Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

False Adwcleaner quarantined 13 pages of data.


  • Please log in to reply
29 replies to this topic

#1 Relaxing

Relaxing

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 08:26 PM

Hi,

After a false Adwcleaner Quarantined a 13 pages of data it rebooted and there was nothing on the screen, the F keys didn't work, the bios was gone, no way to comunicate with the Windows 8 computer. I tried to reinstall Windows 8, the disk would not boot. Without a bios I cant change the boot order.

   I power on and it beeps 2 times, the HD spins a little, the Optical drive is checked and stoped, it sounds as though it is trying to boot time after time for about 8 minutes, then it will stop, wait 15 seconds and start trying to start agian.

  I took the HD out, opened it on another computer, found the the Quarantined folder. There is a bunch of things like this  . :smash:

c: \Pnogram Fires Quanantine
(x86)\Amazon\ABB\abb-bundler-uninstall.exe->C:\AdwCleaner\Quanantine\C\Prognam FiIes
( x86) \Amazon\ABB\abb- bundlen-uninstall . exe. vin
C : \Users \l im&Ca no1 \AppData \Roaming\Systwea k\ s sd \SSDPTstu b . exe - >C : \AdwC leane r \Qua rant
ine\C\Usens\J im&Canol\AppData\Roaming\Systweak\ssd\SSDPTstub . exe. vir
C : \Usens \l im&Ca ro1 \AppData\ Loc a I \GoogIe\Ch rome\Usen
Data\DefauIt\Extensions\eofcbnmajmjmplflapaojj nihcj kigck\10. 2.O ,tg?_Q\manifest . j son -
>C : \AdwCleaner\Qua rantine\C\Usens \ I im&Ca nol\AppData \ Loca I \GoogIe\Ch nome\User
Data\DefauIt\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.O.190_0\manifest.json.
vir
C : \Usens \l im&Ca rol \AppData\ Loc a I \GoogIe\Ch nome\User
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.O.190_0\_metadata\comp
uted_hashes . j son - >C: \AdwCleaner'\Quarantine\C\Usens\l im&Carol\AppData\Local\6oo91e\Ch
rome\Usen
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.O.190_0\_metadata\comp
uted_hashes. json.vin
C : \Us ers \ I im&Ca rol \AppData \ Loca 1 \GoogIe\Ch nome\Use r
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.A.190_0\_metadata\veni
fied_contents.json->C:\AdwCIeanen\Quanantine\C\Users\llm&Carol\AppData\Local\GoogIe\
Chrome\User
Data\DefauIt\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\l-0.2.O.190_0\_metadata\veri
fied_contents . json. vin
C : \Users \ I im&Ca rol \AppData \ Loca I \Google \Ch nome\User
Data\Defau lt \ Exten s ion s \eofc bnmaj mj mplflapaoj j n i h cj kigc k\10. 2 . @ .'J.gA_O\_loca les \zh_Thl
\mes sages . j son - >C : \AdwCleaner\Qua rant i ne\C \Usens \l im&Ca nol \AppData \ Loc a 1 \Google\Ch r"o
me\Usen
Data\DefauIt\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.0.190_0\_locaIes\zh_TW
\messages.json.vir
C : \U s e ns \ I im&Ca ro I \AppDat a \ Loc a 1 \Googl e \C h nome \U se r
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.O.190_0\_Iocales\zh_CN
\messages.json->C:\AdwCIeanen\Quarantine\C\Usens\lim&CaroI\AppData\Local\Google\Chno
me\Usen
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.O.190_0\_locales\zh_CN
\messages.json.vir
C : \Users \l im&Ca nol \AppData \ Loc a l\GoogIe\Ch nome\Use n
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.O.190_0\_loca1es\vi\me
s s ages . j son - >C : \AdwC leanen\Qua rant i ne\C \Usens \ I im&Ca noI \AppData \ Loc a 1 \Google\Ch rome\
User
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.A.190_0\_locales\vi\me
ssages.json.vin
C : \U s e r s \ I im&C a ro1 \AppData \ Loc a 1 \Google \C h nome \Us e n
Data\DefauIt\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\l-0.2.O.190_0\_1ocales\ur\me
s s ages . j son - >C : \AdwCleane r\Qua nant ine\C \Users \lim&Ca nol \AppData \ Loca I \GoogIe\Ch rome\
Usen
Data\DefauIt\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.0.190_0\_locaIes\ur\me
ssages. json. vin
C : \Use rs \ I im&Ca nol \AppData \ Loc a1\Google\Ch rome\User
Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\L0.2.O,1-90_0\_Iocales\uk\me

Page 1

 

LENOVO IdeaCentre K 450 DeskTop

Configeration Number 57315522

CPU I5 4430 3.00

HD 1T

Ram 12G

 

Attached Files

  • Attached File  IMG.jpg   326.61KB   0 downloads

Edited by Relaxing, 15 June 2015 - 08:36 PM.


BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:54 AM

Posted 15 June 2015 - 08:28 PM

Hi Relaxing :)

Where did you download that "fake" AdwCleaner from if I may ask? Also, isn't there a log in the C:\AdwCleaner folder?

Edited by Aura., 15 June 2015 - 08:29 PM.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 Relaxing

Relaxing
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 09:08 PM

Hi From CNET, download.com I love adwcleaner it's the best. I don't know if this is a joke. But my win 8 computer is dust. looking for a new motherboard to get my bios back.

Scammers Are Using a Fake Version of AdwCleaner to Trick ...

