thats the one ...
I tend to look at every thing in "message source" as i never 100% trust any AV ..so the errors were readily apparent ...still I went through the routine for the pleasure of seeing such a well done forgery .... funnily enough at exactly the same time the BBC were running a radio program on the subject ....of phishing and virii ...
The one thing that they didn't mention was to me the most obvious ...
if its phishing then the server it sends you to is highly unlikely to be https ..so most of the time you only have to look at the address bar of where you get sent to ...
course one or two have put up secured servers but then it's not every day that ebay's ( or your banks ) secure servers are in Russia ...
I actually saw this one time ...!
(re-edited due to truly awfull spelling ...sorry )