from a comment in RaymondC's blog:
Reminds me of a phishing email I got about a year ago. It was the standard "please update your ebay info" thing. (It was obviously fake, since I had no ebay account.)
So I went to the page, to see what they were asking for. Viewing the source was an interesting exercise in stupidity -- lo and behold, right in the middle of the page somewhere, there was a large script tag whose src attribute read "file:///c|/Documents%20and%20Settings/someusername/Desktop/ebay_files/blah.js".
I'm sure it worked fine on the phisher's machine... sigh.