Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

AVG Trojans


  • This topic is locked This topic is locked
12 replies to this topic

#1 ilovemcree4079

ilovemcree4079

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 27 May 2017 - 01:13 PM

Hey,

I usually scan my computer using AVG from time and time and today it came up with a warning that it found and removed two trojans but am unsure whether these were false flags or not since I don't download things often and browse safely, I have attatched images of the 2 "trojan" files and the Addition log file. I was just unsure whether the flag was legit or not.

Attached Files



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,978 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:17 PM

Posted 29 May 2017 - 09:53 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Yes, wextrack.exe could be a backdoor Trojan.


Please download Malwarebytes Anti-Malware from here
  • Right-click on the MBAM icon and select Run as administrator to run the tool.
  • Click Yes to accept any security warnings that may appear.
  • Once the MBAM dashboard opens, on the right detail pane click on the word "Current" under the Scan Status to update the tool database.
  • On the left menu pane click the Settings tab, and then select the Protection tab on the top.
  • Under the Scan Options, turn on the button Scan for rootkits and Scan within archives.
  • Click the Scan tab on the right detail pane, select Threat Scan and click the Start Scan button
  • Note: The scan may take some time to finish, so please be patient.
  • If potential threats are detected, ensure to checkmark all the listed items, and click the Quarantine Selected button.
  • While still on the Scan tab, click the View Report button, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log can also be viewed by clicking the log to select it, then clicking the View Report button.
Please post the log for my review.

Note: If asked to restart the computer, please do so immediately.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the LogFile button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleanerCx.txt (x is a number).
===

Please post the logs.

p.s. You have submitted the Addition.txt file I need to see the FRST log created by the Farbar tool.

Let me know what problems persists.
==============================

#3 ilovemcree4079

ilovemcree4079
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 29 May 2017 - 11:31 AM

Hey it's not that I had any problems which i have not the computer runs the same as it always does since I was unsure whether these where legit trojans or false since i though they would be false due to the fact i don't know how they got there, what are the chances it was a false flag since I have not really had issues in that regard it was out of the blue...

Attached Files

  • Attached File  FRST.txt   53.46KB   3 downloads


#4 ilovemcree4079

ilovemcree4079
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 29 May 2017 - 11:42 AM

Hey I used Malware Bytes and it found nothing, do you think that these were and possibly false flags since it makes no sense to me how they even got on there since i browse very safley and keep my pc clean and safe to a ridiculous level.

Attached Files



#5 ilovemcree4079

ilovemcree4079
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 29 May 2017 - 03:01 PM

Hey here is the adwcleaner results do i need to remove any of the stuff it listed?

Attached Files


Edited by ilovemcree4079, 29 May 2017 - 03:01 PM.


#6 nasdaq

nasdaq

  • Malware Response Team
  • 38,978 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:17 PM

Posted 30 May 2017 - 07:30 AM

Hi,


ATTENTION: System Restore is disabled
Turn System Restore On for Drives in Windows 10
http://www.tenforums.com/tutorials/4533-system-protection-turn-off-drives-windows-10-a.html
===

AVG did it's job.

Now clean the PUP items that are installed by the Free AVG program.
When this fix is completed run the AdwCleaner program and delete everything that was idenfified.

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.


Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.7\ToolbarUpdater.exe
HKLM-x32\...\Run: [] => [X]
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2017-04-11]
ShortcutTarget: Twitch.lnk -> C:\Users\Alex\AppData\Roaming\Curse Client\Bin\Twitch.exe (No File)
HKU\S-1-5-21-572797196-1586269638-3121044298-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid=%7B01A4C6A5-A991-4B4A-867D-9D217F0D8752%7D&mid=8c85c3bc84c047ccbd67cdce6a84ce46-e50a8472d77cd510608dbd2a3b2b5cc856109bca&lang=en&ds=AVG&coid=avgtbavg&cmpid=1215av&pr=fr&d=2015-12-04%2019:37:32&v=4.2.3.128&pid=wtu&sg=&sap=hp
SearchScopes: HKU\S-1-5-21-572797196-1586269638-3121044298-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={01A4C6A5-A991-4B4A-867D-9D217F0D8752}&mid=8c85c3bc84c047ccbd67cdce6a84ce46-e50a8472d77cd510608dbd2a3b2b5cc856109bca&lang=en&ds=AVG&coid=avgtbavg&cmpid=1215av&pr=fr&d=2015-12-04 19:37:32&v=4.2.3.128&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-572797196-1586269638-3121044298-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={01A4C6A5-A991-4B4A-867D-9D217F0D8752}&mid=8c85c3bc84c047ccbd67cdce6a84ce46-e50a8472d77cd510608dbd2a3b2b5cc856109bca&lang=en&ds=AVG&coid=avgtbavg&cmpid=1215av&pr=fr&d=2015-12-04 19:37:32&v=4.2.3.128&pid=wtu&sg=&sap=dsp&q={searchTerms}
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.7\\npsitesafety.dll [No File]
CHR HomePage: Default -> mysearch.avg.com
CHR DefaultSearchURL: Default -> hxxps://mysearch.avg.com/search?rvt=1&sap=dsp&q={searchTerms}
CHR DefaultSearchKeyword: Default -> https://mysearch.avg.com
CHR DefaultSuggestURL: Default -> hxxps://toolbar.avg.com/acp?q={searchTerms}&o=1
CHR Extension: (AVG Secure Search) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2015-12-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-12]
CHR HKU\S-1-5-21-572797196-1586269638-3121044298-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx
R2 vToolbarUpdater40.3.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.7\ToolbarUpdater.exe [1354312 2017-02-07] (AVG Secure Search)
U3 idsvc; no ImagePath
Task: {5BA7BD13-85AE-4CFA-A8D9-1C96DC1B7272} - System32\Tasks\1215avUpdateInfo => C:\ProgramData\Avg_Update_1215av\1215av_AVG-Secure-Search-Update.exe
Task: {7EA6E8EA-F14B-4F37-ACEA-F9E637955E10} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\1215avUpdateInfo.job => C:\ProgramData\Avg_Update_1215av\1215av_AVG-Secure-Search-Update.exe


