Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

How to delete/defeat false administrator


  • Please log in to reply
9 replies to this topic

#1 dolman

dolman

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:57 PM

Posted 03 June 2017 - 07:37 PM

A false administrator is on my computer and I need help eliminating it!

I tried elevating a control prompt and the God mode but they were denied or blocked. 

entering security on files that I cannot delete shows an administrator named users (Pete-PC/users)

Pete is the administrator I put on my computer

I first noticed this on a Version of the Chromium Browser that I never put on my computer.

As I have tried various things to get rid of it this browser has changed as follows:

      After using the Control panel to delete it, it is no longer on the list of programs, but it's there!

      Some times on clicking properties The general tab shows 0 files and folders and 0bytes,but the actual size is not changed.

I tried compressing the file and encrypting the file to see if that would do anything properties says that the size of the file reduced from over 400mb to 291mb

 

Also: The file has a creation date 3/1/16 but there are no registry items with that date stamp.

At about that date I stopped being able to access the Documents folder and when I try to use it I get a message urging me to delete it. I finally checked yesterday the same administrator is on that folder.

 

This is getting long but my excuse for letting this problem continue is that when Microsoft was forcing 10 downloads on me I had a power failure that cut off the download after 2700 of more than 30000 .dll files were on the computer and the computer went bannnanas. I've learned a lot fixing it, but this is beyond me!

 

OPPs I running 7 pro 64 bit on a 45 gig SS drive that has < 8 gigs left


Edited by hamluis, 04 June 2017 - 05:18 PM.
Moved from Win 7 to AII - Hamluis.


BC AdBot (Login to Remove)

 


#2 zainmax

zainmax

  • Banned
  • 344 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:57 AM

Posted 03 June 2017 - 08:06 PM

Who is the real administrator, ask him/her, let makes these changes. Users cannot remove administrators.



#3 Guest_Aaron_Warrior_*

Guest_Aaron_Warrior_*

  • Guests
  • OFFLINE
  •  

Posted 03 June 2017 - 08:17 PM

Who owns the computer?


Edited by hamluis, 04 June 2017 - 08:42 AM.


#4 hamluis

hamluis

    Moderator


  • Moderator
  • 56,287 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX

Posted 04 June 2017 - 08:42 AM

Please download MiniToolBox  , save it to your desktop and run it.
 
Checkmark the following checkboxes:
  List last 10 Event Viewer log
  List Installed Programs
  List Users, Partitions and Memory size.
 
Click Go and paste the content into your next post.
 
Also...please Publish a Snapshot using Speccy taking care to post the link of the snapshot in your next post.

   Go to Piriform's website, and download the free version on the left.  Click Download from Piriform.com (the FileHippo link requires an extra click). Or if you want to use a portable version of Speccy (which doesn't require installation), click the builds page link and download the portable version. You will now be asked where you want to save the file. The best place to put it is the Desktop, as it will be easy to find later.

    After the file finishes downloading, you are ready to run Speccy. If you downloaded the installer, simply double-click on it and follow the prompts until installation is complete. If you downloaded the portable version, you will need to unzip it before use. Right-click the ZIP file and click Extract all. Click Next. Open up the extracted folder and double-click on Speccy.
 
     Once inside Speccy, it will look similar to this (with your computer's specifications, of course):
 
post-33068-0-86653600-1480692866_thumb.j

     Now, at the top, click File > Publish Snapshot.

     Click Yes > then Copy to Clipboard

Now, once you are back in the forum topic you are posting in, click the ADD REPLY or REPLY TO THIS TOPIC button. Right-click in the empty space of the Reply box and click Paste. Then, click Add Reply below the Reply box.

Louis



#5 dolman

dolman
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:57 PM

Posted 04 June 2017 - 03:24 PM

Thank you very much Louis 

Tried the Chromium removal method from you guys again this morning. This time the Malwear bytes step ran OK and found a rootkit, but the things are still there though a lot of other stuff is gone. 

don't know   "Speccy" but I expect it's on Piriform. Copied your post,  

 ok Got Specy thanks again 


Edited by dolman, 04 June 2017 - 03:32 PM.


#6 dolman

dolman
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:57 PM

Posted 04 June 2017 - 04:10 PM

Here is the mini toolbox log
MiniToolBox by Farbar Version: 17-06-2016
Ran by online (ATTENTION: The logged in user is not administrator) on 04-06-2017 at 13:35:29
Running from "C:\Users\online\Desktop"
Microsoft Windows 7 Professional Service Pack 1 (X64)
Model: All Series Manufacturer: ASUS

Boot Mode: Normal
***************************************************************************

========================= Event log errors: ===============================

Application errors:
==================
Error: (06/04/2017 12:27:39 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/04/2017 12:16:08 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/04/2017 11:20:44 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2017 10:30:44 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2017 09:54:37 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2017 12:53:59 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2017 09:29:16 AM) (Source: Application Hang) (User: )
Description: The program Everything.exe version 1.2.1.371 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 478
Start Time: 01d2dbbd1b77601d
Termination Time: 16
Application Path: D:\Program Files (x86)\Everything\Everything.exe
Report Id: 8e5d2f9f-47b0-11e7-b21d-305a3a5b5438

Error: (06/02/2017 09:09:28 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/01/2017 05:19:02 PM) (Source: Brother BrLog) (User: )
Description: CC4MN BrtCC4MN: [2017/06/01 17:19:02.451]: [00003400]: FAILED to get path of RootFolder for CC4 Data. (ErrCode = 0x54F)

Error: (06/01/2017 04:46:14 PM) (Source: System Restore) (User: )
Description: An unspecified error occurred during System Restore: (Scheduled Checkpoint). Additional information: 0x80070005.

