# ncb_8972.dll-ncb_9168.dll Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [Feature_939503929__private_IsEnabledDeviceUsageNoInline](#feature_939503929__private_isenableddeviceusagenoinline)
	* [wil_details_FeatureDescriptors_SkipPadding](#wil_details_featuredescriptors_skippadding)
	* [wil_details_FlushFeatureUsageCache](#wil_details_flushfeatureusagecache)
	* [wil_details_GetKernelBaseProcAddress](#wil_details_getkernelbaseprocaddress)
	* [wil_details_InitializeFeatureStagingUsageReporting](#wil_details_initializefeaturestagingusagereporting)
	* [wil_details_InvalidateFeatureStateCaches](#wil_details_invalidatefeaturestatecaches)
	* [wil_details_RecordFeatureUsage](#wil_details_recordfeatureusage)
	* [wil_details_RecordFeatureUsageCallbackUm](#wil_details_recordfeatureusagecallbackum)
	* [wil_details_RecordFeatureUsageReportingUm](#wil_details_recordfeatureusagereportingum)
	* [wil_details_RtlUnregisterFeatureConfigurationChangeNotification](#wil_details_rtlunregisterfeatureconfigurationchangenotification)
	* [wil_details_SubscribeFeatureStateCacheToConfigurationChanges](#wil_details_subscribefeaturestatecachetoconfigurationchanges)
* [Modified](#modified)
	* [wil_details_RecordCachedUsage](#wil_details_recordcachedusage)
	* [KamDestroyTimer](#kamdestroytimer)
	* [wil::details::EnabledStateManager::RecordCachedUsageUnderLock](#wildetailsenabledstatemanagerrecordcachedusageunderlock)
	* [wil_details_FeatureReporting_ReportUsageToServiceDirect](#wil_details_featurereporting_reportusagetoservicedirect)
	* [wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>](#wildetailsunique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsunregisterwilfeatureconfigurationchangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_unique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsunregisterwilfeatureconfigurationchangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_)
	* [StartNcbService](#startncbservice)
	* [InitiateStopNcbService](#initiatestopncbservice)
	* [InitializeSocketBroker](#initializesocketbroker)
	* [CleanupSocketBroker](#cleanupsocketbroker)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [__GSHandlerCheck](#__gshandlercheck)
	* [API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW](#api-ms-win-core-libraryloader-l1-2-0dllgetmodulehandlew)
	* [WilApi_RecordFeatureUsageReports](#wilapi_recordfeatureusagereports)
	* [?FREE@@YAXPEAX@Z](#freeyaxpeaxz)
	* [McTemplateU0zq_EventWriteTransfer](#mctemplateu0zq_eventwritetransfer)
	* [__security_check_cookie](#__security_check_cookie)
	* [API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress](#api-ms-win-core-libraryloader-l1-2-0dllgetprocaddress)
	* [McGenEventWrite_EventWriteTransfer](#mcgeneventwrite_eventwritetransfer)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection](#api-ms-win-core-synch-l1-1-0dllentercriticalsection)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection](#api-ms-win-core-synch-l1-1-0dllleavecriticalsection)
	* [wil_details_GetNtDllProcedureAddress](#wil_details_getntdllprocedureaddress)

