Module: msrdc.exe, 64-bit Full path: C:\Program Files\WSL\msrdc.exe File version: 1.2.4677.0 Description: Remote Desktop PID: 32168 Parent PID: 7548 (wslhost.exe) Priority: 8 Threads: 16 Owner: AGRYNCO-NB\agrynco (S-1-5-21-4255264900-3681165211-3101920415-1001) Session: 1 Started at: 6:17:26 Uptime: 00:04:01.2748712 Command Line: msrdc.exe /v:38D0ADAA-ACCE-44AB-BC92-20368A4C2A0D /hvsocketserviceid:06CBD3BF-FACB-11E6-BD58-64006A7986D3 /silent /wslg /plugin:WSLDVC_PACKAGE /wslgsharedmemorypath:WSL\38D0ADAA-ACCE-44AB-BC92-20368A4C2A0D\wslg "C:\Program Files\WSL\wslg.rdp" Current Directory: C:\Windows\system32\ Environment: ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\agrynco\AppData\Roaming COMPUTERNAME=AGRYNCO-NB ComSpec=C:\Windows\system32\cmd.exe CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files CommonProgramW6432=C:\Program Files\Common Files DriverData=C:\Windows\System32\Drivers\DriverData HOMEDRIVE=C: HOMEPATH=\Users\agrynco IGCCSVC_DB=AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAOJ66MrrVw0+QBhqk5hoEKwQAAAACAAAAAAAQZgAAAAEAACAAAADnIlH5GScq5R1YwQo2Cdo8Ywd0ZnJUWgTOe7r4V5F63wAAAAAOgAAAAAIAACAAAAAlDR5jYnr48atTqrib8QkVE8gaMuCWSNJWtk+jRzAnqmAAAAALixtyTpkBnS9kEaVJMR5ea2pX1V5u/MVPU0mJfqqQjVqIIvyG3dc/oZ+f7BajWsnfH7FhM0r+7l9Y5zMMoZkm2KAtRIvw/7Ty5HukYLvfOe223gFueFWm34eioL7L3xRAAAAAJzbevzwd+31hEaN3Oa+gjRBOMxyfyX5U0mEeaqvaPv/Ds59UhBmINpbz6//2aDTGdkpe40Lp2WLhU71srp61hw== JetBrains Rider=C:\Program Files\JetBrains\JetBrains Rider 2023.2.3\bin; LOCALAPPDATA=C:\Users\agrynco\AppData\Local LOGONSERVER=\\AGRYNCO-NB NUMBER_OF_PROCESSORS=20 NVM_HOME=C:\Users\agrynco\AppData\Roaming\nvm NVM_SYMLINK=C:\Program Files\nodejs OS=Windows_NT OneDrive=C:\Users\agrynco\OneDrive OneDriveConsumer=C:\Users\agrynco\OneDrive PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC POWERSHELL_DISTRIBUTION_CHANNEL=MSI:Windows 10 Pro PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 154 Stepping 3, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=9a03 PSModulePath=%ProgramFiles%\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules PUBLIC=C:\Users\Public Path=C:\Program Files\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\Git\cmd;C:\Program Files\dotnet\;C:\Program Files\LINQPad7;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\170\Tools\Binn\;C:\Program Files\Microsoft SQL Server\150\Tools\Binn\;C:\Users\agrynco\AppData\Roaming\nvm;C:\Program Files\nodejs;C:\Program Files\WireGuard\;C:\Program Files (x86)\Microsoft SQL Server\160\DTS\Binn\;C:\Program Files\TortoiseGit\bin;C:\Program Files\Docker\Docker\resources\bin;C:\Program