Nationwide Phish

From - Tue Mar 04 13:56:27 2008

X-Account-Key: account2

X-UIDL: 1o[!!$MJ!!\Gn!!g0)!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205070523.43362@wXf/Vg3onvSn65zGXCB47g

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m24DmXIg017402

for ; Tue, 4 Mar 2008 06:48:38 -0700 (MST)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m24DmXFj017399

for dave@doctor.nl2k.ab.ca; Tue, 4 Mar 2008 06:48:33 -0700 (MST)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Tue, 4 Mar 2008 06:48:33 -0700

Resent-Message-ID: <20080304134833.GA16555@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1205053337.28419@DXKQSJOXGyHUfjAWIiQHRw

Received: from bream.servers.rbl-mer.misp.co.uk

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m2491FU7027339

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)

for ; Tue, 4 Mar 2008 02:02:16 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from nobody by bream.servers.rbl-mer.misp.co.uk with local (Exim 4.68)

(envelope-from )

id 1JWT19-0000Zi-EL

for doctor@nl2k.ab.ca; Tue, 04 Mar 2008 09:00:59 +0000

To: doctor@nl2k.ab.ca

Subject: {Spam?} You Have 1 Unread Message

From: Nationwide Building Society

MIME-Version: 1.0

Content-type: text/html; charset=iso-8859-1

Content-Transfer-encoding: 8bit

Reply-To: Nationwide Building Society

Message-ID: <3bcee3b81d79280e7a2313e2ee6df608@>

X-Priority: 1

X-MSmail-Priority: High

X-Mailer: Microsoft Office Outlook, Build 11.0.5510

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1441

Date: Tue, 04 Mar 2008 09:00:59 +0000

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - bream.servers.rbl-mer.misp.co.uk

X-AntiAbuse: Original Domain - nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]

X-AntiAbuse: Sender Address Domain - bream.servers.rbl-mer.misp.co.uk

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=7.557, required 1,

HTML_IMAGE_ONLY_20 1.81, HTML_MESSAGE 0.00,

HTML_TAG_BALANCE_BODY 0.81, INVALID_MSGID 2.60, MIME_HTML_ONLY 1.67,

NO_RELAYS -0.00, URG_BIZ 0.67)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m24DmXIg017402

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: 1o[!!$MJ!!\Gn!!g0)!!



Nationwide Building Society - Security<br /><br /> <br /><br /> <br /><br /> <br /><br /> Alert






src="http://nationwide.co.uk/_common_images/NWlogo.gif">






src="http://nationwide.co.uk/_common_images/headers/proud.gif"s/proud.g



if">









Dear Value Nationwide Customer,





You have



received a new message from Graham Beale Chief Executive


of Nationwide Building Society.













We urgently request that you Should















click







the Sign in to read about
the new development






















href="http://www.pko24.pl/uploads/galery/olb2.nationet.com/signon.html"



>



click here to read











Thank















You

The Nationwide Security Department Team.

PS: To



switch off email notifications of new messages, go to 'My Account'



after you've logged in





















2007 NationWide, Inc. All Rights Reserved.










title="">Services Agreement
| Terms of Use |


href="http://nationwide.co.uk/about_nationwide/membership_matters/cooki



e_and _







privacy_policy/cookie_and_privacy_policy.htm?Source=nationwide&campaign







=footlinks&execution=homepage_privacypolicy " title="">Privacy


















--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.






--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







More RBC Phish

From - Sat Mar 01 18:31:51 2008

X-Account-Key: account2

X-UIDL: 6R!"!H/
X-Mozilla-Status: 0001

X-Mozilla-Status2: 10000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204834936.30694@ocSri2M9CTkwW4hGeUOYJw

Return-Path:

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m21KKrPn003784

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Sat, 1 Mar 2008 13:20:59 -0700 (MST)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1204834812.59083@JNHV3ZOaMEoqJils5QHdpg

Received: from azsongtext.com

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m21KJVFX016399

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)

for ; Sat, 1 Mar 2008 13:20:10 -0700 (MST)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: from apache by azsongtext.com with local (Exim 4.63)

(envelope-from )

id 1JVYNl-0007Wo-Og

for aboo@nk.ca; Sat, 01 Mar 2008 21:32:33 +0100

To: aboo@nk.ca

Subject: {Spam?} {Disarmed} Access Suspended

X-PHP-Script: downloadnext.com/index.php for 82.128.20.79, 82.128.20.79

From: Royal Bank of Canada

Reply-To:

Message-Id:

Date: Sat, 01 Mar 2008 21:32:33 +0100

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=6.985, required 1,

HTML_FONT_FACE_BAD 0.61, HTML_IMAGE_ONLY_24 2.21, HTML_MESSAGE 0.00,

MIME_HTML_ONLY 1.67, NO_RELAYS -0.00, RAZOR2_CF_RANGE_51_100 0.50,

RAZOR2_CF_RANGE_E4_51_100 1.50, RAZOR2_CHECK 0.50)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: ssssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: spawn@downloadnext.com

X-Spam-Status: Yes, Yes

X-Null-Tag: b57ab8b2eced6cb0b5009d5965db5ea5

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m21KKrPn003784

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=3.797, required 1,

HTML_FONT_FACE_BAD 0.61, HTML_IMAGE_ONLY_28 1.52, HTML_MESSAGE 0.00,

MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sss

X-NetKnow-InComing-4.67.3-1-MailScanner-From: spawn@downloadnext.com

X-UIDL: 6R!"!H/
X-Antivirus: AVG for E-mail 7.5.516 [269.21.1/1303]

Mime-Version: 1.0

Content-Type: multipart/mixed; boundary="=======AVGMAIL-47CA03882D90======="



--=======AVGMAIL-47CA03882D90=======

Content-Type: text/html

Content-Transfer-Encoding: 8bit















New Page 1



























Royal Bank of Canada Higher Standards


width="170" height="60">









Dear Royal Bank Customer,





Your access to Online

Services has been suspended due to a miss-match of access code between your

personal security question details. To enable you continue accessing your online account

it will only take you few minutes to re-activate your account. Click on

the reference below and you will be guided to your quick re-activation

page.

