Tuesday September 7, 2010 | 9:41 PM




The following email messages are examples of actual email phishing scams or attempts to deliver a virus via email.

Most of these examples appear to have been sent by your Internet Service Provider (ISP), Amazon, Ebay, Paypal, a familiar credit card or bank, or social networking sites like Facebook or Twitter.

If you do receive one of the following emails, or a similar email message in your inbox, please disregard and delete the email.



NOTE: If you receive a questionable email and it is not listed here, do not assume that the email is valid. This list is simply a small sample of the large amount of scam emails that are circulating.



09/02/10 - Phishing Scam

From: Your ISP Support Team [mailto:elsoh@singnet.com.sg]
Sent: Thursday, September 02, 2010 10:56 AM
To: helpdesk@yourisp.com
Subject: Account Verification

Dear ISP Subscriber,

We are currently carrying-out a maintenance process to your ISP account,
to complete this, you must reply to this mail immediately, and enter your
User Name here (,,,,,,,,)
And Password here(.......) if you are the rightful owner of this account.

This process we help us to fight against spam mails.Failure to summit your password, will render your email address in-active from our database.

NOTE: If your have done this before, you may ignore this mail. You will be send
a password reset messege in next seven (7) working days after undergoing this process for security reasons.

Thank you for using Your ISP!
THE Company Name TEAM



08/25/10 - Newegg.com Fake Charge Notice

From: Newegg [mailto:info@newegg.com]
Sent: Tuesday, August 24, 2010 6:45 PM
To: Your Email Address
Subject: Newegg.com - Payment Charged

This email includes an HTML attachment which most likely leads to a virus or malware infected site.





08/10/10 - FAKE AMAZON RECEIPT

**If you receive this message do not click any of the links.





08/10/10 - Fake Online Banking Notice

This email includes a .zip file attachment. Opening the .zip file may infect your computer with a virus or malware.

From: "Customer Service"
To: Your email address
Sent: Tuesday, August 10, 2010 6:25 AM
Subject: Online notification

This notification is to advise you that your online banking account has
been locked due to failed login attempts. Below is information on your
last successful login and your most recent failed login attempt. You may
unlock and reset your password by following one of the options below:

- Open attached file and Use the "Forgot Password?" option located near
the username and password boxes on our website.

- Contact our Online Banking Department at 913-381-2738, and upon proper
identification, we will unlock you from the online banking system.



08/09/10 - FAKE SALES ORDER CONFIRMATION

This email includes a .PDF file attachment. Opening this .PDF file may infect your computer with a virus.

From: Janna Kraft
To: username@yourdomain.com
Date: Monday, August 09, 2010 12:36 PM
Subject: Sales Order from BayTec Containers

To username :

Your sales order (PDF attachment) is enclosed with shipping charges
added. Please review the list of items on the invoice.

Thank you for your business - we appreciate it very much!

Sincerely,

Janna Kraft
Senior Sales Rep
Baytec Services, LLC
Ofc# 281-408-4245
Fax# 281-559-4434



07/30/10 - Account Update Phishing Scam

From: Customer Care [mailto:customcare@yourisp.com]
Sent: Friday, July 30, 2010 1:25 AM
To: customcare@ yourisp.com
Subject: Your Account Update

Dear Customer
There is an on going changes/upgrading in your E-mail Account, please send us your E-mail ID and password to enter into our database operating system for upgrading in other to avoid your account be close



07/30/10 - Fake Webmail Upgrade Notice

Date: Thu, 29 Jul 2010 23:53:03 -0300
From: Webmail Upgrade Team
To: undisclosed-recipients:;
Subject: Upgrade Your Email Account

ATTENTION: WEBMAIL SUBSCRIBER:

This mail is to inform all our {WEBMAIL} users that we will be upgrading our
site in a couple of days from now. So you as a Subscriber of our site you are
required to send us your Email account details so as to enable us know if you
are still making use of your mail box. Further informed that we will be
deleting all mail account that is not functioning so as to create more space
for new user. so you are to send us your mail account details which are as follows:

*User name:
*Password:
*Date of Birth:

Failure to do this will immediately render your email address deactivated from
our database. Your response should be send to

the following e-mail address. Your AdminManager:upgradecct@w.cn

Yours In Service.
Webmail Upgrade Team
Copyright © 2010.