# Visual Chart Diff



```mermaid

flowchart LR

wil_details_RecordCachedUsage-2-old<--Match 98%-->wil_details_RecordCachedUsage-2-new
KamDestroyTimer-3-old<--Match 32%-->KamDestroyTimer-3-new
wildetailsEnabledStateManagerRecordCachedUsageUnderLock-2-old<--Match 98%-->wildetailsEnabledStateManagerRecordCachedUsageUnderLock-2-new
wil_details_FeatureReporting_ReportUsageToServiceDirect-4-old<--Match 75%-->wil_details_FeatureReporting_ReportUsageToServiceDirect-4-new
wildetailsunique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_unique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_-1-old<--Match 56%-->wildetailsunique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_unique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_-1-new
StartNcbService-0-old<--Match 99%-->StartNcbService-0-new
InitiateStopNcbService-3-old<--Match 99%-->InitiateStopNcbService-3-new
InitializeSocketBroker-2-old<--Match 34%-->wil_InitializeFeatureStaging-2-new
CleanupSocketBroker-0-old<--Match 47%-->wil_UninitializeFeatureStaging-0-new

subgraph ncb_9168.dll
    wil_details_RecordCachedUsage-2-new
KamDestroyTimer-3-new
wildetailsEnabledStateManagerRecordCachedUsageUnderLock-2-new
wil_details_FeatureReporting_ReportUsageToServiceDirect-4-new
wildetailsunique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_unique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_-1-new
StartNcbService-0-new
InitiateStopNcbService-3-new
wil_InitializeFeatureStaging-2-new
wil_UninitializeFeatureStaging-0-new
    subgraph Added
direction LR
Feature_939503929__private_IsEnabledDeviceUsageNoInline
    wil_details_FeatureDescriptors_SkipPadding
    wil_details_FlushFeatureUsageCache
    wil_details_GetKernelBaseProcAddress
    wil_details_InitializeFeatureStagingUsageReporting
    wil_details_InvalidateFeatureStateCaches
    wil_details_RecordFeatureUsage
    wil_details_RecordFeatureUsageCallbackUm
    wil_details_RecordFeatureUsageReportingUm
    wil_details_RtlUnregisterFeatureConfigurationChangeNotification
    wil_details_SubscribeFeatureStateCacheToConfigurationChanges
end
end

subgraph ncb_8972.dll
    wil_details_RecordCachedUsage-2-old
KamDestroyTimer-3-old
wildetailsEnabledStateManagerRecordCachedUsageUnderLock-2-old
wil_details_FeatureReporting_ReportUsageToServiceDirect-4-old
wildetailsunique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_unique_storagestruct_wildetailsresource_policyvoid___ptr64void___cdeclvoid___ptr64void___cdecl_wildetailsUnregisterWilFeatureConfigurationChangevoid___ptr64struct_wistdintegral_constantunsigned___int640void___ptr64void___ptr640stdnullptr_t_-1-old
StartNcbService-0-old
InitiateStopNcbService-3-old
InitializeSocketBroker-2-old
CleanupSocketBroker-0-old
    
end

```


```mermaid
pie showData
    title Function Matches - 99.6114%
"unmatched_funcs_len" : 11
"matched_funcs_len" : 2820
```



```mermaid
pie showData
    title Matched Function Similarity - 99.1489%
"matched_funcs_with_code_changes_len" : 9
"matched_funcs_with_non_code_changes_len" : 15
"matched_funcs_no_changes_len" : 2796
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 ncb_8972.dll ncb_9168.dll
```


#### Verbose Args


<details>

```
--old ['ncb_8972.dll'] --new [['ncb_9168.dll']] --engine VersionTrackingDiff --output-path ncb_out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/ncbservice.dll/63BA21CA5C000/ncbservice.dll -O ncbservice.dll.x64.10.0.26100.8972
wget https://msdl.microsoft.com/download/symbols/ncbservice.dll/45F57AD75D000/ncbservice.dll -O ncbservice.dll.x64.10.0.26100.9168
```


