!!6SE"!QS]!!Q>H"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with ESMTP id m8C1wriS021464

for ; Thu, 11 Sep 2008 19:58:58 -0600 (MDT)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.3/8.14.3/Submit) id m8C1wrVD021463

for dave@doctor.nl2k.ab.ca; Thu, 11 Sep 2008 19:58:53 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Thu, 11 Sep 2008 19:58:53 -0600

Resent-Message-ID: <20080912015853.GA21392@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from variotherm.at

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8BNH7WM006615

for ; Thu, 11 Sep 2008 17:17:15 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([81.148.110.218]) by variotherm.at with Microsoft SMTPSVC(6.0.3790.3959);

Fri, 12 Sep 2008 00:19:43 +0200

Reply-To:

From: "AOL Account"

Subject: {?} {Disarmed} You have 1 new ALERT message.

Date: Thu, 11 Sep 2008 23:03:08 +0100

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2800.1081

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1081

Bcc:

Message-ID:

X-OriginalArrivalTime: 11 Sep 2008 22:19:43.0616 (UTC) FILETIME=[7DC1A800:01C9145C]

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam, RFC-IGNORANT-WHOIS,

SpamAssassin (not cached, score=20.512, required 5, autolearn=spam,

BAYES_99 3.50, BOTNET 5.00, FORGED_MUA_OUTLOOK 3.12,

FORGED_OUTLOOK_HTML 0.00, FORGED_OUTLOOK_TAGS 0.00,

HTML_MESSAGE 0.00, MIME_HTML_ONLY 1.46, MISSING_HEADERS 1.29,

RDNS_NONE 0.10, RELAY_CHECKER 0.00, RELAY_CHECKER_IPHOSTNAME 0.01,

URIBL_OB_SURBL 5.00, XMAILER_MIMEOLE_OL_1ECD5 1.03)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: ssssssssssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8C1wriS021464

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221616739.27772@MKomPUsSJN48mErx+Luj7Q

X-UIDL: d%c!!6SE"!QS]!!Q>H"!















You have 1 new ALERT message




Please renew your AOL Account Verification .




Your Online AOL Account is currently locked.






 




To Login, please click the link below:








Copyright AOL.COM, INC 2008. All rights reserved





--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.









More HSBC Phish

From - Thu Sep 11 17:45:11 2008

X-Account-Key: account2

X-UIDL: 0>0"!FSi"!HeM"!mF$"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Received: from gatormail.us

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8BHc5Rx019682

for ; Thu, 11 Sep 2008 11:38:11 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User (unverified [41.204.233.166])

by gatormail.us (SurgeMail 3.8k4) with ESMTP id 2790-1831578

for multiple; Thu, 11 Sep 2008 11:31:05 -0500

From: "HSBC Online"

Subject: {?} Privacy Policy Update (available September 10)

Date: Thu, 11 Sep 2008 17:33:22 +0100

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Message-ID: <1221150666_2529@gm-svr>

X-Authenticated-User: john@gatormail.us

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8BHc5Rx019682

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-From: onlineservices@hsbc.co.uk

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221586692.84335@zE0w5rMKYXofseQ2TsO/YQ

X-Spam-Status: Yes

X-UIDL: 0>0"!FSi"!HeM"!mF$"!



Dear Customer



Your most recent checking account statement for


ending in is now available to view online.





Customers with Consumer checking accounts: Please note this statement


also contains the 2008 Privacy Policy for Consumers (available September 10).





To access your statement, just click on the link below.


You will be asked to enter your Internet Banking User ID, Date of Birth and Your Security Number.









Click here continue





Thank you,





HSBC Bank


Online Banking Customer Service




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.









More HSBC Phish

From - Fri Sep 12 23:05:15 2008

X-Account-Key: account2

X-UIDL: Qm)!!5
X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with ESMTP id m8CMweEb022028

for ; Fri, 12 Sep 2008 16:58:45 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.3/8.14.3/Submit) id m8CMwd5E022026

for dave@doctor.nl2k.ab.ca; Fri, 12 Sep 2008 16:58:39 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Fri, 12 Sep 2008 16:58:39 -0600

Resent-Message-ID: <20080912225839.GA21954@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from acebroker.com

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8CJuJXa001345

for ; Fri, 12 Sep 2008 13:56:25 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from ([127.0.0.1]) with MailEnable ESMTP; Thu, 11 Sep 2008 12:53:15 -0400

From: "HSBC Online"

Subject: {?} Privacy Policy Update (available September 10)