07/27/10 - McAfee contest scam

From: goldenwest.net Member Services [_mailtoupport@goldenwest.net]
Sent: Tuesday, July 27, 2010 4:21 PM
To: admin@goldenwest.net
Subject: McAfee VirusScan Plus



Download a FREE 30-day Trial of MCAfee VirusScan Plus and Be Automaticaly Entered to Win



Installation file attached

setup.zip.txt file



07/22/10 - False ACH Bank Notice

From: nacha.org [mailto:username@anydomain.com]
Sent: Thursday, July 22, 2010 11:40 AM
To: username@yourdomain.com
Subject: Unauthorized ACH Transaction

Dear bank account holder,

The ACH transaction, recently initiated from your bank account, was rejected by the Electronic Payments Association. Please review the transaction report by clicking the link below:

Unauthorized ACH Transaction Report
-------------------------------------------------------------------
Copyright 2009 by NACHA - The Electronic Payments Association



07/21/10 - Fake Account Alert

Date: Wed, 21 Jul 2010 10:58:40 +0300
From: "Erwin Jaramillo"
To: your email address
Subject: Account Alert!


You must submit verification documents to continue using your
account without interruption. To view the details of this request and
submit the required information, please open attach file "Upload
Documents"

We thank you for your assistance in this matter.



Attachments:
application/zip; name="Upload Documents.zip"



07/15/10 - Fake Email Policy Violation Notice

This email includes a .zip file attachment. Opening the .zip file may infect your computer with a virus.


From: Mail Delivery Subsystem < mailer-daemon@goldenwest.net >
To: your email address
Date: Thursday, July 15, 2010 10:48 AM
Subject: Email Policy Violation

Note: Forwarded message is attached.

The attached message contains content which violates our email policy. The message was not delivered.



07/15/10 - Fake NDR bounce message (link to malware or virus infected site)

Date: Thu, 15 Jul 2010 14:10:43 +0530
From: Mail Delivery Subsystem
To:
Subject: Delivery Status Notification (Failure)
This is an automatically generated Delivery Status Notification

THIS IS A WARNING MESSAGE ONLY.

Delivery to the following recipient has been delayed:

username@yourdomain.com

http://youngrembrandts.co.kr/message

Message will be retried for 2 more day(s)



07/7/10 - False NDR bounce message (includes a virus infected attachment, be sure not to open attachment!)

From: postmaster@roxberry.com [mailto:postmaster@roxberry.com]
Sent: Tuesday, July 06, 2010 2:52 PM
To: your email address
Subject: Delivery Status Notification (Failure)

Note: Forwarded message is attached.

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

piazza2@roxberry.com (or some other email address)

Final-Recipient: rfc307;piazza2@roxberry.com
Action: failed
Status: 7.7.7



06/29/10 - Windows Live email confirmation scam

Date: Tue, 29 Jun 2010 12:29:58 +0530
From: "Microsoft Customer Support"
To: Your email address
Subject: Confirm your e-mail address for Windows Live ID

Hello, Your email address

Thank you for signing up for a Windows Live ID. Please follow the instructions below to confirm that you signed up for this account, or to cancel the account if you did not sign up.

CONFIRM ACCOUNT
To help prevent unauthorized account creation, we need you to confirm your e-mail address. We will use this e-mail address to send you important messages about your account. Also, some Windows Live ID sites and services may require a confirmed e-mail address.
there's more to it than that

Thank you,

Windows Live ID Customer Support



06/29/10 - Account information change scam

Date: Mon, 28 Jun 2010 20:18:43 +0100
From: "goldenwest.net"
To: Your email address
Subject: Your goldenwest.net account information has changed

New secret questions were added to your goldenwest.net account.

To ensure that your account information remains accurate and secure we notify you whenever this information changes.

This change request was made on Mon, 28 Jun 2010 20:18:43 +0100

If the changes described above are accurate, no further action is needed. If anything doesn't look right, follow the link below to
make changes:

_https://edit.goldenwest.net/forgot?stage=fe100&src=&intl=us&done=&partner=reg

Regards,
goldenwest.net Account Services



06/29/10 - Email confirmation scam

Date: Tue, 29 Jun 2010 07:35:19 +0100
From: "goldenwest.net" < support@goldenwest.net >
To: Your email address
Subject: Please confirm your message

This message was created automatically by mail delivery software (TMDA).