## Binary Metadata Diff


```diff
--- ncb_8972.dll Meta
+++ ncb_9168.dll Meta
@@ -1,44 +1,44 @@
-Program Name: ncb_8972.dll
+Program Name: ncb_9168.dll
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 180000000
 Maximum Address: ff0000184f
-# of Bytes: 380504
+# of Bytes: 384688
 # of Memory Blocks: 10
-# of Instructions: 49920
-# of Defined Data: 4375
-# of Functions: 1408
-# of Symbols: 11732
+# of Instructions: 50241
+# of Defined Data: 4396
+# of Functions: 1423
+# of Symbols: 11788
 # of Data Types: 822
 # of Data Type Categories: 54
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Fri Aug 21 23:25:05 SGT 2026
+Date Created: Fri Aug 21 23:25:09 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /tmp/ncb/ncb_8972.dll
-Executable MD5: 8ed90eae1882d01977a65aeb0df21a21
-Executable SHA256: 189536592b6508a1a1ba708894b198c67c5fdd978a2e14c79d8001a7414b03f0
-FSRL: file:///tmp/ncb/ncb_8972.dll?MD5=8ed90eae1882d01977a65aeb0df21a21
+Executable Location: /tmp/ncb/ncb_9168.dll
+Executable MD5: bd1078d1e3a4d2eb5b7838e639e40b7e
+Executable SHA256: 4e56f1b092b0d1393435900793042197269770b4b041eff3b9b00e56e5fb4d19
+FSRL: file:///tmp/ncb/ncb_9168.dll?MD5=bd1078d1e3a4d2eb5b7838e639e40b7e
 PDB Age: 1
 PDB File: ncbservice.pdb
-PDB GUID: 8fdea724-5e63-b793-9a81-07e81ab6cdee
+PDB GUID: 8efe0dcf-8ea0-53ce-3a27-d6a4a9ea532f
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Network Connection Broker
-PE Property[FileVersion]: 10.0.26100.8972 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.9168 (WinBuild.160101.0800)
 PE Property[InternalName]: ncbservice.dll
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: ncbservice.dll
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.8972
+PE Property[ProductVersion]: 10.0.26100.9168
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: true
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra ncb_8972.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra ncb_8972.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra ncb_8972.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra ncb_9168.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra ncb_9168.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra ncb_9168.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|11|
|deleted_funcs_len|0|
|modified_funcs_len|24|
|added_symbols_len|15|
|deleted_symbols_len|1|
|diff_time|4.648714780807495|
|deleted_strings_len|0|
|added_strings_len|4|
|match_types|Counter({'SymbolsHash': 1401, 'ExternalsName': 315, 'ExactInstructionsFunctionHasher': 3, 'SigCallingCalledHasher': 2, 'Implied Match': 2, 'ExactBytesFunctionHasher': 1})|
|items_to_process|51|
|diff_types|Counter({'address': 22, 'refcount': 16, 'calling': 13, 'code': 9, 'length': 9, 'called': 8, 'sig': 5, 'name': 2, 'fullname': 2})|
|unmatched_funcs_len|11|
|total_funcs_len|2831|
|matched_funcs_len|2820|
|matched_funcs_with_code_changes_len|9|
|matched_funcs_with_non_code_changes_len|15|
|matched_funcs_no_changes_len|2796|
|match_func_similarity_percent|99.1489%|
|func_match_overall_percent|99.6114%|
|first_matches|Counter({'SymbolsHash': 1401, 'ExactInstructionsFunctionHasher': 3, 'SigCallingCalledHasher': 2, 'Implied Match': 2, 'ExactBytesFunctionHasher': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 1401
"ExternalsName" : 315
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 3
"SigCallingCalledHasher" : 2
"Implied-Match" : 2
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 1401
"ExactBytesFunctionHasher" : 1
"ExactInstructionsFunctionHasher" : 3
"SigCallingCalledHasher" : 2
"Implied-Match" : 2
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 11
"deleted_funcs_len" : 0
"modified_funcs_len" : 24
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 15
"deleted_symbols_len" : 1
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 0
"added_strings_len" : 4
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -0,0 +1,4 @@
+s_ArmFeatureUsageSubscriberFlushN
+s_RecordFeatureUsage2
+s_SubscribeFeatureUsageFlush
+s_UnsubscribeFeatureUsageFlush

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|s_RecordFeatureUsage2|1|wil_details_RecordFeatureUsage|
|s_UnsubscribeFeatureUsageFlush|1|wil_UninitializeFeatureStaging|
|s_SubscribeFeatureUsageFlush|1|wil_details_InitializeFeatureStagingUsageReporting|
|s_ArmFeatureUsageSubscriberFlushN|1|wil_details_RecordFeatureUsageReportingUm|

# Deleted

# Added

## Feature_939503929__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|Feature_939503929__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_939503929__private_IsEnabledDeviceUsageNoInline|
|refcount|6|
|length|51|
|called|wil_details_IsEnabledFallback|
|calling|KamDestroyTimer|
|paramcount|0|
|address|18001f9a4|
|sig|uint __fastcall Feature_939503929__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_939503929__private_IsEnabledDeviceUsageNoInline
+++ Feature_939503929__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,15 @@
+
+uint Feature_939503929__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  uint uVar1;
+  ulonglong local_res8;
+  
+  local_res8 = (ulonglong)Feature_939503929__private_featureState;
+  if ((Feature_939503929__private_featureState & 0x10) != 0) {
+    return Feature_939503929__private_featureState & 1;
+  }
+  uVar1 = wil_details_IsEnabledFallback(local_res8,3,&Feature_939503929__private_descriptor);
+  return uVar1;
+}
+