Feb 11, 2015 - The latest trend in the awful Windows ecosystem is pretty ridiculous — scammers have a fake version of the reputable AdwCleaner tool, which .

cleardot.gif


#4 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:54 AM

Posted 15 June 2015 - 09:10 PM

The only official download links for AdwCleaner are BleepingComputer and ToolLibs. The rest doesn't guarantee you that you'll have the official version, nor the latest release. Give me a minute to download the AdwCleaner from Download.com in a VM and see if its an old version of the real version.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#5 Relaxing

Relaxing
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 09:11 PM

The owners of ADWcleaner wont let Cnet distrabute their software anymore.



#6 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:54 AM

Posted 15 June 2015 - 09:12 PM

There's only one author for AdwCleaner and its Xplode.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#7 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:54 AM

Posted 15 June 2015 - 09:18 PM

Go in the C:\AdwCleaner folder, there should be logs there called AdwCleaner[??].txt. Take the latest one, named AdwCleaner[S?].txt, where ? should be the highest number, open it and copy/paste the content here.

Edited by Aura., 15 June 2015 - 09:19 PM.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#8 Relaxing

Relaxing
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 09:23 PM

I'll put the HD in another computer, go to program files AdwCleaner and look.



#9 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:54 AM

Posted 15 June 2015 - 09:23 PM

The logs are located in C:\AdwCleaner and not C:\Program Files. Follow the instructions in the post above and you'll find it :)

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#10 Relaxing

Relaxing
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 09:45 PM

# AdwCleaner v4.204 - Logfile created 14/05/2015 at 16:11:16
# Updated 12/05/2015 by Xplode
# Database : 2015-05-12.2 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Jim&Carol - JIM-CAROL-T
# Running from : C:\Users\Jim&Carol\Downloads\adwcleaner_4.204.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage
File Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage
File Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage-journal
File Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage-journal
File Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_weatherblink.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.hydroflask.com_0.localstorage
File Found : C:\Users\Jim&Carol\AppData\Roaming\Mozilla\Firefox\Profiles\goks0jei.default\user.js
File Found : C:\Users\Jim&Carol\Desktop\Live PC Help.lnk
File Found : C:\WINDOWS\System32\roboot64.exe
Folder Found : C:\Program Files (x86)\Amazon\ABB
Folder Found : C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd
Folder Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Folder Found : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Folder Found : C:\Users\Jim&Carol\AppData\Roaming\rightbackup
Folder Found : C:\Users\Jim&Carol\AppData\Roaming\Systweak

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\systweak
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : [x64] HKCU\Software\systweak
Key Found : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKLM\SOFTWARE\systweak

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.yahoo.com?type=114576&fr=spigot-yhp-ie

-\\ Mozilla Firefox v27.0.1 (en-US)


-\\ Google Chrome v42.0.2311.152

[C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
[C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Found [Extension] : nfengeggddojhakldhlpjdlddgkkjkdd

*************************

AdwCleaner[R0].txt - [4644 bytes] - [14/05/2015 16:11:16]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4703 bytes] ##########
 



#11 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:54 AM

Posted 15 June 2015 - 09:47 PM

This is a legitimate AdwCleaner log, however it's from May 14th. Are you sure this is the latest log in the AdwCleaner folder?

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#12 Relaxing

Relaxing
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 09:49 PM

Windows update was installing updates at the same time AdwCleaner was doing this during the reboot



#13 Relaxing

Relaxing
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 09:50 PM

I'll look agian



#14 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,537 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:54 AM

Posted 15 June 2015 - 09:52 PM

You should go be modification date. Take the text file that have the most recent modification date in C:\AdwCleaner and that should be it.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#15 Relaxing

Relaxing
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:12:54 AM

Posted 15 June 2015 - 10:02 PM

I think these are real files. The fake AdwCleaner mite not write log's.

# AdwCleaner v4.204 - Logfile created 14/05/2015 at 16:13:04
# Updated 12/05/2015 by Xplode
# Database : 2015-05-12.2 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Jim&Carol - JIM-CAROL-T
# Running from : C:\Users\Jim&Carol\Downloads\adwcleaner_4.204.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\Amazon\ABB
Folder Deleted : C:\Users\Jim&Carol\AppData\Roaming\rightbackup
Folder Deleted : C:\Users\Jim&Carol\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Folder Deleted : C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd
[/!\] Not Deleted ( Junction ) : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
File Deleted : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage
File Deleted : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eofcbnmajmjmplflapaojjnihcjkigck_0.localstorage-journal
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\Users\Jim&Carol\Desktop\Live PC Help.lnk
File Deleted : C:\Users\Jim&Carol\AppData\Roaming\Mozilla\Firefox\Profiles\goks0jei.default\user.js
File Deleted : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_weatherblink.dl.tb.ask.com_0.localstorage
File Deleted : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Deleted : C:\Users\Jim&Carol\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.hydroflask.com_0.localstorage

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\systweak
Key Deleted : HKLM\SOFTWARE\systweak
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v27.0.1 (en-US)


-\\ Google Chrome v42.0.2311.152

[C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
[C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\carol thomas\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Deleted [Extension] : nfengeggddojhakldhlpjdlddgkkjkdd

*************************

AdwCleaner[R0].txt - [4802 bytes] - [14/05/2015 16:12:43]
AdwCleaner[S0].txt - [3850 bytes] - [14/05/2015 16:13:04]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3909  bytes] ##########
 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users