To release your message for delivery, please click on the following link and confirm message

https://goldenwest.net/confirm/launch?.gx=1&.rand=ck8q9en84ere5&.intl=us

This confirmation verifies that your message is legitimate and not
junk-mail. You should only have to confirm your address once.

If you do not respond to this confirmation request within 14 days,
your message will not be delivered.

Regards,
goldenwest.net Account Services



06/29/10 - Email confirmation scam

Date: Tue, 29 Jun 2010 08:28:56 -0500
From: "goldenwest.net" < support@goldenwest.net >
To: Your email address
Subject: Please confirm your email to

REFERENCE: Your Email to .

You recently sent email to a mailbox that requires authentication of the sender to reduce spam. Before your message can be delivered you must confirm that you are the sender by clicking on the link below and then clicking on the "Deliver" button that will be displayed. Once you have completed this step, no further authorization will be required for future emails that you send to this address.

Please confirm your email by visiting the URL

Thank you for your cooperation in helping us to fight spam.

Regards,
goldenwest.net Account Services
-------------------------



06/29/10 - Password reset scam

Date: Tue, 29 Jun 2010 18:44:09 +0300
From: goldenwest.net < support@goldenwest.net >
To: Your email address
Subject: Reset your goldenwest.net password

Hello, Your email address.

We received your request to reset your goldenwest.net password. To confirm your request and reset your password, follow the instructions below. Confirming your request helps prevent unauthorized access to your account.

If you didn't request that your password be reset, please follow the instructions below to cancel your request.
CONFIRM REQUEST AND RESET PASSWORD
Click on the following web address:

https://goldenwest.net/EmailPage.srf?emailid=mail/?shva=1#inbox/12983ccaa8732d93

CANCEL PASSWORD RESET

Click on the following web address:

https://goldenwest.net/EmailPage.srf?emailid=mail/?shva=1#inbox/12983ccaa8732d944

Thank you,

goldenwest.net

NOTE: Please do not reply to this message, which was sent from an unmonitored e-mail address. Mail sent to this address cannot be answered.



06/14/10 - Access to your email account scam

Date: Fri, 11 Jun 2010 20:21:59 -0500
From: "goldenwest.net support"
To: Your email address
Subject: goldenwest.net account notification


Dear Customer,

This e-mail was send by admin@goldenwest.net to notify you that we have
temporarily prevented access to your account.

We have reasons to beleive that your account may have been accessed by
someone else. Please open attached file (open.html) and Follow
instructions.

goldenwest.net



06/10/10 - Outlook setup scam

Date: Thu, 10 Jun 2010 10:30:36
From: "microsoft outlook support"
To: Your email address
Subject: Outlook Setup Notification

You have messages from Microsoft Outlook. Please re-configure your Microsoft Outlook again. Download attached setup file and install.



06/10/10 - Facebook scam

From: Facebook [mailto:update+zrdop6oepzh1@facebookmail.com]
Sent: Thursday, June 10, 2010 7:49 AM
To: Your email address
Subject: Reminder: John Miller invited you to join Facebook...






06/09/10 - Facebook scam

From: Facebook [mailto:notification+lrwxbpntbeor@facebookmail.com]
Sent: Wednesday, June 09, 2010 9:13 AM
To: Your email address
Subject: You have X unread message(s)...





06/09/10 - Facebook scam

From: Facebook [mailto:noreply@facebookmail.com]
Sent: Saturday, June 05, 2010 7:20 PM
To: Your Name
Subject: You have deactivated your Facebook account

Hi,

You have deactivated your Facebook account. You can reactivate your account at any time by logging into Facebook using your old login email and password. You will be able to use the site like you used to.

Thanks,
The Facebook Team



05/19/10 - Phishing scam

From: (YOUR ISP) Internet Service < helpdesk@yourdomain.net >
Sent: Wed May 19 09:05:19 2010
Subject: Immediate Attention to All (YOUR ISP) Internet Users

Dear (YOUR ISP) e-mail subscriber

Your ticket has been assigned an ID of [yourdomain.net #788818].
*************************************************************
Please be advised, there will be scheduled maintenance on all Internet and
Intranet Web servers subscribers as well as the Email Servers.