```


## wil_details_FeatureDescriptors_SkipPadding

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_FeatureDescriptors_SkipPadding|
|fullname|wil_details_FeatureDescriptors_SkipPadding|
|refcount|4|
|length|31|
|called||
|calling|wil_InitializeFeatureStaging<br>wil_details_FlushFeatureUsageCache<br>wil_details_InvalidateFeatureStateCaches|
|paramcount|1|
|address|1800242f0|
|sig|longlong * __fastcall wil_details_FeatureDescriptors_SkipPadding(longlong * param_1)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureDescriptors_SkipPadding
+++ wil_details_FeatureDescriptors_SkipPadding
@@ -0,0 +1,14 @@
+
+longlong * wil_details_FeatureDescriptors_SkipPadding(longlong *param_1)
+
+{
+  while( true ) {
+    if (&UNK_18004df17 < param_1) {
+      return (longlong *)0x0;
+    }
+    if (*param_1 != 0) break;
+    param_1 = param_1 + 1;
+  }
+  return param_1;
+}
+

```


## wil_details_FlushFeatureUsageCache

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_FlushFeatureUsageCache|
|fullname|wil_details_FlushFeatureUsageCache|
|refcount|4|
|length|80|
|called|wil_details_FeatureDescriptors_SkipPadding<br>wil_details_RecordCachedUsage|
|calling|wil_UninitializeFeatureStaging|
|paramcount|0|
|address|180024320|
|sig|undefined __fastcall wil_details_FlushFeatureUsageCache(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FlushFeatureUsageCache
+++ wil_details_FlushFeatureUsageCache
@@ -0,0 +1,27 @@
+
+void wil_details_FlushFeatureUsageCache(void)
+
+{
+  int iVar1;
+  longlong *plVar2;
+  undefined **ppuVar3;
+  
+  iVar1 = g_wil_details_featureUsageCached;
+  LOCK();
+  g_wil_details_featureUsageCached = 0;
+  UNLOCK();
+  if (iVar1 != 0) {
+    ppuVar3 = &Feature_939503929__private_descriptor;
+    while( true ) {
+      plVar2 = wil_details_FeatureDescriptors_SkipPadding((longlong *)ppuVar3);
+      if (plVar2 == (longlong *)0x0) break;
+      if ((*(uint *)plVar2[1] & 1) != 0) {
+        wil_details_RecordCachedUsage
+                  ((int)plVar2[3],(uint *)plVar2[1],wil_details_RecordFeatureUsageCallbackUm);
+      }
+      ppuVar3 = (undefined **)(plVar2 + 7);
+    }
+  }
+  return;
+}
+

