Co to może być za wirus i jak go usunąć?
#1
Mam chyba jakiegoś dziwnego wirusa. Mianowicie niedawno (4 dni temu) mój Windows XP HE został zablokowany. Używałem zawsze konta Administratorabez wpisywania hasła i nagle po tym jak oczyściłem sobie rejestr programem jv16 power tools 1.4.1 po restarcie systemu pojawił mi się monit z logowaniem którego wcześniej nie ustawiałem oraz prośba o wpisanie hasła.
Wszelkie próby naprawy systemu nie powiodły się w związku z tym zainstalowałem od nowa system zgrałem. Jednak co jakiś czas traciłem kontrolę na kompem tzn. wyglądało to tak jakby ktoś z zewnątrz uruchamiał mi programy nawet otwierał moją AVIRE ale zawsze powtarzało się pakowanie Menu Start prze WinRar’a.
Myślałem że ktoś sobie robi jaja (a nie bardzo mi do śmiechu bo pisze prace mgr) więc ze względów bezpieczeństwa wyjąłem nawet kartę sieciową. Przez chwile miałem spokój ale… niestety tylko na chwile Sad
Dlatego też podejrzewam że to tylko jakiś nieznośny wirus. Ale wszystkie pliki z partycji D: zgrałem na płyty i je skasowałem.
Przeskanowałem dysk C i D nowym programem antywirusowym oczywiście AVIRą w wersji Premium(załapałem się wcześniej na tą darmową licencję) Avirka na C nie wykryła nic ale na D wykryła i usunąłem je. Załączam log:

Kod:
Start of the scan: 1 lipca 200814:48

Starting the file scan:

Begin scan in ''D:''
D:System Volume Information_restore{7AF14544-7227-42B5-A4BB-79358B3D7AD3}RP28A0013690.exe
[DETECTION] Contains detection pattern of the dropper DR/PSW.PWDump.2.3
[NOTE]The file was deleted!
D:System Volume Information_restore{FA556BE3-E679-46F7-92EC-821F13C73D98}RP12A0002819.exe
[DETECTION] Contains detection pattern of the SPR/CodeRevel.A.3 program
[NOTE]The file was deleted!
D:System Volume Information_restore{FA556BE3-E679-46F7-92EC-821F13C73D98}RP12A0002820.dll
[DETECTION] Contains detection pattern of the SPR/CodeRevel.A.1 program
[NOTE]The file was deleted!
D:System Volume Information_restore{FA556BE3-E679-46F7-92EC-821F13C73D98}RP12A0002822.exe
[DETECTION] Is the Trojan horse TR/Dldr.Zlob.jbe.26
[NOTE]The file was deleted!


End of the scan: 1 lipca 200814:55
Used time: 06:57 min

The scan has been done completely.

27 Scanning directories
7121 Files were scanned
4 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
4 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
7117 Files not concerned
138 Archives were scanned
0 Warnings
4 Notes


Niestety problem nadal się pojawiał więc sformatowałem dysk D i wcześniej wyłączyłem przywracanie systemu. Formata zrobiłem z poziomu systemu Windows raz szybkie a później normalne. Po formacie dysk jednak nie jest zupełnie czysty mimo iż nic nie ma to jednak gdy sprawdzam przez prawy przycisk myszki i Właściwości to widać że Zajęte miejsce:16 KB.

Dołączam jeszcze Log z programu Hijackthis z wersji 2.0.2 i proszę o pomoc.

