Voila j ai tout bien fait comme il faut
ComboFix 09-04-01.01 - Hugo 2009-04-03 19:20:35.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2047.1424 [GMT -4:00]
Lancé depuis: c:\documents and settings\Hugo\Bureau\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-03 au 2009-04-03 ))))))))))))))))))))))))))))))))))))
.
2009-04-03 16:34 . 2009-04-03 16:34 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-04-03 16:34 . 2009-04-03 16:34 <REP> d-------- c:\documents and settings\Hugo\Application Data\Malwarebytes
2009-04-03 16:34 . 2009-04-03 16:34 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-03 16:34 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-03 16:34 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-04-02 21:54 . 2009-04-02 21:54 <REP> d-------- C:\rsit
2009-03-29 23:33 . 2009-03-29 23:33 <REP> d-------- c:\program files\CCleaner
2009-03-28 14:30 . 2009-03-28 14:30 <REP> d-------- c:\documents and settings\Hugo\Application Data\MAGIX
2009-03-28 14:29 . 2009-03-28 14:29 <REP> d-------- c:\program files\Fichiers communs\MAGIX Shared
2009-03-28 14:26 . 2009-03-28 14:26 <REP> d-------- c:\program files\Fichiers communs\xara
2009-03-28 14:25 . 2009-03-29 22:03 <REP> d-------- c:\documents and settings\All Users\Application Data\MAGIX
2009-03-28 14:24 . 2009-03-28 14:29 <REP> d-------- c:\windows\system32\MAGIX
2009-03-28 14:24 . 2009-03-29 22:03 <REP> d-------- c:\program files\MAGIX
2009-03-28 14:24 . 2008-04-15 15:14 700,416 --a------ c:\windows\system32\mgxoschk.dll
2009-03-28 14:24 . 2007-04-27 09:43 120,200 --a------ c:\windows\system32\DLLDEV32i.dll
2009-03-28 14:24 . 2009-03-28 14:29 6,211 --a------ c:\windows\mgxoschk.ini
2009-03-27 21:45 . 2009-03-27 21:45 <REP> d--h----- c:\windows\PIF
2009-03-25 16:43 . 2009-03-25 16:43 <REP> d-------- c:\documents and settings\Hugo\Application Data\OpenOffice.org
2009-03-25 16:36 . 2009-03-25 16:36 <REP> d-------- c:\program files\OpenOffice.org 3
2009-03-25 16:36 . 2009-03-25 16:36 <REP> d-------- c:\program files\JRE
2009-03-25 16:35 . 2009-03-25 16:35 <REP> d-------- c:\program files\Fichiers communs\Java
2009-03-25 15:12 . 2009-03-25 15:12 <REP> d-------- c:\program files\Super Fast Shutdown
2009-03-25 15:11 . 2009-03-25 15:11 <REP> d-------- c:\program files\SuperCopier2
2009-03-20 13:28 . 2009-03-20 13:28 53,248 --a------ c:\windows\system32\hpfinsta.exe
2009-03-20 13:28 . 2009-03-20 13:28 800 --a------ c:\windows\hpinfo.lnk
2009-03-20 13:27 . 2009-03-20 13:28 <REP> d-------- c:\program files\hp deskjet 825c series
2009-03-20 13:27 . 2009-03-20 13:27 <REP> d-------- c:\program files\Hewlett-Packard
2009-03-20 13:27 . 2009-03-20 13:27 376 --a------ c:\windows\mozregistry.dat
2009-03-20 13:26 . 2001-12-06 12:06 274,432 --a------ c:\windows\system32\hpfinst.dll
2009-03-20 13:26 . 2009-03-20 13:26 262,144 --a------ c:\windows\system32\hpzcon04.dll
2009-03-20 13:26 . 2009-03-20 13:26 200,704 --a------ c:\windows\system32\hpzcoi04.dll
2009-03-20 13:26 . 2009-03-20 13:26 114,744 --a------ c:\windows\system32\hpzlnt04.dll
2009-03-20 13:15 . 2008-04-13 14:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-03-20 13:15 . 2008-04-13 14:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2009-03-18 17:19 . 2009-03-25 15:15 <REP> d-------- c:\program files\Joustra
2009-03-18 15:14 . 2009-03-18 15:14 <REP> d-------- c:\documents and settings\Hugo\Application Data\AVS4YOU
2009-03-18 15:14 . 2009-03-18 15:14 <REP> d-------- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-03-18 15:13 . 2009-03-18 15:13 <REP> d-------- c:\program files\Fichiers communs\AVSMedia
2009-03-18 15:13 . 2009-03-18 15:13 <REP> d-------- c:\program files\AVS4YOU
2009-03-18 15:13 . 2009-01-28 19:49 24,576 --a------ c:\windows\system32\msxml3a.dll
2009-03-17 19:55 . 2009-03-17 19:55 <REP> d-------- c:\program files\Fichiers communs\xing shared
2009-03-17 19:54 . 2009-03-17 19:54 <REP> d-------- c:\program files\Real
2009-03-17 19:54 . 2009-03-17 19:55 <REP> d-------- c:\program files\Fichiers communs\Real
2009-03-11 15:34 . 2008-04-13 22:33 221,184 --a------ c:\windows\system32\wmpns.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-03 23:24 --------- d-----w c:\documents and settings\Hugo\Application Data\Skype
2009-04-03 23:24 --------- d-----w c:\documents and settings\Hugo\Application Data\nView_Wallpaper
2009-04-03 23:22 704,544 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-03 23:22 5,584 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-03 23:22 5,286,432 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-03 23:22 46,572 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-03 20:31 --------- d-----w c:\program files\Mozilla Thunderbird
2009-04-03 20:30 --------- d-----w c:\documents and settings\Hugo\Application Data\dvdcss
2009-04-03 20:25 --------- d-----w c:\documents and settings\Hugo\Application Data\skypePM
2009-04-03 20:24 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-30 03:39 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-30 03:36 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-30 00:37 --------- d-----w c:\documents and settings\Hugo\Application Data\uTorrent
2009-03-27 02:25 --------- d-----w c:\program files\Lavalys
2009-03-25 20:36 --------- d-----w c:\program files\Java
2009-03-25 20:25 --------- d-----w c:\documents and settings\Hugo\Application Data\gtk-2.0
2009-03-20 20:48 --------- d-----w c:\documents and settings\Hugo\Application Data\LimeWire
2009-03-18 04:12 --------- d-----w c:\program files\uTorrent
2009-03-17 23:48 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-03-17 02:47 --------- d-----w c:\documents and settings\Hugo\Application Data\Apple Computer
2009-03-13 01:58 --------- d-----w c:\program files\Castle Creations
2009-03-04 01:08 --------- d-----w c:\program files\eMule
2009-02-12 20:42 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-03 21:47 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 21:47 101,287 ----a-w c:\windows\system32\drivers\klin.dat
1998-04-26 22:00 570,128 ----a-w c:\program files\Fichiers communs\DAO350.dll
2008-12-08 17:36 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-12-31 17:01 61 --sh--w c:\windows\cnerolf.dat
.