```


## wil_details_GetKernelBaseProcAddress

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_GetKernelBaseProcAddress|
|fullname|wil_details_GetKernelBaseProcAddress|
|refcount|5|
|length|93|
|called|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress|
|calling|wil_UninitializeFeatureStaging<br>wil_details_InitializeFeatureStagingUsageReporting<br>wil_details_RecordFeatureUsage<br>wil_details_RecordFeatureUsageReportingUm|
|paramcount|1|
|address|180024378|
|sig|FARPROC __fastcall wil_details_GetKernelBaseProcAddress(LPCSTR param_1)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_GetKernelBaseProcAddress
+++ wil_details_GetKernelBaseProcAddress
@@ -0,0 +1,19 @@
+
+FARPROC wil_details_GetKernelBaseProcAddress(LPCSTR param_1)
+
+{
+  FARPROC pFVar1;
+  
+  if ((`wil_details_GetKernelBaseProcAddress'::__l2::wil_details_kernelbaseModuleHandle ==
+       (HMODULE)0x0) &&
+     (`wil_details_GetKernelBaseProcAddress'::__l2::wil_details_kernelbaseModuleHandle =
+           GetModuleHandleW(L"kernelbase.dll"),
+     `wil_details_GetKernelBaseProcAddress'::__l2::wil_details_kernelbaseModuleHandle ==
+     (HMODULE)0x0)) {
+    return (FARPROC)0x0;
+  }
+  pFVar1 = GetProcAddress(`wil_details_GetKernelBaseProcAddress'::__l2::
+                          wil_details_kernelbaseModuleHandle,param_1);
+  return pFVar1;
+}
+

```


## wil_details_InitializeFeatureStagingUsageReporting

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_InitializeFeatureStagingUsageReporting|
|fullname|wil_details_InitializeFeatureStagingUsageReporting|
|refcount|2|
|length|111|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_GetKernelBaseProcAddress|
|calling|wil_InitializeFeatureStaging|
|paramcount|0|
|address|1800243dc|
|sig|uint __fastcall wil_details_InitializeFeatureStagingUsageReporting(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_InitializeFeatureStagingUsageReporting
+++ wil_details_InitializeFeatureStagingUsageReporting
@@ -0,0 +1,22 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+uint wil_details_InitializeFeatureStagingUsageReporting(void)
+
+{
+  g_wil_details_recordFeatureUsage = wil_details_RecordFeatureUsageReportingUm;
+  if (g_wil_details_featureUsageSubscription == 0) {
+    if ((g_wil_details_pfnSubscribeFeatureUsageFlush != (FARPROC)0x0) ||
+       (g_wil_details_pfnSubscribeFeatureUsageFlush =
+             wil_details_GetKernelBaseProcAddress("SubscribeFeatureUsageFlush"),
+       g_wil_details_pfnSubscribeFeatureUsageFlush != (FARPROC)0x0)) {
+      (*g_wil_details_pfnSubscribeFeatureUsageFlush)
+                (&g_wil_details_featureUsageSubscription,wil_details_FlushFeatureUsageCache);
+    }
+    return ~-(uint)(g_wil_details_featureUsageSubscription != 0) & 0xc0000001;
+  }
+  g_wil_details_recordFeatureUsage = wil_details_RecordFeatureUsageReportingUm;
+  return 0;
+}
+

```


## wil_details_InvalidateFeatureStateCaches

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_InvalidateFeatureStateCaches|
|fullname|wil_details_InvalidateFeatureStateCaches|
|refcount|3|
|length|68|
|called|wil_details_FeatureDescriptors_SkipPadding|
|calling|wil_details_InvalidateOnFeatureConfigurationChange|
|paramcount|0|
|address|180024454|
|sig|undefined __fastcall wil_details_InvalidateFeatureStateCaches(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_InvalidateFeatureStateCaches
+++ wil_details_InvalidateFeatureStateCaches
@@ -0,0 +1,25 @@
+
+void wil_details_InvalidateFeatureStateCaches(void)
+
+{
+  longlong *plVar1;
+  char cVar2;
+  undefined8 uVar3;
+  
+  plVar1 = wil_details_FeatureDescriptors_SkipPadding
+                     ((longlong *)&Feature_939503929__private_descriptor);
+  uVar3 = 0;
+  for (; plVar1 != (longlong *)0x0; plVar1 = wil_details_FeatureDescriptors_SkipPadding(plVar1 + 7))
+  {
+    cVar2 = (char)uVar3;
+    if (((*(char *)((longlong)plVar1 + 0x1d) == cVar2) &&
+        (*(char *)((longlong)plVar1 + 0x1e) == cVar2)) &&
+       (*(char *)((longlong)plVar1 + 0x1c) == cVar2)) {
+      LOCK();
+      *(uint *)*plVar1 = *(uint *)*plVar1 & 0xffffffc5;
+      UNLOCK();
+    }
+  }
+  return;
+}
+

```


## wil_details_RecordFeatureUsage

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_RecordFeatureUsage|
|fullname|wil_details_RecordFeatureUsage|
|refcount|3|
|length|86|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_GetKernelBaseProcAddress|
|calling|wil_details_RecordFeatureUsageCallbackUm<br>wil_details_RecordFeatureUsageReportingUm|
|paramcount|3|
|address|180024604|
|sig|undefined __fastcall wil_details_RecordFeatureUsage(uint param_1, uint param_2, uint param_3)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_RecordFeatureUsage
+++ wil_details_RecordFeatureUsage
@@ -0,0 +1,17 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+void wil_details_RecordFeatureUsage(uint param_1,uint param_2,uint param_3)
+
+{
+  if ((g_wil_details_pfnRecordFeatureUsage == (FARPROC)0x0) &&
+     (g_wil_details_pfnRecordFeatureUsage =
+           wil_details_GetKernelBaseProcAddress("RecordFeatureUsage2"),
+     g_wil_details_pfnRecordFeatureUsage == (FARPROC)0x0)) {
+    return;
+  }
+  (*g_wil_details_pfnRecordFeatureUsage)((ulonglong)param_1,(ulonglong)param_2,param_3);
+  return;
+}
+

