Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need Help With Pop-up Virus!


  • Please log in to reply
7 replies to this topic

#1 ajgiuliano

ajgiuliano

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:23 PM

Posted 06 December 2007 - 01:34 AM

A few days ago my laptop contracted a virus that is causing pop-ups. Windows defender has identified the harmful files as "trojan:Win32/Virtumonde.gen" and "BrowserModifier:Win32/fotomoto". I have both Windows Defender and Ad-Aware SE on my computer and neither have been of any help.

I am running on Windows XP and I use Mozilla Firefox as my web browser. I contracted the virus while using Firefox, but when the pop-ups come up they are through Internet Explorer.

I would greatly appreciate any information you have to help me solve this problem.

Thank You,

ajgiuliano

BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,088 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:23 PM

Posted 06 December 2007 - 08:11 AM

Use the Vundofix tool in the link below.
http://vundofix.atribune.org/

Install Super Antispyware free. Run it in safe mode. Allow it to quarantine whatever it finds.
http://www.superantispyware.com/

Post back with results of scans and for further instructions.
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 ajgiuliano

ajgiuliano
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:23 PM

Posted 06 December 2007 - 07:10 PM

Ok so I updated my java and downloaded and ran the Vundofix program. It detected 6 or 7 files and I think they were removed successfully.

As for the Super Antispyware free program, I was not as successful. I downloaded the program and installed it with all of the updates. But, when I ran the scan while I was in safe mode, my laptop froze. I tried the complete scan 3 times, and it froze each time. Then I tried the quickscan and it froze again.

The popups have subsided greatly since I first posted, but I still think my computer is infected.

What do you think would be the best course of action from here?

Thanks,

ajgiuliano

#4 buddy215

buddy215

  • Moderator
  • 13,088 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:23 PM

Posted 06 December 2007 - 07:24 PM

Try running SAS in normal mode. I agree that malware is still on the computer.
It could also be worthwhile to run the Vundofix tool again.

If you cannot get SAS to run in either mode, I suggest you post a Hijack This Log
in the Hijack This Forum. DO NOT post the log in this forum.
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/
If you are unable to perform some steps in the prep guide, move on. The important thing
is to get the log posted.

Wanted to suggest since you use Firefox, you should install the NoScript addon. It will protect you from
driveby installs of malware and block a ton of ads.

Edited by buddy215, 06 December 2007 - 07:31 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#5 ajgiuliano

ajgiuliano
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:23 PM

Posted 07 December 2007 - 02:56 AM

Okay, so i ran vundofix again and it found the following files:

C:\windows\system32\ssqpq.dll
C:\windows\system32\qpqss.ini
C:\windows\system32\qpqss.ini2

Then I got SAS to run in normal mode. here is the SAS scan log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/06/2007 at 11:26 PM

Application Version : 3.9.1008

Core Rules Database Version : 3356
Trace Rules Database Version: 1355

Scan type : Complete Scan
Total Scan Time : 00:39:15

Memory items scanned : 594
Memory threats detected : 3
Registry items scanned : 6384
Registry threats detected : 32
File items scanned : 40194
File threats detected : 86

Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\SSQPQ.DLL
C:\WINDOWS\SYSTEM32\SSQPQ.DLL
HKLM\Software\Classes\CLSID\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}
HKCR\CLSID\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}
HKCR\CLSID\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}\InprocServer32
HKCR\CLSID\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3F1A654B-FDBA-41DD-9FB4-8BF303F2C0C7}
HKCR\CLSID\{3F1A654B-FDBA-41DD-9FB4-8BF303F2C0C7}
HKCR\CLSID\{3F1A654B-FDBA-41DD-9FB4-8BF303F2C0C7}\InprocServer32
HKCR\CLSID\{3F1A654B-FDBA-41DD-9FB4-8BF303F2C0C7}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}
HKCR\CLSID\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}

Adware.Vundo-Variant/Small
C:\WINDOWS\SYSTEM32\OPNNMNL.DLL
C:\WINDOWS\SYSTEM32\OPNNMNL.DLL
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\opnnmnl
C:\WINDOWS\SYSTEM32\GEBBAXW.DLL

Adware.Vundo-Variant/Small-A
C:\WINDOWS\SYSTEM32\TENDLMRO.DLL
C:\WINDOWS\SYSTEM32\TENDLMRO.DLL
HKLM\Software\Classes\CLSID\{fcf44d1e-7b43-4025-9d0e-e254cb806b0b}
HKCR\CLSID\{FCF44D1E-7B43-4025-9D0E-E254CB806B0B}
HKCR\CLSID\{FCF44D1E-7B43-4025-9D0E-E254CB806B0B}\InprocServer32
HKCR\CLSID\{FCF44D1E-7B43-4025-9D0E-E254CB806B0B}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\ITEGVJLP.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fcf44d1e-7b43-4025-9d0e-e254cb806b0b}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP709\A0047637.DLL
C:\WINDOWS\SYSTEM32\CGBCYLVT.DLL
C:\WINDOWS\SYSTEM32\KHICVDKK.DLL
C:\WINDOWS\SYSTEM32\YLSSPDHE.DLL