End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.

Please let me know what problem persists with this computer.

#7 ilovemcree4079

ilovemcree4079
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 30 May 2017 - 10:21 AM

I removed all that junk already using ADWCLEANER and it emptied it from the quarantine list



#8 nasdaq

nasdaq

  • Malware Response Team
  • 38,978 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:17 PM

Posted 30 May 2017 - 12:32 PM

Any issues with this computer?

#9 ilovemcree4079

ilovemcree4079
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 30 May 2017 - 12:43 PM

Not really at least not related to viruses in that regard, there wasnt any issues in the first place I was just suprised that it found trojans in the first place so wanted to make sure and see if avg was correct, few issues with it sometimes freezing on bootup at bios screen. windows but think its related to windows updates/ my graphics drivers piling up. I appreciate the help though!



#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,978 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:17 PM

Posted 31 May 2017 - 06:43 AM

Check the integrity of the operating system files.
How to run sfc /Scannow
http://support.microsoft.com/kb/929833

When completed refer to the Microsoft article again and follow the instructions to view details of the System File Checker process

Post the contents of the sfcdetails.txt file for my review.

Let me know if the problem persists.

#11 ilovemcree4079

ilovemcree4079
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 31 May 2017 - 07:48 AM

I reinstalled Graphics Drivers and that seemed to help I'll probably do a clean install of windows on a new drive soon anyways since my curent ssd is almost 6 years old...



#12 nasdaq

nasdaq

  • Malware Response Team
  • 38,978 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:17 PM

Posted 03 June 2017 - 07:08 AM

Copied from a Personal message.

Fix result of Farbar Recovery Scan Tool (x64) Version: 02-06-2017
Ran by Alex (02-06-2017 20:52:11) Run:1
Running from C:\Users\Alex\Downloads
Loaded Profiles: Alex (Available Profiles: Alex)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.7\ToolbarUpdater.exe
HKLM-x32\...\Run: [] => [X]
Startup: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2017-04-11]
ShortcutTarget: Twitch.lnk -> C:\Users\Alex\AppData\Roaming\Curse Client\Bin\Twitch.exe (No File)
HKU\S-1-5-21-572797196-1586269638-3121044298-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid=%7B01A4C6A5-A991-4B4A-867D-9D217F0D8752%7D&mid=8c85c3bc84c047ccbd67cdce6a84ce46-e50a8472d77cd510608dbd2a3b2b5cc856109bca&lang=en&ds=AVG&coid=avgtbavg&cmpid=1215av&pr=fr&d=2015-12-04%2019:37:32&v=4.2.3.128&pid=wtu&sg=&sap=hp
SearchScopes: HKU\S-1-5-21-572797196-1586269638-3121044298-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={01A4C6A5-A991-4B4A-867D-9D217F0D8752}&mid=8c85c3bc84c047ccbd67cdce6a84ce46-e50a8472d77cd510608dbd2a3b2b5cc856109bca&lang=en&ds=AVG&coid=avgtbavg&cmpid=1215av&pr=fr&d=2015-12-04 19:37:32&v=4.2.3.128&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-572797196-1586269638-3121044298-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={01A4C6A5-A991-4B4A-867D-9D217F0D8752}&mid=8c85c3bc84c047ccbd67cdce6a84ce46-e50a8472d77cd510608dbd2a3b2b5cc856109bca&lang=en&ds=AVG&coid=avgtbavg&cmpid=1215av&pr=fr&d=2015-12-04 19:37:32&v=4.2.3.128&pid=wtu&sg=&sap=dsp&q={searchTerms}
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.7\\npsitesafety.dll [No File]
CHR HomePage: Default -> mysearch.avg.com
CHR DefaultSearchURL: Default -> hxxps://mysearch.avg.com/search?rvt=1&sap=dsp&q={searchTerms}
CHR DefaultSearchKeyword: Default -> https://mysearch.avg.com
CHR DefaultSuggestURL: Default -> hxxps://toolbar.avg.com/acp?q={searchTerms}&o=1
CHR Extension: (AVG Secure Search) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2015-12-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Chrome Media Router) - C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-12]
CHR HKU\S-1-5-21-572797196-1586269638-3121044298-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx
R2 vToolbarUpdater40.3.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.7\ToolbarUpdater.exe [1354312 2017-02-07] (AVG Secure Search)
U3 idsvc; no ImagePath
Task: {5BA7BD13-85AE-4CFA-A8D9-1C96DC1B7272} - System32\Tasks\1215avUpdateInfo => C:\ProgramData\Avg_Update_1215av\1215av_AVG-Secure-Search-Update.exe
Task: {7EA6E8EA-F14B-4F37-ACEA-F9E637955E10} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\1215avUpdateInfo.job => C:\ProgramData\Avg_Update_1215av\1215av_AVG-Secure-Search-Update.exe