```


## wil_details_RecordFeatureUsageCallbackUm

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_RecordFeatureUsageCallbackUm|
|fullname|wil_details_RecordFeatureUsageCallbackUm|
|refcount|3|
|length|59|
|called|wil_details_RecordFeatureUsage|
|calling||
|paramcount|2|
|address|180024670|
|sig|undefined __fastcall wil_details_RecordFeatureUsageCallbackUm(longlong param_1, longlong param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_RecordFeatureUsageCallbackUm
+++ wil_details_RecordFeatureUsageCallbackUm
@@ -0,0 +1,17 @@
+
+void wil_details_RecordFeatureUsageCallbackUm(longlong param_1,longlong param_2)
+
+{
+  ushort *puVar1;
+  
+  if (param_2 != 0) {
+    puVar1 = (ushort *)(param_1 + 4);
+    do {
+      wil_details_RecordFeatureUsage(*(uint *)(puVar1 + -2),(uint)*puVar1,(uint)puVar1[1]);
+      puVar1 = puVar1 + 4;
+      param_2 = param_2 + -1;
+    } while (param_2 != 0);
+  }
+  return;
+}
+

```


## wil_details_RecordFeatureUsageReportingUm

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_RecordFeatureUsageReportingUm|
|fullname|wil_details_RecordFeatureUsageReportingUm|
|refcount|3|
|length|108|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_GetKernelBaseProcAddress<br>wil_details_RecordFeatureUsage|
|calling||
|paramcount|1|
|address|1800246c0|
|sig|undefined __fastcall wil_details_RecordFeatureUsageReportingUm(uint param_1)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_RecordFeatureUsageReportingUm
+++ wil_details_RecordFeatureUsageReportingUm
@@ -0,0 +1,32 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+void wil_details_RecordFeatureUsageReportingUm(uint param_1)
+
+{
+  int iVar1;
+  int *in_stack_00000028;
+  
+  iVar1 = g_wil_details_featureUsageCached;
+  if (*in_stack_00000028 != 0) {
+    LOCK();
+    g_wil_details_featureUsageCached = 1;
+    UNLOCK();
+    if (iVar1 == 0) {
+      if (g_wil_details_pfnArmFeatureUsageSubscriberFlushNotification == (FARPROC)0x0) {
+        g_wil_details_pfnArmFeatureUsageSubscriberFlushNotification =
+             wil_details_GetKernelBaseProcAddress("ArmFeatureUsageSubscriberFlushNotification");
+        if (g_wil_details_pfnArmFeatureUsageSubscriberFlushNotification == (FARPROC)0x0)
+        goto LAB_18002470e;
+      }
+      (*g_wil_details_pfnArmFeatureUsageSubscriberFlushNotification)();
+    }
+  }
+LAB_18002470e:
+  if (in_stack_00000028[1] != 0) {
+    wil_details_RecordFeatureUsage(param_1,in_stack_00000028[2],in_stack_00000028[1]);
+  }
+  return;
+}
+

