2016-Oct-01 17:42:41.023615 [2340] [INF] [3180] [arkdll]
id: 1495, type: PsCreate (16), flags: 1 (wait: 1), cid: 1876/444:\Device\HarddiskVolume3\Windows\explorer.exe
created process: \Device\HarddiskVolume3\Windows\explorer.exe:1876 --> \Device\HarddiskVolume3\Program Files\Sandboxie\SbieCtrl.exe:5328
type: 0, reason: 0, new: 0, dbg: 0, cmd: "C:\Program Files\Sandboxie\SbieCtrl.exe" /open
signer: C=US|ST=Virginia|L=Fairfax|O=Invincea, Inc.|CN=Invincea, Inc., timestamp: 22.09.2016 18:52:47.0000, thumbprint: 21c33f1f25cef09156e5b5d9abf3f8f836703950
hash: 902e0c2041a76e355a5b79bc0fba48281e55ec44 status: db_cert_white_list, signed, pe32 (0x100204) / signed / unknown
id: 1495 ==> undefined [1], time: 43236.028095 ms
2016-Oct-01 17:43:24.294232 [2340] [INF] [3148] [arkdll]
id: 1575, type: PsCreate (16), flags: 1 (wait: 1), cid: 544/3688:\Device\HarddiskVolume3\Windows\System32\services.exe
created process: \Device\HarddiskVolume3\Windows\System32\services.exe:544 --> \Device\HarddiskVolume3\Program Files\Sandboxie\SbieSvc.exe:4468
type: 0, reason: 0, new: 0, dbg: 0, cmd: "C:\Program Files\Sandboxie\SbieSvc.exe"
signer: C=US|ST=Virginia|L=Fairfax|O=Invincea, Inc.|CN=Invincea, Inc., timestamp: 22.09.2016 18:52:48.0000, thumbprint: 21c33f1f25cef09156e5b5d9abf3f8f836703950
hash: 01e694498d2554136a1a7bb19a58c7002e0ae477 status: db_cert_white_list, signed, pe32 (0x100204) / signed / unknown
id: 1575 ==> undefined [1], time: 42464.739559 ms
2016-Oct-01 17:43:24.570248 [2340] [INF] [3148] [arkdll]
id: 1588, type: LoadKernelImage (39), flags: 1 (wait: 1), cid: 4/68:System Process
hips: type: 3, action: allow [2]
loaded driver: \Device\HarddiskVolume3\Program Files\Sandboxie\SbieDrv.sys
id: 1588 ==> allowed [2], time: 0.048873 ms
2016-Oct-01 17:43:24.709256 [2340] [INF] [3156] [arkdll]
id: 1592, type: LoadKernelImage (39), flags: 1 (wait: 1), cid: 4/68:System Process
hips: type: 3, action: allow [2]
loaded driver: \Device\HarddiskVolume3\program files\sandboxie\sbiedrv.sys
id: 1592 ==> allowed [2], time: 0.047826 ms
2016-Oct-01 17:43:24.710256 [2340] [INF] [3156] [arkdll]
id: 1593, type: LoadKernelImage (39), flags: 1 (wait: 1), cid: 4/68:System Process
hips: type: 3, action: allow [2]
loaded driver: \Device\HarddiskVolume3\program files\sandboxie\sbiedrv.sys
id: 1593 ==> allowed [2], time: 0.020946 ms