Files\PowerShell\7\;C:\Users\agrynco\AppData\Local\Microsoft\WindowsApps;C:\Users\agrynco\AppData\Local\Programs\Microsoft VS Code\bin;C:\Users\agrynco\.dotnet\tools;C:\Program Files\JetBrains\JetBrains Rider 2023.2.3\bin;C:\Program Files\Azure Data Studio\bin ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) ProgramW6432=C:\Program Files SONAR_TOKEN=sqp_4ba776407397ab3d628d0eea2a02bc040832cad0 SystemDrive=C: SystemRoot=C:\Windows TEMP=C:\Users\agrynco\AppData\Local\Temp TMP=C:\Users\agrynco\AppData\Local\Temp USERDOMAIN=AGRYNCO-NB USERDOMAIN_ROAMINGPROFILE=AGRYNCO-NB USERNAME=agrynco USERPROFILE=C:\Users\agrynco ZES_ENABLE_SYSMAN=1 windir=C:\Windows GDI Objects: 88 USER Objects: 81 Processor Time: 00:00:00.0156250 0% Privileged Time: 00:00:00.0156250 0% User Time: 00:00:00.0000000 0% Handle Count: 980 Page File Bytes: 83673088 Page File Bytes Peak: 84180992 Working Set: 58093568 Working Set Peak: 58183680 Pool Nonpaged Bytes: 36784 Pool Paged Bytes: 445296 Private Bytes: 83673088 Page Faults: 15266 0/sec Virtual Bytes: 2203671343104 Virtual Bytes Peak: 2203776454656 IO Data Bytes: 105243180 0/sec IO Read Bytes: 104718892 0/sec IO Write Bytes: 524288 0/sec IO Other Bytes: 203019 0/sec IO Data Operations: 16018 0/sec IO Read Operations: 16017 0/sec IO Write Operations: 1 0/sec IO Other Operations: 1491 0/sec Window title: HWND: 0x50f84 Window style: 84880000 WS_POPUP WS_CLIPSIBLINGS WS_BORDER WS_SYSMENU Extended style: 08000000 WS_EX_NOACTIVATE Modules: Base Size Path (version info is not displayed) 00007FF730F90000 297000 C:\Program Files\WSL\msrdc.exe 00007FF87BE10000 217000 C:\Windows\SYSTEM32\ntdll.dll 00007FF87AD80000 C4000 C:\Windows\System32\KERNEL32.DLL 00007FF879480000 3A5000 C:\Windows\System32\KERNELBASE.dll 00007FF87B8A0000 5E000 C:\Windows\System32\SHLWAPI.dll 00007FF87ACA0000 A7000 C:\Windows\System32\msvcrt.dll 00007FF87BA00000 1AE000 C:\Windows\System32\USER32.dll 00007FF879240000 26000 C:\Windows\System32\win32u.dll 00007FF87AD50000 29000 C:\Windows\System32\GDI32.dll 00007FF879830000 119000 C:\Windows\System32\gdi32full.dll 00007FF879270000 9A000 C:\Windows\System32\msvcp_win.dll 00007FF879950000 111000 C:\Windows\System32\ucrtbase.dll 00007FF87B4F0000 8000 C:\Windows\System32\Normaliz.dll 00007FF8764C0000 2B000 C:\Windows\SYSTEM32\dwmapi.dll 00007FF87A5E0000 389000 C:\Windows\System32\combase.dll 00007FF87AF00000 117000 C:\Windows\System32\RPCRT4.dll 00007FF87BBB0000 31000 C:\Windows\System32\IMM32.DLL 00007FF87A440000 1A0000 C:\Windows\System32\ole32.dll 00007FF87A980000 B1000 C:\Windows\System32\ADVAPI32.dll 00007FF87ABD0000 A6000 C:\Windows\System32\sechost.dll 