Yahoo has hijacked my home page

Started by SellieS, October 02, 2014, 07:19:43 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

SellieS

I have windows 7

I had a friend who sent me an email.  She uses Yahoo. 
I looked in Control Panel and cannot find Yahoo.
Also researched some pretty old post with same problem
I use Google for my browser.
Did and Anti Malware run and they found a pup.

winchester73

Are you talking about the addition of Yahoo! Search or just your home page has reset to Yahoo! instead of what you had been using?

Have you already tried re-setting your Google Chrome home page/browser settings?

Startup/home page:  https://support.google.com/chrome/answer/95314?hl=en

Reset browser settings:  https://support.google.com/chrome/answer/3296214?hl=en


If no joy, let's see the logs requested here:  http://www.landzdown.com/analysis-and-malware-removal/log-posting-instructions/
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member

SellieS

I have lost my answers to your questions and thought I started a new post. 
1. Yes I did research including going to programs to find Yahoo and looking at many posts online. I use Google and not google chrome as my browser and home page.
     I have not restarted my computer. I am afraid of the results.
2. I believe this happened 2 days ago when a friend tried to send me an email using Yahoo. She was having problems and does not use the computer generally.
3. I removed a program to fix imported IOS videos and images as I looked for wonky programs.  The name is 'something like Irfra'.  It worked well then suddenly I had to choose codecs and could not fix my videos I removed that feature.


