GOG Galaxy is a gaming platform similar to Steam.
It's closed alpha but you can download here if you need to
'GalaxyCommunication.exe' is being open and closed over and over again, there's at least 10 copies running at a time.. causing 100% cpu usage
resource access log
Code: Select all
(Drive) \Device\CdRom0
(Drive) \Device\HarddiskVolume2
(Drive) \Device\HarddiskVolume3
(Drive) \Device\HarddiskVolume4
Clsid -------------------------------
File/Key -------------------------------
Image -------------------------------
Image *:\program files\sandboxie\start.exe
Image *:\programdata\gog.com\galaxy\redists\galaxycommunication.exe
Image c:\program files\sandboxie\32\sbiedll.dll
Image c:\program files\sandboxie\sbiedll.dll
Image c:\programdata\gog.com\galaxy\redists\expat.dll
Image c:\programdata\gog.com\galaxy\redists\pcre.dll
Image c:\programdata\gog.com\galaxy\redists\pocofoundation.dll
Image c:\programdata\gog.com\galaxy\redists\pocojson.dll
Image c:\programdata\gog.com\galaxy\redists\poconet.dll
Image c:\programdata\gog.com\galaxy\redists\pocoutil.dll
Image c:\programdata\gog.com\galaxy\redists\pocoxml.dll
Image c:\programdata\gog.com\galaxy\redists\zlib.dll
Image c:\windows\system32\advapi32.dll
Image c:\windows\system32\apphelp.dll
Image c:\windows\system32\comdlg32.dll
Image c:\windows\system32\gdi32.dll
Image c:\windows\system32\imm32.dll
Image c:\windows\system32\iphlpapi.dll
Image c:\windows\system32\kernel32.dll
Image c:\windows\system32\kernelbase.dll
Image c:\windows\system32\lpk.dll
Image c:\windows\system32\msctf.dll
Image c:\windows\system32\msvcp110.dll
Image c:\windows\system32\msvcr110.dll
Image c:\windows\system32\msvcrt.dll
Image c:\windows\system32\ntdll.dll
Image c:\windows\system32\ole32.dll
Image c:\windows\system32\rpcrt4.dll
Image c:\windows\system32\sechost.dll
Image c:\windows\system32\shell32.dll
Image c:\windows\system32\shlwapi.dll
Image c:\windows\system32\user32.dll
Image c:\windows\system32\usp10.dll
Image c:\windows\system32\version.dll
Image c:\windows\system32\winnsi.dll
Image c:\windows\system32\wtsapi32.dll
Image c:\windows\syswow64\advapi32.dll
Image c:\windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
Image c:\windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
Image c:\windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
Image c:\windows\syswow64\api-ms-win-downlevel-user32-l1-1-0.dll
Image c:\windows\syswow64\api-ms-win-downlevel-version-l1-1-0.dll
Image c:\windows\syswow64\crypt32.dll
Image c:\windows\syswow64\cryptbase.dll
Image c:\windows\syswow64\gdi32.dll
Image c:\windows\syswow64\iertutil.dll
Image c:\windows\syswow64\kernel32.dll
Image c:\windows\syswow64\kernelbase.dll
Image c:\windows\syswow64\lpk.dll
Image c:\windows\syswow64\msasn1.dll
Image c:\windows\syswow64\msctf.dll
Image c:\windows\syswow64\msvcrt.dll
Image c:\windows\syswow64\normaliz.dll
Image c:\windows\syswow64\nsi.dll
Image c:\windows\syswow64\ntdll.dll
Image c:\windows\syswow64\profapi.dll
Image c:\windows\syswow64\rpcrt4.dll
Image c:\windows\syswow64\sechost.dll
Image c:\windows\syswow64\shell32.dll
Image c:\windows\syswow64\shlwapi.dll
Image c:\windows\syswow64\sspicli.dll
Image c:\windows\syswow64\user32.dll
Image c:\windows\syswow64\userenv.dll
Image c:\windows\syswow64\usp10.dll
Image c:\windows\syswow64\wininet.dll
Image c:\windows\syswow64\wintrust.dll
Image c:\windows\syswow64\ws2_32.dll
Image c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
Ipc -------------------------------
Ipc \RPC Control\epmapper
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00000244
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00000604
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00000690
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000007FC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00000960
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000009CC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00000B68
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00000E94
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001060
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000011FC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000012A0
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001380
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000014B4
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001510
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001590
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000015AC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000015CC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM0000168C
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001A18
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001B38
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001B70
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001B7C
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001C1C
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001CA8
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001D10
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001D2C
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00001EF8
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00002044