MailScanner has detected a possible fraud attempt from "lushu.org" claiming to be



https://www1.royalbank.com/cgi-bin/rbunxcgiREQUEST=ClientSignin.do






Important Notice:- You are strictly advised to match your Personal Security Questions and Answers correctly to avoid service denial.





Thank You.


Royal Bank Group


Online Banking Customer Services







Royal Bank of Canada, N.A. Member FDIC. Equal Housing Lender


docs/images/icon_house.gif" alt="Equal Housing Lender" border="0" height="9" hspace="3" width="14">
© 2007 Royal Bank Financial Group. All rights



reserved.








--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.


--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.











--=======AVGMAIL-47CA03882D90=======

Content-Type: text/plain; x-avg=cert; charset=us-ascii

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "AVG certification"



No virus found in this incoming message.

Checked by AVG Free Edition.

Version: 7.5.516 / Virus Database: 269.21.1/1303 - Release Date: 2/28/2008 1=

2:14 PM



--=======AVGMAIL-47CA03882D90=======--



More Paypal Phish

From - Sun Mar 02 00:46:49 2008

X-Account-Key: account2

X-UIDL: Nf@!!<)P!![V*#!T`E!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204810776.73013@my8kQstSG+Y1ew1nTUoq8w

Return-Path:

Received: from ns8.wistee.fr

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m21DcnrW017084

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)

for ; Sat, 1 Mar 2008 06:39:15 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from dzdedff by ns8.wistee.fr with local (Exim 4.67)

(envelope-from )

id 1JVRv1-0001Z8-1m

for dave@doctor.nl2k.ab.ca; Sat, 01 Mar 2008 14:38:27 +0100

To: dave@doctor.nl2k.ab.ca

Subject: {Spam?} Verifier Votre Compte

X-PHP-Script: dzdedff.ns8-wistee.fr/mailer.php for 81.192.14.221

From: PayPal

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id:

Sender:

Date: Sat, 01 Mar 2008 14:38:27 +0100

X-Wistee-MailScanner-Information: Please contact the ISP for more information

X-Wistee-MailScanner: Found to be clean

X-Wistee-MailScanner-SpamScore: ss

X-Wistee-MailScanner-From: dzdedff@ns8.wistee.fr

X-Spam-Status: No, Yes

X-Null-Tag: c4be2645303876b30eef00e192afaf35

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m21DcnrW017084

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=1.672, required 1, HTML_MESSAGE 0.00,

MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: s

X-NetKnow-InComing-4.67.3-1-MailScanner-From: dzdedff@ns8.wistee.fr

X-UIDL: Nf@!!<)P!![V*#!T`E!!















PayPal
Protgez les informations concernant votre compte
Veillez ne jamais communiquer votre mot de passe des sites frauduleux.

Pour accder de manire scurise au site PayPal ou votre compte, ouvrez une nouvelle session de votre navigateur Internet (Internet Explorer ou Netscape, par exemple) et saisissez l'URL PayPal (https://www.paypal.com/fr/) pour accder au site authentique de PayPal.

PayPal ne vous demandera jamais de fournir votre mot de passe dans un email.

Pour en apprendre plus sur les manires de vous protger contre la fraude, consultez l'Espace scurit. Cliquez sur Espace scurit, en bas de n'importe quelle page du site PayPal.
Protgez votre mot de passe
Ne donnez jamais votre mot de passe PayPal quiconque, y compris au personnel de PayPal.


Cher Membre PayPal,







En raison des mesures de securit que vous offre PayPal, vous tes pri de suivre les tapes fournies et de confirmer vos informations en ligne pour la sret de vos comptes .






Cliquez ici pour commencer la procedure



Cependant, la non-comfirmation de vos informations peut avoir comme consquence la suspension provisoire de compte. Veuillez comprendre que c'est une mesure de scurit prvue pour aider vous protger vous et votre compte. Nous nous excusons pour n'importe quel drangement.





Cordialement
PayPal



Veuillez ne pas rpondre cet email. Les messages reus cette adresse ne sont pas lus et ne reoivent donc aucune rponse. Pour obtenir de l'aide, connectez-vous votre compte PayPal et cliquez sur le lien Aide situ en haut droite de n'importe quelle page PayPal.

Pour recevoir des notifications par email en texte brut plutt qu'au format HTML, mettez vos prfrences jour ici.




Copyright 1999-2007 PayPal. Tous droits rservs.

PayPal (Europe) S. r.l. & Cie, S.C.A.
Socit en Commandite par Actions
Sige social : 22-24 Boulevard Royal, 5me tage, L-2449, Luxembourg
RCS Luxembourg B 118 349


Email PayPal n PP468





--


Ce message a t vrifi par

MailScanner


pour des virus ou des polluriels et rien de


suspect n'a t trouv.


MailScanner remercie transtec pour son soutien.


--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.













More Paypal Phish

From - Sun Mar 02 00:47:50 2008

X-Account-Key: account2

X-UIDL: W']"!?mH!!6H6!!-+M!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204815541.70343@3RWgKIZ8G3kdURIfKBy7JA

Return-Path:

Received: from mcorep06.live.webc.lyceu.net

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m21EwL32026541

for ; Sat, 1 Mar 2008 07:58:40 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from mcorep06.live.webc.lyceu.net (localhost.localdomain [127.0.0.1])

by localhost (Postfix) with ESMTP id 35D8159725

for ; Sat, 1 Mar 2008 14:27:32 +0100 (CET)

Received: from mcorep05.live.webc.lyceu.net (eu2177f.lyceu.net [213.193.2.227])

by mailcore.webc.lyceu.net (Postfix) with ESMTP id 2732059765

for ; Sat, 1 Mar 2008 14:27:31 +0100 (CET)

Received: from eu1396f.lyceu.net (eu1396f.lyceu.net [213.193.2.196])

by mailcore.webc.lyceu.net (Postfix) with ESMTP id 2871434047

for ; Sat, 1 Mar 2008 14:27:30 +0100 (CET)