00007FF878190000 18000 C:\Windows\SYSTEM32\kernel.appcore.dll 00007FF879A70000 7A000 C:\Windows\System32\bcryptPrimitives.dll 00007FF876210000 AB000 C:\Windows\system32\uxtheme.dll 00007FF879BE0000 859000 C:\Windows\System32\SHELL32.dll 00007FF87AAD0000 F3000 C:\Windows\System32\shcore.dll 00007FF87B500000 D7000 C:\Windows\System32\OLEAUT32.dll 00007FFF9D280000 B31000 C:\Program Files\WSL\rdclientax.dll 00007FF87A970000 8000 C:\Windows\System32\PSAPI.DLL 00007FF879AF0000 6C000 C:\Windows\System32\WINTRUST.dll 00007FF86CBB0000 A000 C:\Windows\SYSTEM32\VERSION.dll 00007FF844AE0000 445000 C:\Windows\SYSTEM32\UIAutomationCore.DLL 00007FF878AE0000 2D000 C:\Windows\SYSTEM32\ncrypt.dll 00007FF87B070000 474000 C:\Windows\System32\SETUPAPI.dll 00007FF8288D0000 35F000 C:\Windows\SYSTEM32\msi.dll 00007FF86B2E0000 50000 C:\Windows\SYSTEM32\pdh.dll 00007FF878B10000 28000 C:\Windows\SYSTEM32\BCRYPT.DLL 00007FF878EA0000 4E000 C:\Windows\SYSTEM32\cfgmgr32.DLL 00007FF878AA0000 37000 C:\Windows\SYSTEM32\NTASN1.dll 00007FF879310000 166000 C:\Windows\System32\CRYPT32.dll 00007FF878E20000 12000 C:\Windows\SYSTEM32\MSASN1.dll 00007FF871810000 8B000 C:\Windows\SYSTEM32\Mf.dll 00007FF870F40000 1CE000 C:\Windows\SYSTEM32\Mfplat.dll 00007FF870C00000 33000 C:\Windows\SYSTEM32\RTWorkQ.DLL 00007FF84AC30000 11F000 C:\Windows\SYSTEM32\Mfreadwrite.dll 00007FF871420000 39A000 C:\Windows\SYSTEM32\MFCORE.DLL 00007FF87BC80000 14F000 C:\Windows\System32\MSCTF.dll 00007FF878000000 C000 C:\Windows\SYSTEM32\Secur32.dll 00007FF878490000 42000 C:\Windows\SYSTEM32\SSPICLI.DLL 00007FF834FA0000 C000 C:\Windows\SYSTEM32\credssp.dll 00007FF864340000 293000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2506_none_270c5ae97388e100\COMCTL32.dll 00007FF877060000 8F4000 C:\Windows\SYSTEM32\windows.storage.dll 00007FF876F20000 13E000 C:\Windows\SYSTEM32\wintypes.dll 00007FF87AE50000 B0000 C:\Windows\System32\clbcatq.dll 00007FF874260000 101000 C:\Windows\SYSTEM32\PROPSYS.dll 00007FF876140000 97000 C:\Windows\SYSTEM32\apphelp.dll 00007FF83E0C0000 1A000 C:\Windows\system32\NetworkExplorer.dll 00007FF864220000 69000 C:\Windows\System32\oleacc.dll 00007FF86ABE0000 B0000 C:\Windows\SYSTEM32\TextShaping.dll 00007FF808AA0000 44000 C:\Windows\SYSTEM32\msIso.dll 00007FF8790B0000 26000 C:\Windows\SYSTEM32\profapi.dll 00007FF849EE0000 E000 C:\Windows\SYSTEM32\atlthunk.dll 00007FF83A060000 2A9000 C:\Windows\system32\explorerframe.dll 00007FF86D420000 14A000 C:\Windows\SYSTEM32\textinputframework.dll 00007FF878E40000 2C000 C:\Windows\SYSTEM32\DEVOBJ.dll 00007FFF9C890000 36000 C:\Program Files\WSL\WSLDVCPlugin.dll 00007FFFD4D00000 E0000 