Sneaky Microsoft, Hidden Download for Windows 10 (thanks to Grandms1)
10 years ago
last modified: 10 years ago
Featured Answer
Sort by:Oldest
Comments (29)
- 10 years agolast modified: 10 years ago
- 10 years agolast modified: 10 years ago
Related Discussions
New rootkit virus ??
Comments (7)Heres what the Symantic website had to say about this trojan Targeting over 400 banks and having the ability to circumvent two-factor authentication are just two of the features that push Trojan.Silentbanker into the limelight. The scale and sophistication of this emerging banking Trojan is worrying, even for someone who sees banking Trojans on a daily basis. This Trojan downloads a configuration file that contains the domain names of over 400 banks. Not only are the usual large American banks targeted but banks in many other countries are also targeted, including France, Spain, Ireland, the UK, Finland, Turkeythe list goes on. The ability of this Trojan to perform man-in-the-middle attacks on valid transactions is what is most worrying. The Trojan can intercept transactions that require two-factor authentication. It can then silently change the user-entered destination bank account details to the attacker's account details instead. Of course the Trojan ensures that the user does not notice this change by presenting the user with the details they expect to see, while all the time sending the bank the attacker's details instead. Since the user doesnÂt notice anything wrong with the transaction, they will enter the second authentication password, in effect handing over their money to the attackers. The Trojan intercepts all of this traffic before it is encrypted, so even if the transaction takes place over SSL the attack is still valid. Unfortunately, we were unable to reproduce exactly such a transaction in the lab. However, through analysis of the Trojan's code it can be seen that this feature is available to the attackers. The Trojan does not use this attack vector for all banks, however. It only uses this route when an easier route is not available. If a transaction can occur at the targeted bank using just a username and password then the Trojan will take that information, if a certificate is also required the Trojan can steal that too, if cookies are required the Trojan will steal those. In fact, even if the attacker is missing a piece of information to conduct a transaction, extra HTML can be added to the page to ask the user for that extra information. (In the example below the user is asked to enter their encryption key, in addition to the regular information.) Here is the login form viewed on a clean machine: (Insert Picture of a Regular Log In Screen) Below the form presented to an infected user is shown, the input box added by the Trojan has been marked in red: (Insert Picture of an Infected Log In Screen) When instructed, the Trojan can also redirect users to an attacker-controlled server instead of the real bank in order to perform a classic man-in-the-middle attack. Currently there is only one bank targeted in this way; however, recent updates to the Trojan change the user's DNS settings to point to an attacker-controlled server. Using this technique the Trojan can start redirecting any site to an attacker site at any time. This feature could also mean that if the Trojan is removed but the DNS settings are left unchanged then the user may still be at risk. (See below for the attackers' DNS server addresses.) Add to all of the above the ability to steal FTP, POP, Web mail, protected storage, and cached passwords and then we start to see the capabilities of this Trojan. But, it doesnÂt stop there  don't forget the porn! The Trojan also contains over 600 pornographic Web site URLs that can be shown to the infected user so that the attacker can make money from the referrals. Lastly, the Trojan can also download updates, which it regularly does. It can also download other executables and it can use the infected machine as a proxy or as a Web server on any chosen port (in tests the http port used was 18102). The multiple configuration files that the Trojan downloads are updated several times per day and currently the Trojan is capable of injecting HTML into about 200 different URLs. The configuration files are compressed and encrypted; however, after decrypting them we can see how the Trojan works in more detail. The configuration files are structured as .ini files and each section of an .ini file represents a different task. Here is a snippet from the configuration file that was used to inject HTML into the banking form shown in the example above: jhw21] pok=insert qas=someBankSite.com/xpage/loginxxxxxxxxxs.htm njd=name="oppasswd; dfr=14 xzn=/)n xzq=2 rek=(div class="clear sep4")(/div) (label for="clave")Clave de firma: (/label) (input name="ESpass" type="password" size="8" maxlength="8" class="input01 aleft w180"/) req=166 The configuration options in the snippet above are as follows: Token: Purpose: pok Action to take qas URL to take action on njd String to search for xzn End string to search for rek HTML to insert The Trojan searches for the string name="oppasswd; then it finds the end tag /) then it inserts the string into the page: (div class="clear sep4")(/div) (label for="clave")Clave de firma: (/label) (input name="ESpass" type="password" size="8" maxlength="8" class="input01 aleft w180"/) Shown below is the HTML shown to the user on a non-infected