Here are my attachments.
Results of screen317's Security Check version 0.99.87 
Windows 7 Service Pack 1 x64 (UAC is enabled) 
Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Enabled! 
Microsoft Security Essentials   
Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````[/u]
Secunia PSI (3.0.0.2004)   
Adobe Flash Player 15.0.0.152 
Adobe Reader XI 
Mozilla Firefox 23.0 Firefox out of Date! 
Google Chrome 37.0.2062.120 
Google Chrome 37.0.2062.124 
````````Process Check: objlist.exe by Laurent````````[/u] 
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
WinPatrol winpatrol.exe
Ruiware WinPatrol WinPatrol.exe 
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````[/u]



DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17280
Run by Diana at 15:14:31 on 2014-10-02
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.6031.3711 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
SP: Microsoft Security Essentials *Enabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\AsHookDevice.exe
C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
C:\Program Files (x86)\EaseUS\Todo Backup\bin\EuWatch.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\System32\vds.exe
C:\Program Files (x86)\EaseUS\Todo Backup\bin\TrayNotify.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Windows\splwow64.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://search.yahoo.com/yhs/web?hspart=w3i&hsimp=yhs-syctransfer&type=W3i_SP,204,0_0,StartPage,20140940,19891,0,31,6944
uProxyOverride = <-loopback>
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [WinPatrol] C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe -expressboot
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [EaseUs Watch] "C:\Program Files (x86)\EaseUS\Todo Backup\bin\EuWatch.exe"
mRun: [EaseUs Tray] "C:\Program Files (x86)\EaseUS\Todo Backup\bin\TrayNotify.exe"
mRun: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [MapsGalaxy EPM Support] "C:\PROGRA~2\MAPSGA~2\bar\1.bin\39medint.exe" T8EPMSUP.DLL,S
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\Diana\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{59695647-A96B-44F9-B00A-07A63E9F4A60} : DHCPNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
x64-Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Diana\AppData\Roaming\Mozilla\Firefox\Profiles\tom6abi5.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
.
============= SERVICES / DRIVERS ===============
.
R0 EUBAKUP;EUBAKUP;C:\Windows\System32\drivers\eubakup.sys [2012-3-21 57480]
R0 EUBKMON;EUBKMON;C:\Windows\System32\drivers\EUBKMON.sys [2012-3-21 48264]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2014-7-17 269008]
R1 EUDSKACS;EUDSKACS;C:\Windows\System32\drivers\eudskacs.sys [2012-3-21 19592]
R1 EUFDDISK;EUFDDISK;C:\Windows\System32\drivers\EuFdDisk.sys [2012-3-21 189576]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-11 140672]
R2 Device Handle Service;Device Handle Service;C:\Windows\SysWOW64\AsHookDevice.exe [2010-8-2 203392]
R2 EaseUS Agent;EaseUS Agent;C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2012-3-21 61064]
R2 Guard Agent;Guard Agent;C:\Program Files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe [2012-3-21 23176]
R2 IntuitUpdateServiceV4;Intuit Update Service v4;C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2011-8-25 13672]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-3-20 125584]
R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2012-6-27 1326176]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2012-6-27 681056]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-8-2 2314240]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-8-2 56344]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-8-2 271872]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-8-22 368624]
R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf.sys [2011-12-16 17976]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;C:\Windows\System32\drivers\BVRPMPR5a64.SYS [2012-5-10 35840]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-8-2 61280]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2009-8-6 704864]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-9-13 111616]