End
*****************

Error: (0) Failed to create a restore point.
Processes closed successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.7\ToolbarUpdater.exe => No running process found
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk => moved successfully
C:\Users\Alex\AppData\Roaming\Curse Client\Bin\Twitch.exe => not found.
HKU\S-1-5-21-572797196-1586269638-3121044298-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-572797196-1586269638-3121044298-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-572797196-1586269638-3121044298-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => key not found.
HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => key not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin => key not found.
Chrome HomePage => not found.
Chrome DefaultSearchURL => not found.
Chrome DefaultSearchKeyword => not found.
Chrome DefaultSuggestURL => not found.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn => not found
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => moved successfully
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm => moved successfully
HKU\S-1-5-21-572797196-1586269638-3121044298-1000\SOFTWARE\Google\Chrome\Extensions\chfdnecihphmhljaaejmgoiahnihplgn => key not found.
vToolbarUpdater40.3.7 => service not found.
HKLM\System\CurrentControlSet\Services\idsvc => key removed successfully
idsvc => service removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5BA7BD13-85AE-4CFA-A8D9-1C96DC1B7272} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BA7BD13-85AE-4CFA-A8D9-1C96DC1B7272} => key removed successfully
C:\WINDOWS\System32\Tasks\1215avUpdateInfo => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1215avUpdateInfo => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7EA6E8EA-F14B-4F37-ACEA-F9E637955E10} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7EA6E8EA-F14B-4F37-ACEA-F9E637955E10} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask => key removed successfully
C:\WINDOWS\Tasks\1215avUpdateInfo.job => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8675328 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 171479938 B
Java, Flash, Steam htmlcache => 534145284 B
Windows/system/drivers => 120502525 B
Edge => 1651393 B
Chrome => 691160997 B
Firefox => 376481373 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 16674 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 128 B
LocalService => 236156 B
NetworkService => 4832 B
Alex => 340189472 B

RecycleBin => 283389378 B
EmptyTemp: => 2.4 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:52:41 ====

I deleted the FRST file in downloads and the FRST folder in my C drive would this be the correct way to remove, also is there anything else i have to do in regards to cleaning or is that ok now?

=============


Download Delfix from this site.
https://www.bleepingcomputer.com/download/delfix/

DelFix is a tool developed by Xplode, the makers of AdwCleaner, which can remove all portable virus cleaning and disinfection tools you’ve ever used. It will also reset the restore points of your computer systems making it even safer.

The program makes some other adjustments to your PC too which include:

Activate UAC: It activates the user account control after cleaning the log files and the unnecessary clutter in your PC.
Remove disinfection tools: Removes the tool you’ve ever used to disinfect your PC.
Create registry backup: The program creates a registry backup and stores it under % windir% \ ERUNT \ DelFix.
Purge system restore: Deletes all your older restore points and creates a fresh one.
Reset system settings: It resets the system settings after the removal process is completed.


Just download the program and run it on your computer system.
There is a default check-mark on feature ‘Remove disinfection tools’ and you need to check other feature manually before running the program should you wish to.
Wait for a few minutes and your computer system will be free of all unnecessary files.

p.s.
Run this tool with the following options.
Remove disinfection tools: Removes the tool you’ve ever used to disinfect your PC.
Create registry backup: The program creates a registry backup and stores it under % windir% \ ERUNT \ DelFix.

Check to make sure that a restore point was created.

Let me know what problem persists with this computer.

#13 ilovemcree4079

ilovemcree4079
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:09:17 PM

Posted 03 June 2017 - 07:19 AM

Hey I ran Delfix does it delete itself after the usage since it's gone, also in regards to the restore point I likley won't bother since im fresh installing soon so ill do when I reinstall on a new drive. I appreciate the help! hopefully should be all good now till i change drives :).


Edited by ilovemcree4079, 03 June 2017 - 07:24 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users