computer: (label for="clave")Clave personal: (/label) (input id="clave" name="oppasswd" type="password" size="8" maxlength="8" class="input01 aleft w180"/) (/div) And on an infected computer: (label for="clave")Clave personal: (/label) (input id="clave" name="oppasswd" type="password" size="8" maxlength="8" class="input01 aleft w180"/) (div class="clear sep4")(/div) (label for="clave")Clave de firma: (/label) (input name="ESpass" type="password" size="8" maxlength="8" class="input01 aleft w180"/) (/div) Note: I substituted ) for > in the above examples. The Trojan can take any of the following actions when altering the HTML of a page: insert, delete, replace, and replace all. The Trojan uses the keyword "ESpass" (see the form above) as a keyword when the user sends a page to the bank and the Trojan checks if the page contains that keyword. Using this technique the Trojan can recognize pages it has altered and can extract the relevant data from the page and send it to the attacker as well as to the bank. The configuration files for this Trojan currently contain over 200kb of data; however, new URLs and HTML are being added to the configuration files on a daily basis. The Trojan is easily updated since the full HTML of any banking-related Web site is sent to the attackers. Using these submissions they can target banks for which they do not have bank accounts already. We are currently monitoring all of the updates to this Trojan. The Trojan accesses the following URLs for configuration, updates, and to send stolen data:  iloveie.info  webcounterstat.info  microcbs.com  reservaza.com  screensaversfor-fun.com  mystabcounter.info  85.255.119.218 The Trojan also downloads a copy of Trojan.Flush.J, which changes the users DNS settings to the following attacker settings:  85.255.116.133  85.255.112.87 For protection, please keep your antivirus definitions up to date and block the above addresses at the firewall. Note: Not only did this Trojan grab my attention for obvious reasons, but the Trojan also installed itself as a .midi driver, causing my music to stop! For the record, the Trojan adds itself the following registry key so that it is loaded in all applications that use sound: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\"midi1 But it also said this: Discovered: December 17, 2007 Updated: January 8, 2008 12:54:17 PM Also Known As: Spy-Agent.cm [McAfee] Type: Trojan Infection Length: 54,189 bytes and 98,304 bytes Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP Trojan.Silentbanker is a Trojan horse that records keystrokes, captures screen images, and steals confidential financial information to send to the remote attacker. Protection Initial Rapid Release version December 17, 2007 revision 023 Latest Rapid Release version January 10, 2008 revision 023 Initial Daily Certified version December 17, 2007 revision 032 Latest Daily Certified version January 15, 2008 revision 016 Initial Weekly Certified release date December 19, 2007 Click here for a more detailed description of Rapid Release and Daily Certified virus definitions. Threat Assessment Wild Wild Level: Low Number of Infections: 0 - 49 Number of Sites: 0 - 2 Geographical Distribution: Low Threat Containment: Moderate Removal: Easy Damage Damage Level: Medium Payload: Records keystrokes and captures screen images Releases Confidential Info: Steals confidential financial information Distribution Distribution Level: Low...See MoreBrothersft search engine & toolbar removal
Comments (2)# AdwCleaner v2.115 - Logfile created 03/28/2013 at 21:45:52 # Updated 17/03/2013 by Xplode # Operating system : Windows Vista (TM) Business Service Pack 2 (32 bits) # User : Judy - JUDY-PC # Boot Mode : Normal # Running from : C:\Users\Judy\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : CltMngSvc ***** [Files / Folders] ***** Deleted on reboot : C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jndeiekmdhemaggmkgljlpdeaomeplbp File Deleted : \END File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\SearchResults.xml File Deleted : C:\user.js File Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\searchplugins\Askcom.xml File Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\searchplugins\BrowserProtect.xml File Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\searchplugins\delta.xml File Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\searchplugins\SearchResults.xml Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\hdvidcodec.com Folder Deleted : C:\Program Files\Movie2KDownloader.com Folder Deleted : C:\Program Files\Qwiklinx Folder Deleted : C:\Program Files\SearchProtect Folder Deleted : C:\Program Files\Windows Searchqu Toolbar Folder Deleted : C:\ProgramData\~0 Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\blekko toolbars Folder Deleted : C:\ProgramData\boost_interprocess Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\WeCareReminder Folder Deleted : C:\Users\Judy\AppData\Local\Conduit Folder Deleted : C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf Folder Deleted : C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo Folder Deleted : C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde Folder Deleted : C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Extensions\jndeiekmdhemaggmkgljlpdeaomeplbp Folder Deleted : C:\Users\Judy\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc Folder Deleted : C:\Users\Judy\AppData\Local\PackageAware Folder