Received: by eu1396f.lyceu.net (Postfix, from userid 1766249)

id D2A763165F; Sat, 1 Mar 2008 14:27:30 +0100 (CET)

To: dave@doctor.nl2k.ab.ca

Subject: {Spam?} Confirmer Votre Compte PayPal

X-WEBC-Mail-Request-IP: 41.248.3.148

X-WEBC-Mail-From-Script: http://www.petrojanse666.com/Zab.php

From: PayPal

Reply-To: Service@PayPal.Fr

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id: <20080301132730.D2A763165F@eu1396f.lyceu.net>

Date: Sat, 1 Mar 2008 14:27:30 +0100 (CET)

X-Null-Tag: 8b089015267eed5b935f4935fa175400

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m21EwL32026541

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=1.673, required 1, HTML_MESSAGE 0.00,

MIME_HTML_ONLY 1.67)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: s

X-NetKnow-InComing-4.67.3-1-MailScanner-From: webmaster@petrojanse666.com

X-Spam-Status: Yes

X-UIDL: W']"!?mH!!6H6!!-+M!!

















PayPal
Protgez les informations concernant votre compte
Veillez ne jamais communiquer votre mot de passe des sites frauduleux.

Pour accder de manire scurise au site PayPal ou votre compte, ouvrez une nouvelle session de votre navigateur Internet (Internet Explorer ou Netscape, par exemple) et saisissez l'URL PayPal (https://www.paypal.com/fr/) pour accder au site authentique de PayPal.

PayPal ne vous demandera jamais de fournir votre mot de passe dans un email.

Pour en apprendre plus sur les manires de vous protger contre la fraude, consultez l'Espace scurit. Cliquez sur Espace scurit, en bas de n'importe quelle page du site PayPal.
Protgez votre mot de passe
Ne donnez jamais votre mot de passe PayPal quiconque, y compris au personnel de PayPal.


Cher Membre PayPal,







En raison des mesures de securit que vous offre PayPal, vous tes pri de suivre les tapes fournies et de confirmer vos informations en ligne pour la sret de vos comptes .






Cliquez ici pour commencer la procedure



Cependant, la non-comfirmation de vos informations peut avoir comme consquence la suspension provisoire de compte. Veuillez comprendre que c'est une mesure de scurit prvue pour aider vous protger vous et votre compte. Nous nous excusons pour n'importe quel drangement.





Cordialement
PayPal



Veuillez ne pas rpondre cet email. Les messages reus cette adresse ne sont pas lus et ne reoivent donc aucune rponse. Pour obtenir de l'aide, connectez-vous votre compte PayPal et cliquez sur le lien Aide situ en haut droite de n'importe quelle page PayPal.

Pour recevoir des notifications par email en texte brut plutt qu'au format HTML, mettez vos prfrences jour ici.




Copyright 1999-2008 PayPal. Tous droits rservs.

PayPal (Europe) S. r.l. & Cie, S.C.A.
Socit en Commandite par Actions
Sige social : 22-24 Boulevard Royal, 5me tage, L-2449, Luxembourg
RCS Luxembourg B 118 349


Email PayPal n PP468





--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.















More RBC Phish

From - Sat Mar 01 11:47:49 2008

X-Account-Key: account2

X-UIDL: CWV"!3i<"!NT*"!EP2"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204803611.19056@TMlHsqfuE1sWY0fr4OXGOA

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m21Be275001175

for ; Sat, 1 Mar 2008 04:40:08 -0700 (MST)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m21Be2L1001169

for dave@doctor.nl2k.ab.ca; Sat, 1 Mar 2008 04:40:02 -0700 (MST)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Sat, 1 Mar 2008 04:40:01 -0700

Resent-Message-ID: <20080301114001.GA886@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204777119.58154@vXcdq3oAjuYrogiaQ2bCYA

Received: from NicholsonCPA.com

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m214IIPB024402

for ; Fri, 29 Feb 2008 21:18:33 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([62.135.84.245]) by NicholsonCPA.com with Microsoft SMTPSVC(6.0.3790.3959);

Fri, 29 Feb 2008 12:41:48 -0500

Reply-To:

From: "RBC Financial Group"

Subject: {Spam?} {Disarmed} RBC Financial Group

Date: Fri, 29 Feb 2008 19:41:46 +0200

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 29 Feb 2008 17:41:48.0408 (UTC) FILETIME=[5C019780:01C87AFA]

X-TM-AS-Product-Ver: SMEX-7.5.0.1243-5.0.1023-15760.000

X-TM-AS-Result: No--6.889300-5.000000-31

X-TM-AS-User-Approved-Sender: No

X-TM-AS-User-Blocked-Sender: No

X-Null-Tag: a329c4bf59cfa2271e0c37c75c517092

X-Null-Tag: 53d60571e3dcb44f36538ab4bc56e65e

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=12.585, required 1, BOTNET 5.00,

FORGED_MUA_OUTLOOK 4.20, FORGED_OUTLOOK_HTML 0.00,

FORGED_OUTLOOK_TAGS 0.00, HTML_MESSAGE 0.00, MIME_HTML_ONLY 1.67,

MISSING_HEADERS 1.58, RDNS_NONE 0.10, RELAY_CHECKER 0.00,

RELAY_CHECKER_BADDNS 0.01, RELAY_CHECKER_IPHOSTNAME 0.01,

RELAY_CHECKER_KEYWORDS 0.01)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m21Be275001175

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: CWV"!3i<"!NT*"!EP2"!











RBC Royal Bank - Online Banking

















function go() {

var curOption = document.theForm.region.options[document.theForm.region.selectedIndex];

if (curOption.value) {

if (curOption.value != "default") {

window.location.href = curOption.value;

}

}

}







































Online Banking: RBC Online Banking Security Guarantee


































































Bank Online with Confidence

 









We understand how important information security and privacy are to you.