S3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;C:\Windows\System32\drivers\netr28x.sys [2009-6-10 620544]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-5-2 19456]
S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2012-6-10 31800]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-5-2 56832]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2014-7-28 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-6-9 1255736]
.
=============== File Associations ===============
.
FileExt: .js: JSFile=C:\Windows\System32\WScript.exe "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2014-10-02 16:47:26   11578928   ----a-w-   C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{133BD870-7CEC-466E-B500-F3E68B86F4D9}\mpengine.dll
2014-10-02 10:45:50   11578928   ----a-w-   C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-10-01 11:36:08   371712   ----a-w-   C:\Windows\System32\qdvd.dll
2014-10-01 11:36:07   519680   ----a-w-   C:\Windows\SysWow64\qdvd.dll
2014-10-01 09:06:23   1188440   ------w-   C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{19CA32E7-689E-43A0-B530-05C6A00CD695}\gapaengine.dll
2014-09-27 07:32:23   539984   ----a-w-   C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2014-09-26 08:43:08   1188440   ------w-   C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4C8C265F-28E3-4290-AC15-81C480E1126D}\gapaengine.dll
2014-09-23 22:07:15   2048   ----a-w-   C:\Windows\SysWow64\tzres.dll
2014-09-23 22:07:15   2048   ----a-w-   C:\Windows\System32\tzres.dll
2014-09-20 05:28:04   --------   d-----w-   C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-20 05:28:04   --------   d-----w-   C:\Program Files\iTunes
2014-09-20 05:28:04   --------   d-----w-   C:\Program Files\iPod
2014-09-20 05:28:04   --------   d-----w-   C:\Program Files (x86)\iTunes
2014-09-20 05:23:15   159744   ----a-w-   C:\Program Files\Internet Explorer\Plugins\npqtplugin5.dll
2014-09-20 05:23:15   159744   ----a-w-   C:\Program Files\Internet Explorer\Plugins\npqtplugin4.dll
2014-09-20 05:23:15   159744   ----a-w-   C:\Program Files\Internet Explorer\Plugins\npqtplugin3.dll
2014-09-20 05:23:15   159744   ----a-w-   C:\Program Files\Internet Explorer\Plugins\npqtplugin2.dll
2014-09-20 05:23:15   159744   ----a-w-   C:\Program Files\Internet Explorer\Plugins\npqtplugin.dll
2014-09-20 05:17:19   --------   d-----w-   C:\ProgramData\Applications
2014-09-20 04:00:11   --------   d-----w-   C:\Users\Diana\AppData\Roaming\IrfanView
2014-09-13 07:01:22   2777088   ----a-w-   C:\Windows\System32\msmpeg2vdec.dll
2014-09-13 07:01:22   2285056   ----a-w-   C:\Windows\SysWow64\msmpeg2vdec.dll
2014-09-12 09:43:10   227728   ----a-w-   C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll
2014-09-12 08:54:57   793600   ----a-w-   C:\Windows\SysWow64\TSWorkspace.dll
2014-09-12 08:54:57   1031168   ----a-w-   C:\Windows\System32\TSWorkspace.dll
2014-09-12 08:54:45   2565120   ----a-w-   C:\Windows\System32\d3d10warp.dll
2014-09-12 08:54:45   1987584   ----a-w-   C:\Windows\SysWow64\d3d10warp.dll
2014-09-12 08:54:25   578048   ----a-w-   C:\Windows\System32\aepdu.dll
2014-09-12 08:54:24   424448   ----a-w-   C:\Windows\System32\aeinv.dll
.
==================== Find3M  ====================
.
2014-10-02 06:30:11   122584   ----a-w-   C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-09-24 18:26:29   71344   ----a-w-   C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-09-24 18:26:29   701104   ----a-w-   C:\Windows\SysWow64\FlashPlayerApp.exe
2014-09-22 06:42:39   278152   ------w-   C:\Windows\System32\MpSigStub.exe
2014-08-23 02:07:00   404480   ----a-w-   C:\Windows\System32\gdi32.dll
2014-08-23 01:45:55   311808   ----a-w-   C:\Windows\SysWow64\gdi32.dll
2014-08-23 00:59:01   3163648   ----a-w-   C:\Windows\System32\win32k.sys
2014-08-18 22:29:49   2724864   ----a-w-   C:\Windows\System32\mshtml.tlb
2014-08-18 22:29:35   4096   ----a-w-   C:\Windows\System32\ieetwcollectorres.dll
2014-08-18 22:19:53   5833728   ----a-w-   C:\Windows\System32\jscript9.dll
2014-08-18 22:15:34   547328   ----a-w-   C:\Windows\System32\vbscript.dll