Deleted : C:\Users\Judy\AppData\Local\Temp\CT3281348 Folder Deleted : C:\Users\Judy\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\Judy\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Judy\AppData\LocalLow\Delta Folder Deleted : C:\Users\Judy\AppData\Roaming\Babylon Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\Conduit Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\ConduitCommon Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\ConduitEngine Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\CT3281348 Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\extensions\(6921B3CC-9935-4D28-9A83-B3D824210580) Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\extensions\(94193c2f-e73f-4feb-b393-2b95f0a01430) Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\extensions\staged Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\extensions\wecarereminder@bryan Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\jetpack Folder Deleted : C:\Users\Judy\AppData\Roaming\Mozilla\Firefox\Profiles\g264jafr.default\Smartbar Folder Deleted : C:\Users\Judy\AppData\Roaming\OpenCandy Folder Deleted : C:\Users\Judy\AppData\Roaming\Qwiklinx Folder Deleted : C:\Users\Judy\AppData\Roaming\SearchProtect Folder Deleted : C:\Users\Judy\Desktop\Programs\hdvidcodec.com ***** [Registry] ***** Key Deleted : HKCU\Software\1ClickDownload Key Deleted : HKCU\Software\5d538a8bb46eec10 Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\Software\xfin_portal Key Deleted : HKCU\Software\BabylonToolbar Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\delta LTD Key Deleted : HKCU\Software\Google\Chrome\Extensions\jndeiekmdhemaggmkgljlpdeaomeplbp Key Deleted : HKCU\Software\Headlight Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\(0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9) Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\(9BB47C17-9C68-4BB3-B188-DD9AF0FD2102) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\(15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\(2E497885-E60B-420A-832D-0148B392E058)_is1 Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\xfin_portal Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\(82E1477C-B154-48D3-9891-33D83C26BCD3) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\(C1AF5FA5-852C-4C90-812E-A7F75E011D87) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\(D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\(FD72061E-9FDE-484D-A58A-0BAB4151CAD8) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\(82E1477C-B154-48D3-9891-33D83C26BCD3) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\(9D425283-D487-4337-BAB6-AB8354A81457) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\(C1AF5FA5-852C-4C90-812E-A7F75E011D87) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\(D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\(DF7770F7-832F-4BDF-B144-100EDDD0C3AE) Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\(FD72061E-9FDE-484D-A58A-0BAB4151CAD8) Key Deleted : HKCU\Software\Qwiklinx Key Deleted : HKCU\Software\SearchCore for Browsers Key Deleted : HKCU\Software\SearchProtect Key Deleted : HKCU\Software\wecarereminder Key Deleted : HKCU\Software\Zugo Key Deleted : HKLM\SOFTWARE\5d538a8bb46eec10 Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\(49BC4DD1-0E69-4611-9164-0009538C5E46) Key Deleted : HKLM\SOFTWARE\Classes\AppID\(4FBBF769-ECEB-420A-B536-133B1D505C36) Key Deleted : HKLM\SOFTWARE\Classes\AppID\(608D3067-77E8-463D-9084-908966806826) Key Deleted : HKLM\SOFTWARE\Classes\AppID\(BDB69379-802F-4EAF-B541-F8DE92DD98DB) Key Deleted : HKLM\SOFTWARE\Classes\AppID\(C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3) Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(0214A12B-C5A3-437F-A6F3-068ABCD8C85E) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(08635077-8829-49E2-B338-C968817EB460) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(20A3F109-F7C1-47B4-8098-8E654B264B1D) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(2EECD738-5844-4A99-B4B6-146BF802613B) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(3C471948-F874-49F5-B338-4F214A2EE0B1) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(4B9BCCE8-A70B-402A-A7E1-DB96831EE26F) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(80922EE0-8A76-46AE-95D5-BD3C3FE0708D) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(8C7478AB-3155-463E-936F-55F91F0F10D0) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(96DD9437-5D20-4EFB-BF52-A4A605A4E0AA) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(D824F0DE-3D60-4F57-9EB1-66033ECD8ABB) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(E46C8196-B634-44A1-AF6E-957C64278AB1) Key Deleted : HKLM\SOFTWARE\Classes\CLSID\(F773BB94-6C19-4643-A570-0E429103D1C3) Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\(96DD9437-5D20-4EFB-BF52-A4A605A4E0AA) Key Deleted : HKLM\SOFTWARE\Classes\Interface\(E2C1A522-B8E1-45D1-B316-F5625004A28C) Key Deleted : HKLM\SOFTWARE\Classes\Interface\(F773BB94-6C19-4643-A570-0E429103D1C3) Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\QwiklinxBHO Key Deleted : HKLM\SOFTWARE\Classes\QwiklinxBHO.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3281348 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\(204C0025-C26A-43E2-853C-D8A8EB1BCE51) Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\(B12920CF-BE13-4C09-890D-1B6EFFFE2FBE) Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr...See Moreupgrade to W10-FREE?