To provide you with greater peace of mind, we have developed the RBC Online Banking Security Guarantee. If an unauthorized transaction is conducted through your RBC Online Banking service, you will be reimbursed 100% for any resulting losses to those accounts.+





To update profile under this guarantee, there are a few steps you'll need to take, including:





  • Sign in your banking account;


  • Insert your personal information correct in the fields.


  • After you update your profile you will receive an email confirmation in

    24h.






For start the update Click Here





Shared Responsibility







+ For a definition of an unauthorized transaction and for full details regarding the protections and limitations of the RBC Online Banking Security Guarantee, please see your Electronic Access Agreement. This guarantee is given by Royal Bank of Canada in connection with its Online Banking service.


































--


This message has been scanned for viruses and




dangerous content by

MailScanner, and is


believed to be clean.







More Halifax Bank Plc Phish

From - Tue Feb 26 20:40:19 2008

X-Account-Key: account2

X-UIDL: e6p"!I5^"!<4f"!hPE"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204489676.58542@uqMBVbNasyu21z5pFXuPiw

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1QKF89g005137

for ; Tue, 26 Feb 2008 13:15:35 -0700 (MST)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m1QJ2XHr006697

for dave@doctor.nl2k.ab.ca; Tue, 26 Feb 2008 12:02:33 -0700 (MST)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Tue, 26 Feb 2008 12:02:33 -0700

Resent-Message-ID: <20080226190233.GD5922@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204477046.22055@/EGrk5+JL2va1kGzLFm5Jw

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1QGulFL018530

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Tue, 26 Feb 2008 09:56:54 -0700 (MST)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1204476983.37674@6zxMWlIabxmBwStZ552YpQ

Received: from krystal.mynet.at

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m1QGu3jN019451

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)

for ; Tue, 26 Feb 2008 09:56:19 -0700 (MST)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: from krystal.mynet.at (localhost.mynet.at [127.0.0.1])

by krystal.mynet.at (8.13.8/8.13.8-) with ESMTP id m1QGu1EU024105

for ; Tue, 26 Feb 2008 17:56:01 +0100 (CET)

(envelope-from www@krystal.mynet.at)

Received: (from www@localhost)

by krystal.mynet.at (8.13.8/8.13.8/Submit) id m1QGu0hc024091;

Tue, 26 Feb 2008 17:56:00 +0100 (CET)

(envelope-from www)

Date: Tue, 26 Feb 2008 17:56:00 +0100 (CET)

Message-Id: <200802261656.m1QGu0hc024091@krystal.mynet.at>

To: doctor@nl2k.ab.ca

Subject: {Spam?} {Disarmed} Online Verification Notice

From: Halifax Bank Plc

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=5.047, required 1, ALL_TRUSTED -1.44,

HTML_IMAGE_ONLY_32 1.32, HTML_MESSAGE 0.00, MIME_HTML_ONLY 1.67,

RAZOR2_CHECK 0.50, TVD_PH_REC 3.00)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: sssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: www@krystal.mynet.at

X-Spam-Status: Yes, Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=3.229, required 1, ALL_TRUSTED -1.44,

HTML_MESSAGE 0.00, MIME_HTML_ONLY 1.67, TVD_PH_REC 3.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sss

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1QKF89g005137

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: e6p"!I5^"!<4f"!hPE"!









Alert












height="682" border="0" align="center" cellspacing="1"

bordercolor="#000066" bgcolor="#D8E0EB" id="AutoNumber1" style="border-collapse: collapse">


































height="79">

height="40">personal & business account

height="171">


Dear Customer









It has come to our attention that your Halifax Online Account Banking Information needs to be updated as part of our Security commitment to protect your account and to reduce theft and fraud on our website.If you could please take 5-10 minutes out of your online experience and update your billing records so that you will not run into any future problems with our online banking service.





However, failure to update your records will result in account suspension. Please update your records on informations with us. Once you have updated your account records, your Halifax Online session will not be interrupted and will continue as normal.





To Get Started,Please Click On :





MailScanner has detected a possible fraud attempt from "www.champsmayet.com" claiming to be https://www.halifax-



online.co.uk/_mem_bin/FormsLogin.aspsource=halifaxcouk





This email was sent by the Halifax Online server to verify



your e-mail address. This is done for your protection , because some of our members will no longer have access to their online banking and we must verify



it. "Know the customer. Care for the customer. Act in the customer's best interest."





Online Security Department




Security Advisor


Halifax PLC.



height="28">
color="#808080">Please do not reply to this e-mail. Mail sent to this address cannot be answered.Halifax Email ID # 1009





--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.


--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.













More RBC Phish

From - Tue Feb 26 17:40:01 2008

X-Account-Key: account2

X-UIDL: >!7!!#kc!!=E(#!/dN!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204474730.97275@BW/ptrZ0oXfVCetuKdqsMA

Received: from exchange.omni1031.com

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1QGHmxt000764

for ; Tue, 26 Feb 2008 09:18:07 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from rbc ([12.7.162.10]) by exchange.omni1031.com with Microsoft SMTPSVC(6.0.3790.3959);

Tue, 26 Feb 2008 11:10:15 -0500

Reply-To:

From: "Royal Bank of Canada"

Subject: {Spam?} Your Online Banking

Date: Tue, 26 Feb 2008 08:17:40 -0800

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 26 Feb 2008 16:10:15.0968 (UTC) FILETIME=[13048200:01C87892]

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1QGHmxt000764

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=13.564, required 1, BOTNET 5.00,

FORGED_MUA_OUTLOOK 4.20, FORGED_OUTLOOK_HTML 0.00, HTML_MESSAGE 0.00,

MIME_HTML_ONLY 1.67, MISSING_HEADERS 1.58, RDNS_NONE 0.10,

RELAY_CHECKER 0.00, RELAY_CHECKER_NORDNS 0.01,

TVD_PH_SUBJ_META 1.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssssssssssss

X-NetKnow-InComing-4.67.3-1-MailScanner-From: customer-alert@rbconlinebanking.com

X-Spam-Status: Yes

X-UIDL: >!7!!#kc!!=E(#!/dN!!









none



















Dear Royal Bank of Canada customer,



This e-mail was sent to you because we have

detected an error in your billing information on file with Internet Banking during

our regular schedule account maintenance and verification. This might be due to either following reasons:





  • A recent change in your personal information (i.e. change of address).  