Kod:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:08:51, on 2008-07-01
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesLavasoftAd-Aware 2007aawservice.exe
C:WINDOWSExplorer.EXE
C:Program FilesAviraAntiVir PersonalEdition Premiumavgnt.exe
C:Program FilesHPHP Software UpdateHPWuSchd2.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesHPDigital Imagingbinhpqtra08.exe
C:WINDOWSsystem32spoolsv.exe
C:Program Files802.11g Wireless LANMonitor.exe
C:Program FilesAviraAntiVir PersonalEdition Premiumsched.exe
C:Program FilesAviraAntiVir PersonalEdition Premiumavguard.exe
C:Program FilesAviraAntiVir PersonalEdition Premiumavesvc.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesAviraAntiVir PersonalEdition PremiumAVWEBGRD.EXE
C:WINDOWSsystem32wscntfy.exe
C:Program FilesHPDigital ImagingbinhpqSTE08.exe
C:WINDOWSsystem32wpabaln.exe
C:HiJackThisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:Program FilesHPSmart Web Printinghpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:Program FilesHPSmart Web Printinghpswp_framework.dll
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir PersonalEdition Premiumavgnt.exe" /min
O4 - HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe
O4 - HKLM..Run: [Ashampoo FireWall] "C:Program FilesAshampooAshampoo FireWallFireWall.exe" -TRAY
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ''USŁUGA LOKALNA'')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ''USŁUGA SIECIOWA'')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ''SYSTEM'')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User ''Default user'')
O4 - Startup: Monitor.lnk = C:Program Files802.11g Wireless LANMonitor.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: Kolekcja wycinków HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:Program FilesHPSmart Web Printinghpswp_extensions.dll
O9 - Extra button: Zaznaczanie HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:Program FilesHPSmart Web Printinghpswp_extensions.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:Program FilesLavasoftAd-Aware 2007aawservice.exe
O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Premiumavmailc.exe
O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Premiumsched.exe
O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Premiumavguard.exe
O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition PremiumAVWEBGRD.EXE
O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Premiumavesvc.exe

--
End of file - 4404 bytes


A dodam, że wcześniej używałem programu antywirusowego Avast 4.8 Pro

Dodaje jeszcze log zSilent Runners:

Kod:
"Silent Runners.vbs", revision 58, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}
"CTFMON.EXE" = "C:WINDOWSsystem32ctfmon.exe" [MS]
"MSMSGS" = ""C:Program FilesMessengermsmsgs.exe" /background" [MS]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"avgnt" = ""C:Program FilesAviraAntiVir PersonalEdition Premiumavgnt.exe" /min" ["Avira GmbH"]
"HP Software Update" = "C:Program FilesHPHP Software UpdateHPWuSchd2.exe" ["Hewlett-Packard Co."]
"Ashampoo FireWall" = ""C:Program FilesAshampooAshampoo FireWallFireWall.exe" -TRAY" [null data]
"NeroFilterCheck" = "C:WINDOWSsystem32NeroCheck.exe" ["Ahead Software Gmbh"]

HKLMSOFTWAREMicrosoftActive SetupInstalled Components
>{26923b43-4d38-484f-9b9e-de460746276c}(Default) = "Internet Explorer"
StubPath = "C:WINDOWSsystem32shmgrate.exe OCInstallUserConfigIE" [MS]
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}(Default) = "Outlook Express"
StubPath = "C:WINDOWSsystem32shmgrate.exe OCInstallUserConfigOE" [MS]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{0347C33E-8762-4905-BF09-768834316C61}(Default) = "HP Print Enhancer"
-> {HKLM...CLSID} = "HP Print Enhancer"
InProcServer32(Default) = "C:Program FilesHPSmart Web Printinghpswp_printenhancer.dll" ["Hewlett-Packard Co."]
{053F9267-DC04-4294-A72C-58F732D338C0}(Default) = (no title provided)
-> {HKLM...CLSID} = "HP Print Clips"
InProcServer32(Default) = "C:Program FilesHPSmart Web Printinghpswp_framework.dll" ["Hewlett-Packard Co."]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSsystem32hticons.dll" [file not found]
"{3028902F-6374-48b2-8DC6-9725E775B926}" = "IE Microsoft AutoComplete"
-> {HKLM...CLSID} = "IE Microsoft AutoComplete"
InProcServer32(Default) = "C:WINDOWSsystem32browseui.dll" [MS]
"{EFA24E62-B078-11d0-89E4-00C04FC9E26E}" = "History Band"
-> {HKLM...CLSID} = "History Band"
InProcServer32(Default) = "C:WINDOWSsystem32shdocvw.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10msohev.dll" [MS]
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
InProcServer32(Default) = "C:Program FilesAviraAntiVir PersonalEdition Premiumshlext.dll" ["Avira GmbH"]
"{0561EC90-CE54-4f0c-9C55-E226110A740C}" = "Haali Column Provider"
-> {HKLM...CLSID} = "Haali Column Provider"
InProcServer32(Default) = "C:WINDOWSsystem32mmfinfo.dll" [null data]
"{5574006C-28F5-4a65-A28C-74DE6BFBE0BB}" = "Haali Matroska Shell Property Page"
-> {HKLM...CLSID} = "Haali Matroska Shell Property Page"
InProcServer32(Default) = "C:WINDOWSsystem32mmfinfo.dll" [null data]
"{327669A0-59A7-4be9-B99E-1C9F3A57611A}" = "Haali Matroska Thumbnail Extractor"
-> {HKLM...CLSID} = "Haali Matroska Thumbnail Extractor"
InProcServer32(Default) = "C:WINDOWSsystem32mmfinfo.dll" [null data]