------- Sigcheck -------
2008-04-13 22:34 979968 3efe912dd25d2586e6a0341db0a66f69 c:\windows\explorer.exe
2004-08-19 19:09 1036288 2a7bd330924252a2fd80344fc949bb72 c:\windows\$NtServicePackUninstall$\explorer.exe
2008-04-13 22:34 979968 3efe912dd25d2586e6a0341db0a66f69 c:\windows\ServicePackFiles\i386\explorer.exe
2004-08-19 19:10 112640 fc21787f32e3793a4c7c02d2bfaa5ae0 c:\windows\$NtServicePackUninstall$\wuauclt.exe
2008-10-16 14:09 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\ServicePackFiles\i386\wuauclt.exe
2008-10-16 14:09 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\system32\wuauclt.exe
2008-10-16 14:09 51224 e654b78d2f1d791b30d0ed9a8195ec22 c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2008-12-02 3882312]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"RocketDock"="c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 630784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2007-10-02 233472]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2007-10-02 131072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-03-17 198160]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2009-03-20 196608]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-12 206088]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-01 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-12-07 809488]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 16:41 72208 c:\program files\Fichiers communs\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Privoxy.lnk]
backup=c:\windows\pss\Privoxy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Hugo^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Hugo^Menu Démarrer^Programmes^Démarrage^RocketDock.lnk]
backup=c:\windows\pss\RocketDock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2009-02-27 17:10 35696 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMusicClient]
--a------ 2004-06-22 14:18 86016 c:\program files\Winamp\eMusic\eMusicClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-12-08 13:36 30192 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-12-07 13:56 133104 c:\documents and settings\Hugo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 16:17 159744 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-03 19:02 36352 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MultiProxy\\MProxy.exe"=
"c:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2008-12-07 10384]
R3 chdrvr01;CH Control Manager Driver 1;c:\windows\system32\drivers\chdrvr01.sys [2008-12-31 219072]
R3 chdrvr02;CH Control Manager Driver 2;c:\windows\system32\drivers\chdrvr02.sys [2008-12-31 5120]
R3 chdrvr03;CH Control Manager Driver 3;c:\windows\system32\drivers\chdrvr03.sys [2008-12-31 8704]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-08-28 44032]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2009-03-28 1527900]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-12-08 30192]
S3 SaiH0763;SaiH0763;c:\windows\system32\drivers\SaiH0763.sys [2007-05-01 132232]
S3 SaiH0BAC;SaiH0BAC;c:\windows\system32\drivers\SaiH0BAC.sys [2007-09-14 135168]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c9175afe-0f62-11de-86ca-00301b429ff0}]
\Shell\AutoRun\command - f:\driver\usb\usb_driver.exe
\Shell\open\command - f:\driver\usb\usb_driver.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-776561741-725345543-1003.job
- c:\documents and settings\Hugo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-07 13:56]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-SVHSTs - svhosts.exe
.
------- Examen supplémentaire -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 127.0.0.1:9051
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Hugo\Application Data\Mozilla\Firefox\Profiles\3t69vvty.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.ftp - 123.237.109.145
FF - prefs.js: network.proxy.ftp_port - 1080
FF - prefs.js: network.proxy.gopher - 123.237.109.145
FF - prefs.js: network.proxy.gopher_port - 1080
FF - prefs.js: network.proxy.http - 123.237.109.145
FF - prefs.js: network.proxy.http_port - 1080
FF - prefs.js: network.proxy.socks - 123.237.109.145
FF - prefs.js: network.proxy.socks_port - 1080
FF - prefs.js: network.proxy.ssl - 123.237.109.145
FF - prefs.js: network.proxy.ssl_port - 1080
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\Hugo\Application Data\Mozilla\Firefox\Profiles\3t69vvty.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\Hugo\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-03 19:24:54
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1084)
c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll
c:\program files\fichiers communs\logishrd\bluetooth\LBTServ.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\searchindexer.exe
c:\program files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-04-03 19:28:56 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-03 23:28:52
Avant-CF: 68 667 740 160 octets libres
Après-CF: 68,622,483,456 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
269 --- E O F --- 2009-03-17 03:20:36