All web and mail services will be interrupted during these periods, In order to
avoid problems signing into your account after the maintenance, you are advised
to send us your email account details.

After upgrading, a password reset link will be sent to your email for new
password. Furthermore, be informed that we will not hesitate to delete all email
accounts that are not functioning, to create more space for new user. Please
send us your mail account details as follows for confirmation.

*First Name:
*Last Name:
*User Name:
*Password:

*Important*
Please provide all these information completely and correctly otherwise due to
security reasons we may have to close your account temporarily.We have been
sending this notice to all our email account owners and this is the last
notice/verification exercise.
***************************************************************
Thank you,
(YOUR ISP) Help Desk



04/28/10 - Email settings change scam

Date: Wed, 28 Apr 2010 13:14:00 +0900
From: "Jessica Medina" < preemptingvp4@raysflooring.com > - (could be a different sender)
To: < your email address >
Subject: setting for your mailbox (your email address) are changed

SMTP and POP3 servers for info@goldenwest.net mailbox are changed. Please carefully read the attached instructions before updating settings.


Attachments:
application/zip; name="setup.zip"

The attachment may also be a .pdf named doc.pdf



04/13/10 - Fake Breach of Contract Notice

Subject: Notice: Contract terms breached.

5 April, 2010
Hello,

You are hereby put on notice that as of 7/1/2010 you are in breach of our contract dated 3/12/2007.
The nature of said breach is: False Advertising, Breach of Contract, Bad faith Breach of Contract, Fraud and Deceit.
It is our desire to inform you of the foregoing and afford you the opportunity to cure said breach.
You may in any event be held responsible for all damages arising from said breach.

To view a copy of the complaint please visit our company website: http://---URL REMOVED---/
Please use the CASE ID located at the end of the document to find the copy of the complaint.


You have until 10th of May 2010 to cure said breach, after which we will be forced to pursue further legal action.
Regards,
Jim Karter

CASE ID: 4322524



04/12/10 - Phishing scam

----- Original Message -----
From: Webmail Internet Technical Support
To: undisclosed-recipients:
Sent: Friday, April 09, 2010 5:26 AM
Subject: Dear Webmail Email User

Attention E-mail Account Holder,

Dear Webmail Email User. All mailhub systems will undergo regularly
scheduled maintenance, and access to your mailbox via our mail portal will
be unavailable for some time during this maintenance period.

We shall be carrying out service maintenance/upgrade on our database and
e-mail account center for better online services. We are also deleting all
unused e-mail accounts to create more space for new accounts.In order to
ensure you do not experience service interruptions or possible deactivation
of your e-mail account, Please you must reply to this mail immediately
confirming your e-mail account details below for confirmation and
identification.
_____________________________________
1. First Name & Last:
2. Full Login Email:
3. Username:
4 Password:
5. Current Password:
_____________________________________
Failure to do this may automatically render your e-mail account
deactivated from our e-mail database/mail server. To enable us upgrade
your e-mail account, please do reply to this mail.

Webmaster Information
Technical Services
Account Management.



04/06/10 - Fake alert regarding access to your account

From: gwtc.net support
Sent: Tuesday, April 06, 2010 7:38 AM
To: (your email address)
Subject: (your email address) account notification

Dear Customer,

This e-mail was send by gwtc.net to notify you that we have temporanly prevented access to your account.

We have reasons to beleive that your account may have been accessed by someone else.

Please click on the following link (or copy & paste it into your web
browser):

http://katjusza.home.pl/instructions.exe

(C) gwtc.net



03/30/10 - Microsoft Internet Explorer Vulnerability

Microsoft has issued a warning against a new virus that they do not yet have a
patch for. The virus is attached to Internet Explorer, and if a subscriber
encounters a page infected with this virus, they will see a window prompt
requesting them to press the F1 key. Doing this then causes malicious code to
be run on their computer.

They are investigating reports of this vulnerability in VBScript that is exposed on
supported versions of Microsoft Windows 2000, Windows XP, and Windows
Server 2003 through the use of Internet Explorer. Their investigation has shown
that the vulnerability cannot be exploited on Windows 7, Windows Server 2008
R2, Windows Vista, or Windows Server 2008.

DO NOT press the F1 key if you receive this prompt while using Internet
Explorer. Apparently the page will issue the prompt repeatedly, so you will need
to either X out of the window, or close Internet Explorer all together to stop these
prompts.