System errors:
=============
Error: (06/04/2017 12:26:46 PM) (Source: Service Control Manager) (User: )
Description: The Print Spooler service failed to start due to the following error:  %%1069 = The service did not start due to a logon failure.

Error: (06/04/2017 12:26:46 PM) (Source: Service Control Manager) (User: )
Description: The Spooler service was unable to log on as NT AUTHORITY\SYSTEM with the currently configured password due to the following error:  %%50 = The request is not supported.  To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (06/04/2017 12:25:49 PM) (Source: Service Control Manager) (User: )
Description: The Acronis Sync Agent Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (06/04/2017 12:25:49 PM) (Source: Service Control Manager) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (06/04/2017 12:25:49 PM) (Source: Service Control Manager) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.

Error: (06/04/2017 12:25:49 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (06/04/2017 12:25:48 PM) (Source: Service Control Manager) (User: )
Description: The BrYNSvc service terminated unexpectedly. It has done this 1 time(s).

Error: (06/04/2017 12:25:47 PM) (Source: Service Control Manager) (User: )
Description: The Acronis Managed Machine Service Mini service terminated unexpectedly. It has done this 1 time(s).

Error: (06/04/2017 12:25:47 PM) (Source: Service Control Manager) (User: )
Description: The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).

Error: (06/04/2017 12:25:47 PM) (Source: Service Control Manager) (User: )
Description: The ASUS Com Service service terminated unexpectedly. It has done this 1 time(s).

Microsoft Office Sessions:
=========================
Error: (06/04/2017 12:27:39 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/04/2017 12:16:08 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/04/2017 11:20:44 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2017 10:30:44 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2017 09:54:37 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2017 12:53:59 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/02/2017 09:29:16 AM) (Source: Application Hang)(User: )
Description: Everything.exe1.2.1.37147801d2dbbd1b77601d16D:\Program Files (x86)\Everything\Everything.exe8e5d2f9f-47b0-11e7-b21d-305a3a5b5438

Error: (06/02/2017 09:09:28 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/01/2017 05:19:02 PM) (Source: Brother BrLog)(User: )
Description: CC4MNBrtCC4MN: [2017/06/01 17:19:02.451]: [00003400]: FAILED to get path of RootFolder for CC4 Data. (ErrCode = 0x54F)

Error: (06/01/2017 04:46:14 PM) (Source: System Restore)(User: )
Description: Scheduled Checkpoint0x80070005