HKLMSYSTEMCurrentControlSetControlSession Manager
<<!>> "BootExecute" = "autocheck autochk *"|"lsdelete" [null data]

HKLMSOFTWAREClassesFoldershellexColumnHandlers
{0561EC90-CE54-4f0c-9C55-E226110A740C}(Default) = "Haali Column Provider"
-> {HKLM...CLSID} = "Haali Column Provider"
InProcServer32(Default) = "C:WINDOWSsystem32mmfinfo.dll" [null data]

HKLMSOFTWAREClasses*shellexContextMenuHandlers
Shell Extension for Malware scanning(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
InProcServer32(Default) = "C:Program FilesAviraAntiVir PersonalEdition Premiumshlext.dll" ["Avira GmbH"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]

HKLMSOFTWAREClassesDirectoryshellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]

HKLMSOFTWAREClassesFoldershellexContextMenuHandlers
Shell Extension for Malware scanning(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
InProcServer32(Default) = "C:Program FilesAviraAntiVir PersonalEdition Premiumshlext.dll" ["Avira GmbH"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem

"disableregistrytools" = (REG_DWORD) dword:0x00000000
{Prevent access to registry editing tools}

HKCUSoftwarePoliciesMicrosoftWindowsSystem

"disablecmd" = (REG_DWORD) dword:0x00000000
{Disable the command prompt}

HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState


Windows Portable Device AutoPlay Handlers
-----------------------------------------

HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAutoplayHandlersHandlers

HPAutoplayPSE
"Provider" = "HP Photosmart Essential 2.01"
"InvokeProgID" = "HpqPSApl.Autoplay"
"InvokeVerb" = "Play"
HKLMSOFTWAREClassesHpqPSApl.AutoplayshellPlayDropTargetCLSID = "{A6873065-D632-4615-A3A9-C5F05EE109C1}"
-> {HKLM...CLSID} = (no title provided)
LocalServer32(Default) = "C:Program FilesHPDigital ImagingbinHpqPsApl.exe" ["Hewlett-Packard"]


Startup items in "Admin" & "All Users" startup folders:
-------------------------------------------------------

C:Documents and SettingsAdminMenu StartProgramyAutostart
"Monitor" -> shortcut to: "C:Program Files802.11g Wireless LANMonitor.exe" [empty string]

C:Documents and SettingsAll UsersMenu StartProgramyAutostart
"HP Digital Imaging Monitor" -> shortcut to: "C:Program FilesHPDigital Imagingbinhpqtra08.exe" ["Hewlett-Packard Co."]
"Microsoft Office" -> shortcut to: "C:Program FilesMicrosoft OfficeOffice10OSA.EXE -b -l" [MS]


Enabled Scheduled Tasks:
------------------------

"WebReg Deskjet F2100 series" -> launches: "C:Program FilesHPDigital Imagingbinhpqwrg.exe "Deskjet F2100 series"" ["Hewlett-Packard Co."]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