2014-08-18 22:15:09   66048   ----a-w-   C:\Windows\System32\iesetup.dll
2014-08-18 22:14:38   48640   ----a-w-   C:\Windows\System32\ieetwproxystub.dll
2014-08-18 22:14:10   83968   ----a-w-   C:\Windows\System32\MshtmlDac.dll
2014-08-18 22:08:55   4232704   ----a-w-   C:\Windows\SysWow64\jscript9.dll
2014-08-18 22:03:47   139264   ----a-w-   C:\Windows\System32\ieUnatt.exe
2014-08-18 22:03:37   111616   ----a-w-   C:\Windows\System32\ieetwcollector.exe
2014-08-18 22:03:01   758272   ----a-w-   C:\Windows\System32\jscript9diag.dll
2014-08-18 21:57:44   2724864   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2014-08-18 21:56:17   940032   ----a-w-   C:\Windows\System32\MsSpellCheckingFacility.exe
2014-08-18 21:46:26   454656   ----a-w-   C:\Windows\SysWow64\vbscript.dll
2014-08-18 21:45:23   61952   ----a-w-   C:\Windows\SysWow64\iesetup.dll
2014-08-18 21:45:12   72704   ----a-w-   C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-08-18 21:44:44   51200   ----a-w-   C:\Windows\SysWow64\ieetwproxystub.dll
2014-08-18 21:44:09   61952   ----a-w-   C:\Windows\SysWow64\MshtmlDac.dll
2014-08-18 21:36:07   112128   ----a-w-   C:\Windows\SysWow64\ieUnatt.exe
2014-08-18 21:35:24   597504   ----a-w-   C:\Windows\SysWow64\jscript9diag.dll
2014-08-18 21:23:17   2104832   ----a-w-   C:\Windows\System32\inetcpl.cpl
2014-08-18 21:23:16   1249280   ----a-w-   C:\Windows\System32\mshtmlmedia.dll
2014-08-18 21:22:48   60416   ----a-w-   C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-08-18 21:15:13   2310656   ----a-w-   C:\Windows\System32\wininet.dll
2014-08-18 21:08:54   2014208   ----a-w-   C:\Windows\SysWow64\inetcpl.cpl
2014-08-18 21:07:44   1068032   ----a-w-   C:\Windows\SysWow64\mshtmlmedia.dll
2014-08-18 20:46:48   1812992   ----a-w-   C:\Windows\SysWow64\wininet.dll
2014-07-28 18:52:00   6112072   ----a-w-   C:\Windows\System32\usbaaplrc.dll
2014-07-28 18:52:00   54784   ----a-w-   C:\Windows\System32\drivers\usbaapl64.sys
2014-07-25 06:35:46   875688   ----a-w-   C:\Windows\SysWow64\msvcr120_clr0400.dll
2014-07-25 03:47:06   869544   ----a-w-   C:\Windows\System32\msvcr120_clr0400.dll
2014-07-17 22:05:06   269008   ----a-w-   C:\Windows\System32\drivers\MpFilter.sys
2014-07-17 22:05:06   125584   ----a-w-   C:\Windows\System32\drivers\NisDrvWFP.sys
2014-07-14 02:02:45   1216000   ----a-w-   C:\Windows\System32\rpcrt4.dll
2014-07-14 01:40:58   664064   ----a-w-   C:\Windows\SysWow64\rpcrt4.dll
2014-07-09 02:03:23   7168   ----a-w-   C:\Windows\System32\KBDYAK.DLL
2014-07-09 02:03:22   7168   ----a-w-   C:\Windows\System32\KBDBASH.DLL
2014-07-09 01:31:42   7168   ----a-w-   C:\Windows\SysWow64\KBDYAK.DLL
2014-07-09 01:31:41   6656   ----a-w-   C:\Windows\SysWow64\KBDBASH.DLL
.
============= FINISH: 15:14:45.00 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 6/5/2011 12:20:07 PM
System Uptime: 9/30/2014 12:36:03 PM (51 hours ago)
.
Motherboard: ASUSTeK Computer INC. |  | CM5675
Processor: Intel(R) Core(TM) i5 CPU         650  @ 3.20GHz | LGA1156 | 3201/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 917 GiB total, 836.649 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP615: 9/27/2014 4:42:54 AM - Windows Update
RP616: 9/30/2014 4:46:22 AM - Windows Update
RP617: 10/2/2014 1:38:22 AM - Windows Update
.
==== Installed Programs ======================
.
64 Bit HP CIO Components Installer
Adobe Flash Player 15 ActiveX
Adobe Flash Player 15 Plugin
Adobe Reader XI (11.0.09)
AI Manager
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ASUS Backup Wizard
ASUS VIBE
ASUSUpdate
Best Buy pc app
Bonjour
Canon iP4500 series
Canon iP4500 series User Registration
Canon My Printer
Canon Utilities Solution Menu
CCleaner
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Defraggler
EaseUS Todo Backup Free 4.0
Epson Copy Utility 3.5
Epson Event Manager
EPSON Perfection V30/V300 Photo Scanner Driver Update
EPSON Scan
EPU-4 Engine
ESET Online Scanner v3
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
HiJackThis
iCloud
Intel(R) Control Center
Intel(R) Graphics Media Accelerator Driver
Intel(R) Management Engine Components
iTunes
Junk Mail filter update