  • Submitting invalid information during the initial sign up process.


  • An inability to accurately verify your selected option of payment due an internal error with our processors.




Click the link below and confirm your Internet Banking personal information, otherwise your Debit/ATM Card access will become restricted:



Click here



We are very sorry for the incovenience.

©Royal Bank of Canada 2001 - 2007

rbc.com is an online information service operated by Royal Bank of Canada.






--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







Bank of Montreal Phish

From - Tue Feb 26 22:59:57 2008

X-Account-Key: account2

X-UIDL: :LZ"!B)l!!>?\"!(0K!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204497710.8824@Hjq9pqSukBM9WiN6LxB7cQ

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1QMdqct027638

for ; Tue, 26 Feb 2008 15:39:57 -0700 (MST)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m1QMdqqT027637

for dave@doctor.nl2k.ab.ca; Tue, 26 Feb 2008 15:39:52 -0700 (MST)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Tue, 26 Feb 2008 15:39:52 -0700

Resent-Message-ID: <20080226223952.GA27440@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204484901.3963@enV0GFmd/65Gy5GHJyXL4A

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1QJ74i7008433

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Tue, 26 Feb 2008 12:07:10 -0700 (MST)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1204484680.259@xl6GDMBoYD+8gzSpJkW42g

Received: from psa1.webignite.net

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m1QJ4SUn000912

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL)

for ; Tue, 26 Feb 2008 12:04:39 -0700 (MST)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: (qmail 91403 invoked by uid 2525); 26 Feb 2008 07:57:10 -0800

Date: 26 Feb 2008 07:57:10 -0800

Message-ID: <20080226155710.91401.qmail@psa1.webignite.net>

To: root@nk.ca

Subject: {Spam?} Profile Has Been Blocked

X-PHP-Script: adrianaprimadonna.com/images/mail.php for 82.128.6.79, 82.128.6.79

From: Bank of Montreal

Reply-To: profile@bmo.com

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (cached, score=6.616, required 1,

DATE_IN_PAST_03_06 1.39, HTML_IMAGE_ONLY_16 2.50, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: ssssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: anonymous@psa1.webignite.net

X-Spam-Status: Yes, Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=5.926, required 1,

DATE_IN_PAST_03_06 1.39, HTML_IMAGE_ONLY_20 1.81, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssss

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1QMdqct027638

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: :LZ"!B)l!!>?\"!(0K!!










src="https://www1.bmo.com/images/en/bmo_bank_logo_ef.gif"; align=baseline

border=0>














































--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.







More RBC Phish

From - Mon Feb 25 21:39:04 2008

X-Account-Key: account2

X-UIDL: >F/!![67"!NjD"!AEX"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204406869.47067@3JwPB9UTzRFBsHbZ171kgA

Received: from envirosbs.Enviro.local

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1PLPbo2024382

for ; Mon, 25 Feb 2008 14:27:42 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from capitalone ([12.7.162.10]) by envirosbs.Enviro.local with Microsoft SMTPSVC(5.0.2195.6713);

Mon, 25 Feb 2008 12:57:04 -0800

Reply-To:

From: "Royal Bank of Canada"

Subject: {Disarmed} Your Online Banking

Date: Mon, 25 Feb 2008 12:54:36 -0800

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 25 Feb 2008 20:57:05.0250 (UTC) FILETIME=[FA22CC20:01C877F0]

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1PLPbo2024382

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-From: customer-alert@rbconlinebanking.com

X-Spam-Status: No

X-UIDL: >F/!![67"!NjD"!AEX"!









none











Your Online Banking Profile Has Been Blocked

For your security, your online banking profile has been locked
due to inactivity or because of many failed login attempts.





















href="http://supportouranimals.com/adoptions/BMO11/BMO11/BMO11/BMO11/BMO11/BMO11/BMO11/BMO%20BY%20CYBESTER/BMO%20BY%20CYBESTER/bmo/";

>
size=2>
Click Here to re-activate your BMO account









1999 2007 BMO Bank of Montreal. All rights reserved.










Dear Royal Bank of Canada customer,



This e-mail was sent to you because we have

detected an error in your billing information on file with Internet Banking during

our regular schedule account maintenance and verification. This might be due to either following reasons:





  • A recent change in your personal information (i.e. change of address).  


  • Submitting invalid information during the initial sign up process.


  • An inability to accurately verify your selected option of payment due an internal error with our processors.




Click the link below and confirm your Internet Banking personal information, otherwise your Debit/ATM Card access will become restricted:



MailScanner has detected a possible fraud attempt from "0xd1.0x3c.0x07.0x25" claiming to be Click here



We are very sorry for the incovenience.

©Royal Bank of Canada 2001 - 2007

rbc.com is an online information service operated by Royal Bank of Canada.






--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







More RBC Phish

From - Mon Feb 25 19:59:02 2008

X-Account-Key: account2

X-UIDL: $/$#!HW:"!7cZ!!3iN"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204401280.45@Z0rf5Fh1D4DKSKjU1rcm/g

Return-Path:

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1PJsCCO004902

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Mon, 25 Feb 2008 12:54:38 -0700 (MST)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1204401204.7406@HjRxj+DwZDMvBnlzNK4ecw

Received: from host.ohohost.com

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m1PJr01I008038

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)

for ; Mon, 25 Feb 2008 12:53:22 -0700 (MST)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: from apache by host.ohohost.com with local (Exim 4.60)

(envelope-from )

id 1JTj5a-0004EV-3S

for dave@nk.ca; Tue, 26 Feb 2008 02:34:14 +0700

To: dave@nk.ca

Subject: {Spam?} {Disarmed} Royal Bank Security Alert: Re-Confirm Your Banking Profile