Date: Thu, 11 Sep 2008 17:52:42 +0100

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Message-ID: <8514C5DF199D40E0B7657CAAB0BCB6C7.MAI@acebroker.com>

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam,

RFC-IGNORANT-POSTMASTER, RFC-IGNORANT-ABUSE,

SpamAssassin (not cached, score=9.466, required 5, BAYES_99 3.50,

FORGED_MUA_OUTLOOK 3.12, FORGED_OUTLOOK_HTML 0.00,

FORGED_OUTLOOK_TAGS 0.00, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 0.10, MIME_HTML_ONLY 1.46,

MISSING_HEADERS 1.29, UNPARSEABLE_RELAY 0.00)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: sssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8CMweEb022028

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221692328.20858@m2+/KweGarbIAi8AgY9ulA

X-UIDL: Qm)!!5


Dear Customer



Your most recent checking account statement for


ending in is now available to view online.





Customers with Consumer checking accounts: Please note this statement


also contains the 2008 Privacy Policy for Consumers (available September 10).





To access your statement, just click on the link below.


You will be asked to enter your Internet Banking User ID, Date of Birth and Your Security Number.









Click here continue





Thank you,





HSBC Bank


Online Banking Customer Service




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.









More Scotia Bank Phish

From - Fri Sep 12 17:55:15 2008

X-Account-Key: account2

X-UIDL: [&_"!cpX!!$e;"!c,h!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with ESMTP id m8CHs5M7025626

for ; Fri, 12 Sep 2008 11:54:10 -0600 (MDT)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.3/8.14.3/Submit) id m8CHs5El025617

for dave@doctor.nl2k.ab.ca; Fri, 12 Sep 2008 11:54:05 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Fri, 12 Sep 2008 11:54:04 -0600

Resent-Message-ID: <20080912175404.GA25511@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from mail.fh.nl

by doctor.nl2k.ab.ca (8.14.3/8.14.3) with SMTP id m8CHiOKZ021753

for ; Fri, 12 Sep 2008 11:44:31 -0600 (MDT)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([81.243.252.202]) by mail.fh.nl with Microsoft SMTPSVC(6.0.3790.3959);

Fri, 12 Sep 2008 17:51:14 +0200

Reply-To:

From: "service@scotiabank.com"

Subject: {?} {Disarmed} Security ways to protect yourself from online threats

Date: Fri, 12 Sep 2008 17:47:27 +0200

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 12 Sep 2008 15:51:14.0953 (UTC) FILETIME=[631FAF90:01C914EF]

X-NetKnow-InComing-4-71-10-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=14.488, required 5, autolearn=spam,

BAYES_99 3.50, BOTNET 5.00, FORGED_MUA_OUTLOOK 3.12,

FORGED_OUTLOOK_HTML 0.00, FORGED_OUTLOOK_TAGS 0.00,

HTML_MESSAGE 0.00, MIME_HTML_ONLY 1.46, MISSING_HEADERS 1.29,

RDNS_NONE 0.10, RELAY_CHECKER 0.00, RELAY_CHECKER_IPHOSTNAME 0.01,

RELAY_CHECKER_KEYWORDS 0.01)

X-NetKnow-InComing-4-71-10-1-MailScanner-SpamScore: ssssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4-71-10-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-InComing-4-71-10-1-MailScanner-ID: m8CHs5M7025626

X-NetKnow-InComing-4-71-10-1-MailScanner-IP-Protocol: IPv4

X-NetKnow-InComing-4-71-10-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-NetKnow-InComing-4-71-10-1-MailScanner-Watermark: 1221674051.58069@sffg7Y0bUFyIJhx4mvkJHg

X-UIDL: [&_"!cpX!!$e;"!c,h!!











































Scotia OnLine









































































































































































  Communications Centre

































































































































 































































































































Dear ScotiaCard Member,








































 
Web Bug from /images/1x1_blackline.gif




















Welcome to "Communications Centre" service.





You may use this service to contact us with enquiries regarding your accounts or the products and services we offer.

>From time to time, we will also use "Communications Centre" to contact you. This may be in relation to existing products

and services which you have with us or to keep you informed of enhancements to our products and services.



Be sure to check "Communications Centre" regularly for any new messages. "Communications Centre" will only retain 30 messages

so you may want to delete those you do not need.



You have 1 new message



To read your message now, please click the Sign-on.



Internet Banking: Sign-on



Sincerily,


Scotiabank


Online Customer Service























































































































































--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.