Malwarebytes Anti-Malware version 2.0.2.1012
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Business 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared 64-bit MUI (English) 2010
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Security Client
Microsoft Security Essentials
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 23.0 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB2758694)
MSXML 4.0 SP3 Parser (KB973685)
QuickTime 7
Realtek Ethernet Controller Driver For Windows Vista and Later
Realtek High Definition Audio Driver
RealUpgrade 1.1
Revo Uninstaller Pro 2.5.8
Safari
Secunia PSI (3.0.0.2004)
Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2)
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972216)
Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2810073) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
SUPERAntiSpyware
TurboTax 2010
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wrapper
TurboTax 2010 wvaiper
TurboTax 2011
TurboTax 2011 WinPerFedFormset
TurboTax 2011 WinPerReleaseEngine
TurboTax 2011 WinPerTaxSupport
TurboTax 2011 wrapper
TurboTax 2011 wvaiper
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Excel 2010 (KB2889836) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
WinPatrol
.
==== Event Viewer Messages From Past Week ========
.
9/30/2014 12:37:04 PM, Error: VDS Basic Provider [1]  - Unexpected failure. Error code: D@01010004
9/27/2014 12:28:22 AM, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
10/2/2014 1:41:38 AM, Error: Schannel [36888]  - The following fatal alert was generated: 70. The internal error state is 105.
10/2/2014 1:41:38 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.     New Signature Version:      Previous Signature Version: 1.185.1873.0     Update Source: Microsoft Update Server     Update Stage: Search     Source Path: http://www.microsoft.com     Signature Type: AntiVirus     Update Type: Full     User: NT AUTHORITY\SYSTEM     Current Engine Version:      Previous Engine Version: 1.1.11005.0     Error code: 0x80072f8f     Error description: A security error occurred
.
==== End Of File ===========================

Corrine

Hi, Ellie.  The logs help.  Thank you for posting them because they show that whatever your friend did, your start page was changed to Yahoo. 

1.  I understand that Google is your usual start page but which browser do you regularly use?  You have the following installed on your computer:

Firefox 23 (outdated)
Google Chrome
Internet Explorer 11
Safari

2.  Please download Adware Cleaner by Xplode.    Please save it to your desktop!

  • Close all open programs and internet browsers.
  • Double-click AdwCleaner.exe to run the tool. 
    Note:  Windows Vista, Windows 7/8 users right-click and select Run As Administrator.
  • Click the Scan button.
  • AdwCleaner will begin.  Be patient as the scan may take some time to complete.
  • After the scan has finished, click the Report button.  A logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

SellieS

Hi Corrine.......

I am using Google to search and Internet Explorer 11 as the website.

If I am using Google Chrome I don't know it.  I keep it as a program with reservations from past experience.   

I have complicated my Google email system by getting an email ID that I don't understand the need for. It is not a priority to fix. 

I also keep Safari as my backup because I have an iPhone and iPad.
and Foxfire is just on there as another back up that I pay no attention.

SellieS

Here are the results for AdwCleaner


# AdwCleaner v3.311 - Report created 02/10/2014 at 20:35:51
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Diana - OWNER-PC
# Running from : C:\Users\Diana\Downloads\adwcleaner_3.311.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280


-\\ Mozilla Firefox v23.0 (en-US)

[ File : C:\Users\Diana\AppData\Roaming\Mozilla\Firefox\Profiles\tom6abi5.default\prefs.js ]


-\\ Google Chrome v37.0.2062.124

[ File : C:\Users\Diana\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

[ File : C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3728 octets] - [05/07/2014 16:01:27]