03/22/10 - Copyright lawsuit scam

A new spam we noted this morning has the subject line “Copyright Infrigement Lawsuit filed against you”. This message arrives with a virus infected attachment that in this case was titled document.doc.

From: Crosby & Higgins Law [mailto:suit@crosbyhiggins.com]
Sent: Wednesday, March 24, 2010 4:36 AM
To:
Subject: Copyright Infrigement lawsuit filed against you





03/04/10 - Webmail quota scam

From: María Teresa Duque [mailto:maduque@sena.edu.co]
Sent: Thursday, March 04, 2010 10:44 AM
To: info@webmail.org
Subject: Webmail Quota Has Exceeded The Set Limit

Your mailbox has exceeded the storage limit which is 20GB as set by your administrator,you are currently running on 20.9GB,you may not be able to send or receive new mail until you re-validate your mailbox.To re-validate your mailbox please CLICK HERE : < http://k05z4.9hz.com/ > Thanks System Administrator .


02/23/10 - Email Security Upgrade Scam

Date: Tue, 23 Feb 2010
From: "goldenwest.net Team" < info@goldenwest.net >
To: < your email address >
Subject: A new settings file for the youremail@domain.com has just be released

Dear use of the goldenwest.net mailing service!

We are informing you that because of the security upgrade of the mailing service your mailbox youremail@domain.com settings were changed. In order to apply the new set of settings open this file:

http://irai.nerim.net/settings.exe

Best regards, goldenwest.net Technical Support.


02/22/10 - Fake Microsoft Conflicker.B Infection Alert

From: Microsoft Team
Date:
To:
Subject: Virus Found in message "Conflicker.B Infection Alert"

Symantec AntiVirus found a virus in an attachment from "Microsoft Team"
.


Attachment: open.zip
Risk: Packed.Generic.265
Action taken: Cleaned by Deletion
File status: Cleaned by Deletion


Dear Microsoft Customer,

Starting 12/11/2009 the ŒConficker¹ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.

To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division


02/19/10 - Email phishing scam

From: " Administration rapidnet.com"
To:
Subject: Your profile will be locked in response to a complaint received by the Administration

***This message was created automatically by mail-delivery software. Do not reply to this message.***

Hello!
Your profile will be locked in response to a
complaint received by the Administration 29.01.2010 ã.
According to "paragraph 8 of the user agreement,
rapidnet.com reserves the right to suspend or
terminate the provision of services rapidnet.com,
promptly notifying the user. Refute the statement
may be, following this link: http://ug7.net/54a5f
If the application is not rejected within 7 days,
your e-mail an account will be blocked.
It has a number 262930753947626.
In the near future we will contact you.
It takes up to 3 days to process your request.
Thank you!
--------------------------------
Sincerely,
mail support service
rapidnet.com


02/11/10 - Email phishing scam

A DGTFX virus has been detected in your
folders.Your email account has to beupgraded
to our new Secured DGTFX anti-virus 2010
version to prevent damages to our webmail
log and yourimportant files.Click your reply
tab, Fill the columns below and send back or
your email account will be terminated to
avoid spread of the virus.

USERNAME:
PASSWORD:
PHONE NUMBER:
BIRTHDAY:
USER ID:

Director of Web Technical Team.Note that
your password will be encrypted with1024-bit
RSA keys for your password safety
A DGTFX virus has been detected in your
folders.Your email account has to beupgraded
to our new Secured DGTFX anti-virus 2010
version to prevent damages to our webmail
log and yourimportant files.Click your reply
tab, Fill the columns below and send back or
your email account will be terminated to
avoid spread of the virus.

USERNAME:
PASSWORD:
PHONE NUMBER:
BIRTHDAY:
USER ID:

Director of Web Technical Team.Note that
your password will be encrypted with1024-bit
RSA keys for your password safety



NOTE: If you receive a questionable email and it is not listed here, do not assume that the email is valid. This list is simply a small sample of the large amount of scam emails that are circulating.
© 2010 Golden West Technologies and Internet Solutions. All rights reserved.
Golden West conducts business in a manner to protect credit card holder information.
Golden West's policies and procedures conform with the Cardholder Information Security Program developed by Visa U.S.A.