C:\Windows\System32\MSAudDecMFT.dll 00007FF8482B0000 12F000 C:\Windows\SYSTEM32\mfperfhelper.dll 00007FF870780000 34000 C:\Windows\system32\winmm.dll 00007FF86A850000 9D000 C:\Windows\System32\MMDevApi.dll 00007FF8756E0000 252000 C:\Windows\SYSTEM32\dcomp.dll 00007FF86A590000 285000 C:\Windows\System32\msxml6.dll 00007FF877C30000 2D000 C:\Windows\SYSTEM32\Iphlpapi.dll 00007FF80C340000 5A000 C:\Windows\SYSTEM32\cryptui.dll 00007FF877FE0000 14000 C:\Windows\SYSTEM32\WTSAPI32.dll 00007FF877BB0000 66000 C:\Windows\SYSTEM32\WINSTA.dll 00007FF874C10000 5EE000 C:\Windows\SYSTEM32\d2d1.dll 00007FF862B80000 1EC000 C:\Windows\SYSTEM32\AUDIOSES.DLL 00007FF85BB30000 174000 C:\Windows\System32\Windows.UI.dll 00007FF879B60000 71000 C:\Windows\System32\WS2_32.dll 00007FF8786A0000 69000 C:\Windows\system32\mswsock.dll 00007FF876650000 7000 C:\Windows\system32\wshhyperv.dll 00007FF85B400000 4F4000 C:\Windows\SYSTEM32\WININET.dll 00007FF863E40000 2BC000 C:\Windows\SYSTEM32\iertutil.dll 00007FF84CFE0000 6C6000 C:\Windows\System32\Windows.Media.dll 00007FFFD5A10000 294000 C:\Windows\System32\msmpeg2vdec.dll 00007FF863D00000 3C000 C:\Windows\SYSTEM32\CompPkgSup.DLL 00007FF862A80000 FC000 C:\Windows\System32\Windows.ApplicationModel.dll 00007FF871230000 135000 C:\Windows\SYSTEM32\AppXDeploymentClient.dll 00007FF862D70000 EB000 C:\Windows\System32\Windows.StateRepositoryPS.dll 00007FF870580000 3D000 C:\Windows\SYSTEM32\windows.staterepositoryclient.dll 00007FF8705C0000 1A000 C:\Windows\SYSTEM32\windows.staterepositorycore.dll 00007FF80B170000 27B000 C:\Windows\System32\Windows.ApplicationModel.Store.dll 00007FF86BB50000 625000 C:\Windows\System32\OneCoreUAPCommonProxyStub.dll 00007FF8734C0000 17000 C:\Windows\SYSTEM32\usermgrcli.dll 00007FFFD5890000 1E000 C:\Windows\SYSTEM32\MSACM32.dll 00007FF85B0F0000 29000 C:\Windows\SYSTEM32\winmmbase.dll 00007FF81D020000 D000 C:\Windows\SYSTEM32\imaadp32.acm 00007FF8148B0000 C000 C:\Windows\SYSTEM32\msadp32.acm 00007FF814770000 A000 C:\Windows\SYSTEM32\msg711.acm 00007FF8145C0000 E000 C:\Windows\SYSTEM32\msgsm32.acm 00007FFFA5120000 1C000 C:\Windows\System32\l3codeca.acm 00007FFFD58B0000 46000 C:\Windows\SYSTEM32\wdmaud.drv 00007FF8718B0000 B000 C:\Windows\SYSTEM32\AVRT.dll 00007FF855560000 9000 C:\Windows\SYSTEM32\ksuser.dll 00007FF83F8C0000 E000 C:\Windows\SYSTEM32\msacm32.drv 00007FFFD6B20000 B000 C:\Windows\SYSTEM32\midimap.dll 00007FF877F90000 4D000 C:\Windows\SYSTEM32\powrprof.dll 00007FF877F70000 13000 C:\Windows\SYSTEM32\UMPDC.dll 00007FF876BF0000 15000 C:\Windows\SYSTEM32\resourcepolicyclient.dll 00007FF8579A0000 28000 C:\Windows\SYSTEM32\edputil.dll