AdwCleaner[R1].txt - [3720 octets] - [05/07/2014 16:09:41]
AdwCleaner[R2].txt - [1075 octets] - [05/07/2014 16:31:13]
AdwCleaner[R3].txt - [1196 octets] - [05/07/2014 16:52:46]
AdwCleaner[R4].txt - [1256 octets] - [05/07/2014 16:55:28]
AdwCleaner[R5].txt - [1377 octets] - [08/07/2014 02:05:48]
AdwCleaner[R6].txt - [2564 octets] - [02/10/2014 20:33:08]
AdwCleaner[S0].txt - [3683 octets] - [05/07/2014 16:13:58]
AdwCleaner[S1].txt - [1140 octets] - [05/07/2014 16:36:05]
AdwCleaner[S2].txt - [1320 octets] - [05/07/2014 16:55:53]
AdwCleaner[S3].txt - [1440 octets] - [08/07/2014 02:07:54]
AdwCleaner[S4].txt - [2341 octets] - [02/10/2014 20:35:51]

########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [2401 octets] ##########

Corrine

Ok, Internet Explorer 11 is browser you are using and Google is the start page you want to use. 

What has happened is somehow you changed the start page of Internet Explorer 11 (IE 11) to this:  https://search.yahoo.com/yhs/web?hspart=w3i&hsimp=yhs-syctransfer&type=W3i_SP,204,0_0,StartPage,20140940,19891,0,31,6944

If what you want for a start page is this https://www.google.com/?gws_rd=ssl do the following:

1.  Click the Tools button and then click Internet options.
2.  On the General tab, under Home page, paste the URL for your Google Start page:  https://www.google.com/?gws_rd=ssl
3.  Click Apply, and click OK.

Since you have WinPatrol, unless you have monitoring disabled, your friend would have approved changing the start page too.  :(

Has this solved the current problem or are there other issues?


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

SellieS

The problem is solved. I never saw any sign of Yahoo in the log.  I don't know how my friend could impose Yahoo on me unless it was a mistake. She quit the email because she makes so many mistakes.  Just not a user.

Thanks so much again, Corrine.

Corrine

You're welcome, Ellie. 

Let's take care of removing the tools used:

Please download Delfix from here.

Ensure the following boxes are checked:
  • Remove disinfection tools
  • Create registry backup
  • Purge system restore

  • Click Run


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

SellieS

I am done and happy.  Good stuff





DelFix v10.8 - Logfile created 04/10/2014 at 02:44:52
# Updated 29/07/2014 by Xplode
# Username : Diana - OWNER-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Removing disinfection tools ...

Deleted : C:\JRT
Deleted : C:\AdwCleaner
Deleted : C:\Program Files (x86)\Trend Micro\Hijackthis
Deleted : C:\ComboFix.txt
Deleted : C:\Users\Diana\Downloads\adwcleaner (1).exe
Deleted : C:\Users\Diana\Downloads\adwcleaner (2).exe
Deleted : C:\Users\Diana\Downloads\adwcleaner.exe
Deleted : C:\Users\Diana\Downloads\adwcleaner_3.214 (1).exe
Deleted : C:\Users\Diana\Downloads\adwcleaner_3.214 (2).exe
Deleted : C:\Users\Diana\Downloads\adwcleaner_3.214 (3).exe
Deleted : C:\Users\Diana\Downloads\adwcleaner_3.214 (4).exe
Deleted : C:\Users\Diana\Downloads\adwcleaner_3.214.exe
Deleted : C:\Users\Diana\Downloads\adwcleaner_3.311.exe
Deleted : C:\Users\Diana\Downloads\dds (1) - Shortcut.lnk
Deleted : C:\Users\Diana\Downloads\dds (1).scr
Deleted : C:\Users\Diana\Downloads\dds (2).scr
Deleted : C:\Users\Diana\Downloads\dds.scr
Deleted : C:\Users\Diana\Downloads\JRT (1).exe
Deleted : C:\Users\Diana\Downloads\JRT (2).exe
Deleted : C:\Users\Diana\Downloads\JRT (3).exe
Deleted : C:\Users\Diana\Downloads\JRT.exe
Deleted : C:\Users\Diana\Downloads\SecurityCheck (1).exe
Deleted : C:\Users\Diana\Downloads\SecurityCheck (2).exe
Deleted : C:\Users\Diana\Downloads\SecurityCheck (3).exe
Deleted : C:\Users\Diana\Downloads\SecurityCheck (4).exe
Deleted : C:\Users\Diana\Downloads\SecurityCheck (5) - Shortcut.lnk
Deleted : C:\Users\Diana\Downloads\SecurityCheck (5).exe
Deleted : C:\Users\Diana\Downloads\SecurityCheck (6).exe
Deleted : C:\Users\Diana\Downloads\SecurityCheck.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware

~ Creating registry backup ... OK

~ Cleaning system restore ...


New restore point created !

Corrine

Excellent!  It is always nice to have happy results.   :thumbsup:


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.