X-PHP-Script: www.cmsthailand.com//modules/xfsection/modify.php for 41.219.235.50

From: Royal Bank of Canada

Message-Id: <130746559.207@rbconlinebanking.com>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Date: Tue, 26 Feb 2008 02:34:14 +0700

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (cached, score=5.722, required 1,

HTML_IMAGE_ONLY_16 2.50, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00,

RAZOR2_CHECK 0.50)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: sssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: cmsthai@cmsthailand.com

X-Spam-Status: Yes, Yes

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1PJsCCO004902

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=4.532, required 1,

HTML_IMAGE_ONLY_20 1.81, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ssss

X-NetKnow-InComing-4.67.3-1-MailScanner-From: cmsthai@cmsthailand.com

X-UIDL: $/$#!HW:"!7cZ!!3iN"!




src="https://www1.royalbank.com/common/images/english/logo_rbc_rb.gif" border="0"

width="140" height="49">



Dear Reliable Customer,

For your protection, RBC Royal Bank automatically

alerts customers when personal information

changes on our systems. We notices a changes on your banking details

on our system and if you did

not authorize this changes and you the need

assistance related to this Security Alert, please verify your details immediately

at the secure server webform by clicking the link below..




href="http://www.akersbergagk.se/components/com_docman/rbunxcgi.php"

target="_blank" rel="nofollow">MailScanner has detected a possible fraud attempt from "www.akersbergagk.se" claiming to be http://www.rbc.com/cgi-cin/online-security.Password=logon





Internet Banking

customers can receive other alerts informing

you of important account activity and much more.This alert relates to your Online Banking Profile,

rather than a particular account. The account listed is for verification

purposes only..



(c) Royal Bank of Canada










--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.







Nationwide Phish

From - Tue Feb 26 13:09:56 2008

X-Account-Key: account2

X-UIDL: en;"!VO7!!7#i"!G8J"!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204463103.93616@rC5zk4mt4ARHunwctJDhIA

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1QD4vwo008021

for ; Tue, 26 Feb 2008 06:05:02 -0700 (MST)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m1QD4ugv008014

for dave@doctor.nl2k.ab.ca; Tue, 26 Feb 2008 06:04:56 -0700 (MST)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Tue, 26 Feb 2008 06:04:56 -0700

Resent-Message-ID: <20080226130456.GA7566@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204423232.88682@B3hc1CWjLWzjeDdnIPGF8A

Received: from h115026.serverkompetenz.net

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1Q200CH010984

for ; Mon, 25 Feb 2008 19:00:21 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: (qmail 11622 invoked by uid 521); 23 Feb 2008 17:24:05 -0000

Date: 23 Feb 2008 17:24:05 -0000

Message-ID: <20080223172405.11621.qmail@h115026.serverkompetenz.net>

To: doctor@doctor.nl2k.ab.ca

Subject: {Spam?} Networking Nationwide Updates

From: Security Updates Department

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

X-Null-Tag: c88d0c936a6a5fc0b4867cd7c3e48abe

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=8.191, required 1,

HTML_IMAGE_ONLY_28 1.52, HTML_MESSAGE 0.00, MIME_HTML_ONLY 1.67,

NO_RELAYS -0.00, URIBL_PH_SURBL 5.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1QD4vwo008021

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: en;"!VO7!!7#i"!G8J"!



























Nationwide Logo
src="http://nationwide.co.uk/_common_images/NWlogo.gif" width=206

border=0>proud to be different
src="http://nationwide.co.uk/_common_images/headers/proud.gif" width=199

border=0>







You have 1 new Security Message

Alert!




Dear Customer,






It's our top priority to safeguard your personal

information and to prevent you from fruad.




This new security message is to safeguard and proof

your account ownership with us.




Fellow the reference below to resolve this matter:









Thank you for using Nationwide Bank !

Nationwide Building

Society.









Please do

not reply to this e-mail as this is only a notification. Mail sent to this

address cannot be answered.

Email ID:

544344






This message is intended for UK residents unless otherwise

stated.

--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.















More Desjardins PHish

From - Mon Feb 25 00:41:50 2008

X-Account-Key: account2

X-UIDL: 2^=!!82[!!?Y]"!l$3!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204331764.68249@2QBVLoi3TU5b/GpPVEkLOA

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1P0ZuAn026927

for ; Sun, 24 Feb 2008 17:36:01 -0700 (MST)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m1P0ZuL8026926

for dave@doctor.nl2k.ab.ca; Sun, 24 Feb 2008 17:35:56 -0700 (MST)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Sun, 24 Feb 2008 17:35:56 -0700

Resent-Message-ID: <20080225003556.GB26226@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204327968.60644@GBvdXxtxaqzON1F6c6wxdg

Received: from headfirstinc.com

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1ONWQeg010703

for ; Sun, 24 Feb 2008 16:32:42 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from User ([66.55.74.20]) by headfirstinc.com with Microsoft SMTPSVC(6.0.3790.211);

Sun, 24 Feb 2008 18:06:27 -0500

Reply-To:

From: "Desjardins"

Subject: {Spam?} Desjardins : Account Update !

Date: Mon, 25 Feb 2008 01:06:09 +0200

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 1

X-MSMail-Priority: High

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 24 Feb 2008 23:06:27.0779 (UTC) FILETIME=[E28CF930:01C87739]

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

RFC-IGNORANT-POSTMASTER, SpamAssassin (not cached, score=15.146,

required 1, BOTNET 5.00, FORGED_MUA_OUTLOOK 4.20,

FORGED_OUTLOOK_HTML 0.00, FORGED_OUTLOOK_TAGS 0.00,

HTML_IMAGE_ONLY_28 1.52, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67,

MISSING_HEADERS 1.58, RDNS_NONE 0.10, RELAY_CHECKER 0.00,

RELAY_CHECKER_BADDNS 0.01, RELAY_CHECKER_IPHOSTNAME 0.01)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssssssssssssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1P0ZuAn026927

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: 2^=!!82[!!?Y]"!l$3!!






















src="http://geocities.com/s0ulfly1/bandeau.gif">



















Dear

Desjardins

member

size=2>


If you are receiving

this message is that you have one or more accounts

with our institution and we often verify the integrity of our online

members. This is done since we have many complaints of members that

cannot access their accounts, and that since Sunday 25 February 2008.