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00002234
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000022FC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00002394
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000023EC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00002598
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000025A0
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000025BC
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000025C0
Ipc \Sessions\1\BaseNamedObjects\POCOTRM00002614
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000026C8
Ipc \Sessions\1\BaseNamedObjects\POCOTRM000027EC
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_10220
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_1540
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_1680
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_2044
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_2400
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_2508
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_2920
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_3732
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4192
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4604
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4768
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_4992
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_5392
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_5520
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_5548
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_5580
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_5772
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_580
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_6148
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_6456
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_6680
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_6732
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_6968
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7024
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7028
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7036
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7196
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7316
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7336
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7440
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7468
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_7928
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_8260
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_8424
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_8956
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9108
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9112
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9156
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9196
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9632
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9660
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9664
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9748
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_DummyEvent_9928
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_DcomLaunch
Ipc \Sessions\1\BaseNamedObjects\SBIE_BOXED_ServiceInitComplete_RpcSs
Ipc O \KnownDlls\advapi32.dll
Ipc O \KnownDlls\COMDLG32.dll
Ipc O \KnownDlls\gdi32.dll
Ipc O \KnownDlls\kernel32.dll
Ipc O \KnownDlls\kernelbase.dll
Ipc O \KnownDlls\LPK.dll
Ipc O \KnownDlls\MSCTF.dll
Ipc O \KnownDlls\MSVCRT.dll
Ipc O \KnownDlls\ole32.dll
Ipc O \KnownDlls\rpcrt4.dll
Ipc O \KnownDlls\SHELL32.dll
Ipc O \KnownDlls\SHLWAPI.dll
Ipc O \KnownDlls\user32.dll
Ipc O \KnownDlls\USP10.dll
Ipc O \KnownDlls32\advapi32.dll
Ipc O \KnownDlls32\api-ms-win-downlevel-advapi32-l1-1-0.dll
Ipc O \KnownDlls32\api-ms-win-downlevel-normaliz-l1-1-0.dll
Ipc O \KnownDlls32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
Ipc O \KnownDlls32\api-ms-win-downlevel-user32-l1-1-0.dll
Ipc O \KnownDlls32\api-ms-win-downlevel-version-l1-1-0.dll
Ipc O \KnownDlls32\CRYPT32.dll
Ipc O \KnownDlls32\CRYPTBASE.dll
Ipc O \KnownDlls32\gdi32.dll
Ipc O \KnownDlls32\IERTUTIL.dll
Ipc O \KnownDlls32\kernel32.dll
Ipc O \KnownDlls32\kernelbase.dll
Ipc O \KnownDlls32\LPK.dll
Ipc O \KnownDlls32\MSASN1.dll
Ipc O \KnownDlls32\MSCTF.dll
Ipc O \KnownDlls32\MSVCRT.dll
Ipc O \KnownDlls32\NORMALIZ.dll
Ipc O \KnownDlls32\NSI.dll
Ipc O \KnownDlls32\profapi.dll
Ipc O \KnownDlls32\rpcrt4.dll
Ipc O \KnownDlls32\SHELL32.dll
Ipc O \KnownDlls32\SHLWAPI.dll
Ipc O \KnownDlls32\SspiCli.dll
Ipc O \KnownDlls32\user32.dll
Ipc O \KnownDlls32\USERENV.dll
Ipc O \KnownDlls32\USP10.dll
Ipc O \KnownDlls32\WININET.dll
Ipc O \KnownDlls32\WINTRUST.dll
Ipc O \KnownDlls32\WS2_32.dll
Ipc O \RPC Control\lsasspirpc
Ipc O \RPC Control\SbieSvcPort
Ipc O \Security\LSA_AUTHENTICATION_INITIALIZED
Ipc O \Sessions\1\Windows\SharedSection
Pipe -------------------------------
Pipe \Device\Afd
Pipe \Device\USBPDO-12
Pipe \Device\USBPDO-8
Pipe O \Device\Afd
WinCls -------------------------------
WinCls O Shell_TrayWnd
WinCls X ShockwaveFlashFullScreen
not sure what to do