Transport Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
C:Program FilesAshampooAshampoo FireWallspi.dll [null data], 01 - 07, 18 - 19
%SystemRoot%system32mswsock.dll [MS], 08 - 17, 22 - 24
avsda.dll ["Avira GmbH"], 20 - 21, 27
%SystemRoot%system32rsvpsp.dll [MS], 25 - 26


Toolbars, Explorer Bars, Extensions:
------------------------------------

Extensions (Tools menu items, main toolbar menu buttons)

HKLMSOFTWAREMicrosoftInternet ExplorerExtensions
{58ECB495-38F0-49CB-A538-10282ABF65E7}
"ButtonText" = "Kolekcja wycinków HP"
"CLSIDExtension" = "{E763472E-A716-4CD9-89BD-DBDA6122F741}"
-> {HKLM...CLSID} = "ClipBookBtn Class"
InProcServer32(Default) = "C:Program FilesHPSmart Web Printinghpswp_extensions.dll" ["Hewlett-Packard Co."]

{700259D7-1666-479A-93B1-3250410481E8}
"ButtonText" = "Zaznaczanie HP Smart"
"CLSIDExtension" = "{A93C41D8-01F8-4F8B-B14C-DE20B117E636}"
-> {HKLM...CLSID} = "EnhSelectionBtn Class"
InProcServer32(Default) = "C:Program FilesHPSmart Web Printinghpswp_extensions.dll" ["Hewlett-Packard Co."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:Program FilesMessengermsmsgs.exe" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ad-Aware 2007 Service, aawservice, ""C:Program FilesLavasoftAd-Aware 2007aawservice.exe"" ["Lavasoft"]
Avira AntiVir Premium Guard, AntiVirService, ""C:Program FilesAviraAntiVir PersonalEdition Premiumavguard.exe"" ["Avira GmbH"]
Avira AntiVir Premium MailGuard helper service, AVEService, ""C:Program FilesAviraAntiVir PersonalEdition Premiumavesvc.exe"" ["Avira GmbH"]
Avira AntiVir Premium Scheduler, AntiVirScheduler, ""C:Program FilesAviraAntiVir PersonalEdition Premiumsched.exe"" ["Avira GmbH"]
Avira AntiVir Premium WebGuard, antivirwebservice, ""C:Program FilesAviraAntiVir PersonalEdition PremiumAVWEBGRD.EXE"" ["Avira GmbH"]
hpqcxs08, hpqcxs08, "C:WINDOWSsystem32svchost.exe -k hpdevmgmt" {"C:Program FilesHPDigital Imagingbinhpqcxs08.dll" ["Hewlett-Packard Co."]}
Net Driver HPZ12, Net Driver HPZ12, "C:WINDOWSSystem32svchost.exe -k HPZ12" {"C:WINDOWSsystem32HPZinw12.dll" ["Hewlett-Packard"]}
Pml Driver HPZ12, Pml Driver HPZ12, "C:WINDOWSSystem32svchost.exe -k HPZ12" {"C:WINDOWSsystem32HPZipm12.dll" ["Hewlett-Packard"]}
Usługa HP CUE DeviceDiscovery, hpqddsvc, "C:WINDOWSsystem32svchost.exe -k hpdevmgmt" {"C:Program FilesHPDigital Imagingbinhpqddsvc.dll" ["Hewlett-Packard Co."]}


Print Monitors:
---------------

HKLMSYSTEMCurrentControlSetControlPrintMonitors
LIDIL hpzll5haDriver = "hpzll5ha.dll" ["Hewlett-Packard Company"]
PrimoMonDriver = "Primomonnt.dll" [null data]


---------- (launch time: 2008-07-01 18:31:42)
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 8 seconds.
---------- (total run time: 72 seconds)


Czy to możliwe żeby w Pliku który ściągnąłem tzn. ComboFix z linku z tego forum roiło się od wirusów bo moja Avirka ich znalazła całą gromadkę?
Odpowiedz


Wiadomości w tym wątku
Co to może być za wirus i jak go usunąć? - przez fig - 01.07.2008, 17:25

Skocz do:


Użytkownicy przeglądający ten wątek: 1 gości