=========================== Installed Programs ============================
Acronis True Image (HKLM-x32\...\{4AF9B183-3620-49EA-93B5-FDF77818DBC7}) (Version: 20.0.8053 - Acronis) Hidden
Acronis True Image (HKLM-x32\...\{4AF9B183-3620-49EA-93B5-FDF77818DBC7}Visible) (Version: 20.0.8053 - Acronis)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Flash Player 25 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Ancient Jewels 3 v1.0.1 (HKLM-x32\...\Ancient Jewels 3_is1) (Version: - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Brother MFL-Pro Suite MFC-L2700DW series (HKLM-x32\...\{F8ECC2FD-CE2B-4ED4-BDCC-90D0D34206FD}) (Version: 1.0.2.0 - Brother Industries, Ltd.)
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.20.286 - SurfRight B.V.)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4170 - Intel Corporation)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.0.1.5 - PandoraTV)
Magical Jelly Bean KeyFinder (HKLM-x32\...\KeyFinder_is1) (Version: 2.0.10.10 - Magical Jelly Bean)
Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft Encarta Encyclopedia Standard 2004 (HKLM-x32\...\{04410044-9149-45C6-A806-F2BF9CFCE762}) (Version: 2004 - Microsoft Corporation)
Microsoft Office XP Media Content (HKLM-x32\...\{90300409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2619.0 - Microsoft Corporation)
Microsoft Office XP Small Business (HKLM-x32\...\{91130409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.01 - Microsoft Corporation)
Microsoft Picture It! Photo Premium 9 (HKLM-x32\...\PictureIt_v9) (Version: 9.0.0.0000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Word 2002 (HKLM-x32\...\{911B0409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.01 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{B9966F27-9678-4620-9579-925E3084647E}) (Version: 07.03.0719 - Microsoft Corporation)
Microsoft Works 2004 Setup Launcher (HKLM-x32\...\Works2004Setup) (Version: - )
Microsoft Works Suite Add-in for Microsoft Word (HKLM-x32\...\{33BEE6F3-9987-4F98-A069-97A64EC8321A}) (Version: 7.0.0.0000 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
Sandboxie 5.18 (64-bit) (HKLM\...\Sandboxie) (Version: 5.18 - Sandboxie Holdings, LLC)
Shockwave (HKLM-x32\...\Shockwave) (Version: - )
TaxAct 2015 1040 Edition (HKLM-x32\...\TaxAct 2015 1040 Edition) (Version: 1.08 - TaxAct, Inc.)
TaxAct 2015 California (HKLM-x32\...\TaxAct 2015 California) (Version: 1.03 - TaxAct, Inc.)
TaxAct 2016 1040 Edition (HKLM-x32\...\TaxAct 2016 1040 Edition) (Version: 1.03 - TaxAct, Inc.)
TaxAct 2016 California (HKLM-x32\...\TaxAct 2016 California) (Version: 1.01 - TaxAct, Inc.)
WinPatrol (HKLM-x32\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 35.5.2017.8 - Ruiware)
ZoneAlarm Antivirus (HKLM-x32\...\{D457D6C7-C040-40CB-8BF8-D8ECC8FDDACE}) (Version: 15.1.501.17249 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Extreme Security (HKLM-x32\...\ZoneAlarm Extreme Security) (Version: 15.1.501.17249 - Check Point)
ZoneAlarm Find My Laptop (HKLM-x32\...\{C7E7A446-DE1F-441D-9519-BD858266A7AB}) (Version: 15.1.501.17249 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Firewall (HKLM-x32\...\{902E1EFE-94FC-4209-9409-EBB2CA9E8DA6}) (Version: 15.1.501.17249 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Parental Controls (HKLM\...\{9D0D6B72-4C5C-498D-9A8A-DA53341E8BC1}) (Version: 7.2.6.1 - ContentWatch) Hidden
ZoneAlarm Security (HKLM-x32\...\{9F5DAD59-9A81-44E4-A075-0C943932FD10}) (Version: 15.1.501.17249 - Check Point Software Technologies Ltd.) Hidden


========================= Memory info: ===================================
Percentage of memory in use: 30%
Total physical RAM: 8064.04 MB
Available physical RAM: 5619.21 MB
Total Virtual: 16126.29 MB
Available Virtual: 13787.53 MB

========================= Partitions: =====================================
1 Drive c: (New Volume) (Fixed) (Total:55.9 GB) (Free:6.93 GB) NTFS
2 Drive d: (WIN7) (Fixed) (Total:819.21 GB) (Free:736.05 GB) NTFS
3 Drive e: (DATA) (Fixed) (Total:1205.33 GB) (Free:1120.38 GB) NTFS
5 Drive g: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
6 Drive h: () (Fixed) (Total:931.41 GB) (Free:910.26 GB) NTFS

========================= Users: ========================================
User accounts for \\PETE-PC

http://speccy.piriform.com/results/L07byDXV2mo1wIOnrxlIBRD
 

Edited by hamluis, 04 June 2017 - 05:10 PM.


#7 hamluis

hamluis

    Moderator


  • Moderator
  • 56,287 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:08:57 PM

Posted 04 June 2017 - 05:18 PM

For Your Info.

 

You have a scheduled item listed for above reflected on your Speccy data.

 

Topic moved to Am I Infected based on stated Administrator problems and above.

 

Louis



#8 dolman

dolman
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:57 PM

Posted 04 June 2017 - 06:44 PM

Thank you I'll try to find it. There is no doubt I am infected.

FYI the rouge administrator shows up in all the downloads I used.

Didn't look when I was running them

 

Question this thing aggressively blocks helpful files and something it does not want seen must be in my documents folder.

If I put a password on a flash drive and downloaded the files to that would that isolate this and prevent administrator from infecting them??


Edited by dolman, 04 June 2017 - 06:53 PM.


#9 Guest_Aaron_Warrior_*

Guest_Aaron_Warrior_*

  • Guests
  • OFFLINE
  •  

Posted 04 June 2017 - 09:02 PM

Thank you I'll try to find it. There is no doubt I am infected.

FYI the rouge administrator shows up in all the downloads I used.

Didn't look when I was running them

 

Question this thing aggressively blocks helpful files and something it does not want seen must be in my documents folder.

If I put a password on a flash drive and downloaded the files to that would that isolate this and prevent administrator from infecting them??

 

It's a bad idea to do any kind of computing at all, downloading, anything, until you are malware free.  You should assume ever file on that computer, and any file that comes into it, is infected, and will infect someone else's computer too.



#10 dolman

dolman
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:57 PM

Posted 05 June 2017 - 02:00 PM

Louis:

          Thank you for your help. Re Smart System Care. I removed most of it from the control panel, but the bad administrator grabbed one file and locked it. Wish I understood permissions better.  is there a specific place in the registry where users are stored? I have hunted there but 30000 plus files makes a dense thicket.

 

Warrior:

           Every thing you say is true. Wish I had other options.

 

everybody:

           Any helpful suggestions are welcome! I won't carp at SWAGS.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users