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{0a397638-307a-4e92-a9be-83a03b0172d8}
HKCR\CLSID\{0A397638-307A-4E92-A9BE-83A03B0172D8}
HKCR\CLSID\{0A397638-307A-4E92-A9BE-83A03B0172D8}\InprocServer32
HKCR\CLSID\{0A397638-307A-4E92-A9BE-83A03B0172D8}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\KHKDQOV.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0a397638-307a-4e92-a9be-83a03b0172d8}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{11A69AE4-FBED-4832-A2BF-45AF82825583}

Trojan.WinFixer
HKLM\Software\Classes\CLSID\{6F8903EB-552A-43C3-92DA-1CB7E1542F8B}
HKCR\CLSID\{6F8903EB-552A-43C3-92DA-1CB7E1542F8B}
HKCR\CLSID\{6F8903EB-552A-43C3-92DA-1CB7E1542F8B}\InprocServer32
HKCR\CLSID\{6F8903EB-552A-43C3-92DA-1CB7E1542F8B}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\MLJJG.DLL

Adware.Tracking Cookie
C:\Documents and Settings\Owner.TONY\Cookies\owner@advertising[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@ad.zanox[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@findwhat[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@publishers.clickbooth[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@indiads[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@ads4.blastro[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@mediatraffic[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@ads3.blastro[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@ads.monster[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@statcounter[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@login.revenueloop[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@2o7[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@edserver.advertserve[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@zedo[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@apmebf[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@fastclick[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@ads.addynamix[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@indexstats[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@lynxtrack[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@trafficmp[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@precisionclick[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@www.burstnet[2].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@atwola[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@doubleclick[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@ad.yieldmanager[1].txt
C:\Documents and Settings\Owner.TONY\Cookies\owner@stats.sellmosoft[1].txt

Adware.Web Buying
HKU\S-1-5-21-2167402874-2339249052-4096134463-1006\Software\WebBuying

Malware.LocusSoftware Inc/BestSellerAntivirus
C:\Documents and Settings\Owner.TONY\Application Data\BestsellerAntivirus\avtasks.dat
C:\Documents and Settings\Owner.TONY\Application Data\BestsellerAntivirus\Logs\av.log
C:\Documents and Settings\Owner.TONY\Application Data\BestsellerAntivirus\Logs\ga6Support.log
C:\Documents and Settings\Owner.TONY\Application Data\BestsellerAntivirus\Logs
C:\Documents and Settings\Owner.TONY\Application Data\BestsellerAntivirus\PGE.dat
C:\Documents and Settings\Owner.TONY\Application Data\BestsellerAntivirus
C:\DOCUMENTS AND SETTINGS\OWNER.TONY\LOCAL SETTINGS\TEMP\MOFUGCLQ.EXE
C:\DOCUMENTS AND SETTINGS\OWNER.TONY\LOCAL SETTINGS\TEMP\URCLQECD.EXE
C:\WINDOWS\Prefetch\MOFUGCLQ.EXE-13944063.pf

Malware.LocusSoftware Inc/SpyGuardPro
HKLM\Software\SpyGuardPro
HKLM\Software\SpyGuardPro#ProductCode
HKLM\Software\SpyGuardPro#InstallDate
C:\Program Files\SpyGuardPro\Config\pgs.xml
C:\Program Files\SpyGuardPro\Config
C:\Program Files\SpyGuardPro\Dat
C:\Program Files\SpyGuardPro\Engines
C:\Program Files\SpyGuardPro\Graphics
C:\Program Files\SpyGuardPro\LA\License.rtf
C:\Program Files\SpyGuardPro\LA
C:\Program Files\SpyGuardPro\rpt.dll
C:\Program Files\SpyGuardPro\scnkrnl.dll
C:\Program Files\SpyGuardPro\sqlite3.dll
C:\Program Files\SpyGuardPro\Tools
C:\Program Files\SpyGuardPro\unins000.dat
C:\Program Files\SpyGuardPro\unins000.exe
C:\Program Files\SpyGuardPro\Up
C:\Program Files\SpyGuardPro
C:\Program Files\Common Files\SpyGuardPro

Malware.LocusSoftware Inc/ConfidentSurf
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#Salestart [ "C:\Program Files\Common Files\BestsellerAntivirus\bm.exe" dm=http://bestsellerantivirus.com; ad=http://bestsellerantivirus.com ]

Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\OWNER.TONY\LOCAL SETTINGS\TEMP\IS-KN7P0.TMP\GFL.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP704\A0047305.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP708\A0047582.EXE
C:\WINDOWS\R2FYESBHAXVSAWFUBW\LZIVYM1JURPPUQIRVT.VBS

Trojan.Downloader-Gen/DDC
C:\DOCUMENTS AND SETTINGS\OWNER.TONY\LOCAL SETTINGS\TEMP\MBSRJBQA.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP708\A0047572.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP708\A0047573.EXE
C:\WINDOWS\SYSTEM32\BEVFICEW.EXE
C:\WINDOWS\SYSTEM32\ROHGTLMD.EXE
C:\WINDOWS\Prefetch\BEVFICEW.EXE-311C6F8F.pf
C:\WINDOWS\Prefetch\ROHGTLMD.EXE-107D0A0C.pf

Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP703\A0047283.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP714\A0047759.EXE
C:\WINDOWS\SYSTEM32\FT21\BASENDLL2.EXE

Trojan.Unclassified/17PHolmes
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP704\A0047465.EXE
C:\WINDOWS\MROFINU572.EXE.TMP

Adware.Vundo/Traff-2
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP705\A0047480.EXE

Adware.Vundo-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP705\A0047487.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP708\A0047593.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP710\A0047650.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP714\A0047764.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP716\A0048854.DLL

Trojan.Downloader-Gen/TaLDrv
C:\WINDOWS\SYSTEM32\MM6\NCSTDB33.EXE




Also, I installed NoScript addon. thank you for the tip.

Hopefully this imformation will be useful in helping me solve my problem.

thank you,

ajgiuliano

#6 buddy215

buddy215

  • Moderator
  • 13,088 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:23 PM

Posted 07 December 2007 - 05:23 AM

Remove temporary files, logs, cookies, etc. by using Ccleaner. Do not use "Advanced Settings" or the "Issues" button. Use only the default settings. http://www.ccleaner.com/
During the install you will be offered the Yahoo Toolbar. UNcheck if not wanted.

Rerun the Vundofix tool. It still found infected files.

You should be able to run Super Antispyware in safe mode now. Try it. SAS UPDATED AFTER 8PM EST YESTERDAY. BE SURE TO UPDATE!!

Run the online scan for Bit Defender in normal mode. Allow it to quarantine whatever it finds.
http://www.bitdefender.com/scan8/ie.html

Post back with results of scans and what problems you are experiencing.

Edited by buddy215, 07 December 2007 - 05:28 AM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#7 ajgiuliano

ajgiuliano
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:23 PM

Posted 07 December 2007 - 08:04 PM

I ran the CCleaner, but the log is too long to fit in a post. It deleted 1300 MB worth of files though!



Then I used the vundofix tool again and it found the same files as last time. I think they got removed this time though.



Next, I tried to run SAS in safe mode again. This was unsuccessful. Again my computer froze during the scan. I scanned again in normal mode and this is the log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/07/2007 at 10:49 AM

Application Version : 3.9.1008

Core Rules Database Version : 3357
Trace Rules Database Version: 1356

Scan type : Complete Scan
Total Scan Time : 00:38:36

Memory items scanned : 583
Memory threats detected : 0
Registry items scanned : 6378
Registry threats detected : 4
File items scanned : 39066
File threats detected : 13

Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27FEE5FE-5B56-43B6-8745-A6F1DCA1F884}
HKCR\CLSID\{27FEE5FE-5B56-43B6-8745-A6F1DCA1F884}
HKCR\CLSID\{27FEE5FE-5B56-43B6-8745-A6F1DCA1F884}\InprocServer32
HKCR\CLSID\{27FEE5FE-5B56-43B6-8745-A6F1DCA1F884}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\SSQPQ.DLL

Adware.Vundo-Variant/Small
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052912.DLL

Adware.Vundo-Variant/Small-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052913.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052914.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052915.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052916.DLL

Unclassified.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052917.DLL

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052922.VBS

Trojan.Downloader-Gen/DDC
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052923.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052924.EXE

Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052925.EXE

Trojan.Downloader-Gen/TaLDrv
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP717\A0052926.EXE

Adware.Vundo-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP718\A0055090.DLL




After I finished this I tried to use the BitDefender online scan, but I could not get it working. It says it requires IE, but using IE7 I still could not even start the scan. I couldn't even get past the license agreement because it wouldn't let me click the "agree" button. I am probably doing something wrong.


hopefully this information will give you a better idea of what is going on in my system


once again thank you so much,


ajgiuliano

#8 buddy215

buddy215

  • Moderator
  • 13,088 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:05:23 PM

Posted 07 December 2007 - 08:27 PM

Post a Hijack This Log in the Hijack This Forum by following the directions in the link below. DO NOT post a log in this forum. http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/
If you are unable to perform any of the steps, skip and move on to the next. The important thing is to get the
log posted.
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users