Comments (62)Thanks Shaddy. I personally use a Rolodex for all the passwords. Spinning wheel, easier to replace a card then scribbling out in a notebook which I have done in the past. I keep my passwords and my husbands on it because he keeps changing them as he forgets the old ones. You know the 'forgot your password?' Worse thing they ever offered. He keeps doing that and doesn't write it down. Like many of us, you think you'll remember. I think what he did when he turned on the Win8 computer was put hotmail address because the computer said he couldn't use it without one. At least that's what he remembers. He states he never put a password for log on. I'm not sure but he has never had a log-on password but the Start-Up screen might have confused him. I can use it but have to log on this hotmail address to get in. I can't find a way to change the log on to my name nor get rid of the hotmail address. I did turn him off as administrator and put myself, but only his log-on appears when you turn the machine on. I'll figure it out eventually when I stop using my XP machine. I just don't have the energy for this anymore. Its so tiring and time consuming to hunt around for answers or where Microsoft decided to move everything and change the names. I thought the easiest thing would be to wipe it all out by reinstalling Windows until I realized it never came with disks. How dumb! Anyway, us older folks keep plugging away best we can. I don't feel like spending the money on a tech, at this point. You and Emma are doing better than me. I haven't even gotten to Win 10 yet! Got to get past Win 8 first. Good luck to all, Jane...See Moreadvice, tips? Removing Win10
Comments (19)Just a question... (1) Are your and your husband's account on the same computer, or separate computers? (2) If so, the computer is back to 8.1 now? (3) Your husbands mail opens and works fine? (4) You have the mail shortcut to click, but clicking it results in the app not coming up? ------------------------------------------------------------ Just thoughts, I'm not a tech... Maybe instead of doing get-appxpackage -AllUsers *microsoft.windowscommunicationsapps* | remove-appxpackage and possibly removing your husband's working mail, you could do get-appxpackage *microsoft.windowscommunicationsapps* | remove-appxpackage to remove only your own? (notice the lack of the AllUsers switch) Don't take my word on that, I may be wrong, wait for someone else, I don't run Windows enough to know my way around. ------------------------------------------------------------- My thought on removing your account, rebooting and adding it again... Might work but I'd probably not be in a hurry to delete my account. Instead, I'd add a second account, switch to it and see if I could get mail working in it. Then I'd make a decision whether to delete the first account or not. That's just me though, and remember, I'm really a Windows user. Just giving you something to consider until someone more qualified comes along. :)...See More- 10 years agolast modified: 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years ago
- 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years ago
- 10 years ago
- 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years ago
- 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years ago
- 10 years ago
- 10 years ago
- 10 years ago
- 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years agolast modified: 10 years ago
- 10 years ago
- 10 years ago
- 10 years ago
- 10 years agolast modified: 10 years ago
Related Stories

DOORS10 Ways to Work Screen Doors, Inside and Out
Take this functional feature up a notch with one of the many alternative door styles available
Full Story
ORGANIZING10 Principles of Organizing That Work in Every Room
Use these ideas to make it easier to find and put away your things
Full Story
BATHROOM DESIGN10 Elements of a Dream Master Bath
A heavenly bathroom could be just a few features away. Would any of these be must-haves for your renovation?
Full Story
RUGS10 Tips for Getting a Dining Room Rug Just Right
Is the rug you’re considering the right size, shape and weave for your dining room? Here’s what to keep in mind
Full Story
LIFE7 Things to Do Before You Move Into a New House
Get life in a new house off to a great start with fresh paint and switch plates, new locks, a deep cleaning — and something on those windows
Full Story
ARTNew Digital Art Frame Gets Put to the Test
Our writer sets up the EO1 at home, then invites artist friends over for a look — at images of their own work. See what they have to say
Full Story
OUTBUILDINGSThe Glass-Walled Cabin That Romance Built
Envisioning sunsets and starry skies, newlywed artists construct a 1-room retreat on a family farm
Full Story
STORAGEBedroom Storage: 12 Ways to Work Your Wardrobe
Instead of letting the mess in your closet overwhelm you, tackle it head on with these smart and simple solutions
Full Story
DECORATING PROJECTSWhat to Do With Old Family Photos
Find out how to research, share and preserve images that offer a connection to the past
Full Story
REMODELING GUIDESOriginal Home Details: What to Keep, What to Cast Off
Renovate an older home without regrets with this insight on the details worth preserving
Full StorySponsored

jrb451