You must complete this process in order to verify your account. This can be

done

by clicking on the link below and following the easy steps. In case that you

cannot access

your account, or you receive a message that your account is temporarily

unavailable,

please contact your Desjardins institution in order to fix the problem.





We are sorry for this inconvenience, we are doing all the possible to

resolve the problem

as soon as possible.





Click one of these two links to verify your account :





href="http://www.stacciaburatta.it/des.htm"

type=hidden>Personal accounts here.

href="http://www.stacciaburatta.it/des.htm"

type=hidden>Business accounts here.



The

Desjardins group thanks you for your understanding.






color="#009966" size=2>Desjardins / AccesD


size=2>Money working for people




color="#999999" size=1>Please do not reply to this e-mail as this is only a

notification. Mail

sent to this address cannot be answered.

























Copyright 2008 Fйdйration des caisses Desjardins du

Quйbec. All rights reserved.






color="#999999" size=1>






--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.







WellFargo Phish

From - Mon Feb 25 00:21:22 2008

X-Account-Key: account2

X-UIDL: TpU!!iPC!!BmQ!!pga!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204330482.05966@6ovvmZoFfSShxWiNiJcxIw

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1P0EUQm021127

for ; Sun, 24 Feb 2008 17:14:35 -0700 (MST)

Received: (from root@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m1P0EUxX021126

for dave@doctor.nl2k.ab.ca; Sun, 24 Feb 2008 17:14:30 -0700 (MST)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Sun, 24 Feb 2008 17:14:30 -0700

Resent-Message-ID: <20080225001430.GB17586@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204324870.38289@Bf71v6jsxoLJVwjEHGxkiQ

Received: from gallifrey.nk.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1OMeeZ5026998

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)

for ; Sun, 24 Feb 2008 15:40:49 -0700 (MST)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Watermark: 1204324354.06724@7GxoHR8nQu6RjknKlQIlYg

Received: from server1.friskyhosting.com

by gallifrey.nk.ca (8.14.2/8.14.2) with ESMTP id m1OMWGSH018447

(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)

for ; Sun, 24 Feb 2008 15:32:33 -0700 (MST)

X-Spam-Filter: check_local@gallifrey.nk.ca by digitalanswers.org

Received: from apache by server1.friskyhosting.com with local (Exim 4.67)

(envelope-from )

id 1JTPK9-0007Yw-4Y

for sales@nk.ca; Mon, 25 Feb 2008 06:27:57 +0800

To: sales@nk.ca

X-PHP-Script: muarcity.com//photo/mediatemp/mickoclassdonranker.php for 82.128.35.154

From: Wellsfargo Online Banking

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id:

Date: Mon, 25 Feb 2008 06:27:57 +0800

X-NetKnow-OutGoing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4.67.3-1-MailScanner: Found to be clean

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=5.222, required 1,

HTML_IMAGE_ONLY_16 2.50, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-OutGoing-4.67.3-1-MailScanner-SpamScore: sssss

X-NetKnow-OutGoing-4.67.3-1-MailScanner-From: muarcity@muarcity.com

Subject: {Spam?} {Disarmed} Wellsfargo Bank***Security Alert*** (Unlock Your Online Acces Account)

X-Spam-Status: Yes, Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=5.222, required 1,

HTML_IMAGE_ONLY_16 2.50, HTML_MESSAGE 0.00,

HTML_MIME_NO_HTML_TAG 1.05, MIME_HTML_ONLY 1.67, NO_RELAYS -0.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: sssss

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1P0EUQm021127

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: TpU!!iPC!!BmQ!!pga!!




bordercolor="#111111" width="550" id="AutoNumber2">











bordercolor="#111111" width="100%" id="AutoNumber3">














color="#000080">

Unlock your profile




Security Alert: Our



(2008 Sercive Alert)





For your security, your online banking profile has been locked due to inactivity or because of too many failed login attempts.

Click here and you will automatically unlock your online access account profile.











method="get">












--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.







More Desjardins PHish

From - Sat Feb 23 02:39:31 2008

X-Account-Key: account2

X-UIDL: %Xg!!fXd"!c("#!&::!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204165798.62422@Ta6r0v3vXetNE7iQpk9yJw

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1N2T4uv008197

for ; Fri, 22 Feb 2008 19:29:52 -0700 (MST)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m1N2SYob008157

for dave@doctor.nl2k.ab.ca; Fri, 22 Feb 2008 19:28:34 -0700 (MST)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Fri, 22 Feb 2008 19:28:29 -0700

Resent-Message-ID: <20080223022829.GC5623@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204162776.20711@r8OVSQPUmbysY8LZImGp/Q

Received: from ndtheadquarters.afbi.local

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1N1cGhY026652

for ; Fri, 22 Feb 2008 18:39:31 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from connie ([89.47.113.36]) by ndtheadquarters.afbi.local with Microsoft SMTPSVC(6.0.3790.3959);

Fri, 22 Feb 2008 17:15:30 -0500

From: "AccиsD Service"

Subject: {Disarmed} Alert : Tentative de connexion Innentendu !

Date: Sat, 23 Feb 2008 00:20:19 -0800

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Bcc:

Message-ID:

X-OriginalArrivalTime: 22 Feb 2008 22:15:31.0046 (UTC) FILETIME=[6FC50860:01C875A0]

X-TM-AS-Product-Ver: SMEX-7.5.0.1166-5.0.1023-15746.001

X-TM-AS-Result: No-1.346700-5.000000-31

X-TM-AS-User-Approved-Sender: No

X-TM-AS-User-Blocked-Sender: No

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-Spam-Status: No, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1N2T4uv008197

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: %Xg!!fXd"!c("#!&::!!










Dear Accesd customer,





We recently noticed one or more attempts to log in to your account from a foreign IP address. If you accessed your account


while travelling, the unusual login attempts may have been initiated by you. However, if you did not initiate the logins,


please visit Accesd. as soon as possible to verify your identity.




This is a security measure that will ensure that you are the only person who can access your online account.


Thank you for your patience as we work together to protect your account.









To get started, please click the link below and login to your account:







MailScanner has detected a possible fraud attempt from "dbjinnovations.com" claiming to be https://accesd.desjardins.com/en/accesd



Best Regards,


Desjardins Online Solutions, Security Center














Cher(e)s Accesd client,





Nous avons remarquй rйcemment une ou plusieurs tentatives de connexion а votre compte а partir d'une adresse IP йtrangиre.


Si vous avez accйdй а votre compte En voyage, les tentatives de connexion inhabituel peut avoir йtй initiйe par vous.


Toutefois, si vous n'avez pas йtй а l'origine de la connexion, Sil vous plaоt visitez Accesd. Dиs que possible afin de vйrifier votre identitй.




Ceci est une mesure de sйcuritй visant а garantir que vous кtes la seule personne qui peut accйder а votre compte en ligne.


Nous vous remercions de votre patience pendant que nous travaillons ensemble pour protйger votre compte.









Pour commencer, sil vous plaоt cliquer sur le lien ci-dessous et de vous connecter а votre compte:







MailScanner has detected a possible fraud attempt from "dbjinnovations.com" claiming to be https://accesd.desjardins.com/fr/accesd





Cordialement,


Desjardins Solutions en ligne, Centre de sйcuritй














--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is




believed to be clean.







More Royal Bank of Canada Phish

From - Fri Feb 22 19:10:52 2008

X-Account-Key: account2

X-UIDL: _lm"!;"U!!/@L"!j>+!!

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204137481.317@B4zo1J7S3cOX0w+klEdNmQ

Return-Path:

Received: from doctor.nl2k.ab.ca

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1MIZgqH023854

for ; Fri, 22 Feb 2008 11:36:17 -0700 (MST)

Received: (from doctor@localhost)

by doctor.nl2k.ab.ca (8.14.2/8.14.1/Submit) id m1MIZLHt023783

for dave@doctor.nl2k.ab.ca; Fri, 22 Feb 2008 11:35:21 -0700 (MST)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Fri, 22 Feb 2008 11:35:16 -0700

Resent-Message-ID: <20080222183516.GA22903@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-NetKnow-InComing-4.67.3-1-MailScanner-Watermark: 1204122821.01343@JRRgzKCGQTydBC3xNO1P/g

Received: from web.kuwaitit.net

by doctor.nl2k.ab.ca (8.14.2/8.14.2) with ESMTP id m1MEVafN017368

(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)

for ; Fri, 22 Feb 2008 07:32:47 -0700 (MST)

X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org

Received: from nobody by web.kuwaitit.net with local (Exim 4.69 (FreeBSD))

(envelope-from )

id 1JSYvn-000077-RG

for doctor@nl2k.ab.ca; Fri, 22 Feb 2008 17:31:19 +0300

To: doctor@nl2k.ab.ca

Subject: {Disarmed} {Spam?} {Disarmed} 2008 Security Update

From: RBC Royal Bank

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id:

Date: Fri, 22 Feb 2008 17:31:19 +0300

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - web.kuwaitit.net

X-AntiAbuse: Original Domain - nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [65534 1003] / [26 6]

X-AntiAbuse: Sender Address Domain - web.kuwaitit.net

X-Source: /bin/sh

X-Source-Args: sh -c /usr/sbin/sendmail -t -i

X-Source-Dir: aldabi.com:/public_html/Qadsia/uploads

X-Null-Tag: 36066838f16ba482a9d92f3f31ef42eb

X-Null-Tag: 5206be2097b777f9a8c1523da955057b

X-NetKnow-InComing-4.67.3-1-MailScanner: Found to be clean, Found to be clean

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamCheck: spam,

SpamAssassin (not cached, score=4.668, required 1, HTML_MESSAGE 0.00,

MIME_HTML_ONLY 1.67, NO_RELAYS -0.00, TVD_PH_REC 3.00)

X-NetKnow-InComing-4.67.3-1-MailScanner-SpamScore: ssss

X-Spam-Status: Yes, No

X-NetKnow-InComing-4.67.3-1-MailScanner-Information: Please contact the ISP for more information

X-MailScanner-ID: m1MIZgqH023854

X-NetKnow-InComing-4.67.3-1-MailScanner-From: doctor@doctor.nl2k.ab.ca

X-UIDL: _lm"!;"U!!/@L"!j>+!!



















Dear Customer

















Dear valued Customer,



You have received this alert as a

result of our concern on the


safety of your Online Account for 2008.



 





Due to

a recent upgrade of our online banking security system for 2008,



we are notifying you on the need to Update Your Online Account Information.



This is

done as our continuous commitment to protect our customers account and reduce



the

instance of online fraud on our customers.






 



You are hereby required

to update your online information by filling our secure


online update form in order to secure your account and activate your new

personal



online banking security

alert for 2008.Updating your records enables us serve you better.




 



Once you have updated your account records,

your new personal 





online banking security

alert for 2008 will be automatically activated.


Services will not be interrupted and will continue as usual.



To update and secure your Online

records, click on the following link:





MailScanner has detected definite fraud in the website at "members.lycos.co.uk". Do not trust this website: MailScanner has detected definite fraud in the website at "members.lycos.co.uk". Do not trust this website:





http://www.rbcroyalbank.com/home?screenid=Update_Acct



An email confirmation

will be sent to you within 24hours of activating your new personal



Online banking security

alert for 2008.



Thank You for your understanding.





Accounts Management As outlined in our User

Agreement, rbcroyalbank (R) will


periodically send you information about site changes and enhancements.



Visit our Privacy Policy and User Agreement if

you have any questions.








http://www.rbcroyalbank.com/cm/cs.php?p
rivacy=Href&urlname/cc/terms










--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.