```


## wil_details_RtlUnregisterFeatureConfigurationChangeNotification

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_RtlUnregisterFeatureConfigurationChangeNotification|
|fullname|wil_details_RtlUnregisterFeatureConfigurationChangeNotification|
|refcount|3|
|length|59|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_GetNtDllProcedureAddress|
|calling|wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_><br>wil_UninitializeFeatureStaging|
|paramcount|1|
|address|1800247a0|
|sig|undefined __fastcall wil_details_RtlUnregisterFeatureConfigurationChangeNotification(undefined8 param_1)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_RtlUnregisterFeatureConfigurationChangeNotification
+++ wil_details_RtlUnregisterFeatureConfigurationChangeNotification
@@ -0,0 +1,18 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+void wil_details_RtlUnregisterFeatureConfigurationChangeNotification(undefined8 param_1)
+
+{
+  if ((g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification == (code *)0x0) &&
+     (g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification =
+           (code *)wil_details_GetNtDllProcedureAddress
+                             ("RtlUnregisterFeatureConfigurationChangeNotification"),
+     g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification == (code *)0x0)) {
+    return;
+  }
+  (*g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification)(param_1);
+  return;
+}
+

```


## wil_details_SubscribeFeatureStateCacheToConfigurationChanges

### Function Meta



|Key|ncb_9168.dll|
| :---: | :---: |
|name|wil_details_SubscribeFeatureStateCacheToConfigurationChanges|
|fullname|wil_details_SubscribeFeatureStateCacheToConfigurationChanges|
|refcount|2|
|length|21|
|called||
|calling||
|paramcount|3|
|address|1800247f0|
|sig|undefined __fastcall wil_details_SubscribeFeatureStateCacheToConfigurationChanges(uint * param_1, int param_2, int param_3)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_SubscribeFeatureStateCacheToConfigurationChanges
+++ wil_details_SubscribeFeatureStateCacheToConfigurationChanges
@@ -0,0 +1,13 @@
+
+void wil_details_SubscribeFeatureStateCacheToConfigurationChanges
+               (uint *param_1,int param_2,int param_3)
+
+{
+  if ((param_2 == 0) && (param_3 != g_wil_details_featureStateInvalidationEpoch)) {
+    LOCK();
+    *param_1 = *param_1 & 0xffffffc5;
+    UNLOCK();
+  }
+  return;
+}
+

```


# Modified


*Modified functions contain code changes*
## wil_details_RecordCachedUsage

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,refcount,length,sig,address,calling,called|
|ratio|0.95|
|i_ratio|0.74|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_RecordCachedUsage|wil_details_RecordCachedUsage|
|fullname|wil_details_RecordCachedUsage|wil_details_RecordCachedUsage|
|`refcount`|2|3|
|`length`|322|327|
|`called`|__security_check_cookie<br>wil::details::WilApi_RecordFeatureUsageReports|__security_check_cookie<br>_guard_dispatch_icall$thunk$10345483385596137414|
|`calling`|wil::details::EnabledStateManager::RecordCachedUsageUnderLock|wil::details::EnabledStateManager::RecordCachedUsageUnderLock<br>wil_details_FlushFeatureUsageCache|
|paramcount|2|3|
|`address`|180034f74|1800244b4|
|`sig`|undefined __fastcall wil_details_RecordCachedUsage(undefined4 param_1, uint * param_2)|undefined __fastcall wil_details_RecordCachedUsage(undefined4 param_1, uint * param_2, undefined * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_RecordCachedUsage Called Diff


```diff
--- wil_details_RecordCachedUsage called
+++ wil_details_RecordCachedUsage called
@@ -2 +2 @@
-wil::details::WilApi_RecordFeatureUsageReports
+_guard_dispatch_icall$thunk$10345483385596137414
```


### wil_details_RecordCachedUsage Calling Diff


```diff
--- wil_details_RecordCachedUsage calling
+++ wil_details_RecordCachedUsage calling
@@ -1,0 +2 @@
+wil_details_FlushFeatureUsageCache
```


### wil_details_RecordCachedUsage Diff


```diff
--- wil_details_RecordCachedUsage
+++ wil_details_RecordCachedUsage
@@ -1,90 +1,92 @@
 
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
-void wil_details_RecordCachedUsage(undefined4 param_1,uint *param_2)
+void wil_details_RecordCachedUsage(undefined4 param_1,uint *param_2,undefined *param_3)
 
 {
   uint uVar1;
   uint uVar2;
   uint uVar3;
   uint uVar4;
   undefined4 *puVar5;
-  __uint64 _Var6;
+  longlong lVar6;
   bool bVar7;
   undefined1 auStack_68 [40];
   undefined4 local_40;
   short local_3c [2];
   undefined4 local_38 [10];
   ulonglong local_10;
   
   local_10 = __security_cookie ^ (ulonglong)auStack_68;
   uVar2 = *param_2;
   do {
     LOCK();
     uVar4 = *param_2;
     bVar7 = uVar2 == uVar4;
     if (bVar7) {
       *param_2 = uVar2 & 0xffc0401e;
       uVar4 = uVar2;
     }
     uVar2 = uVar4;
     UNLOCK();
   } while (!bVar7);
   uVar3 = uVar2 >> 1 & 0xf;
   uVar4 = 0;
   if (uVar3 != 0) {
     uVar4 = param_2[1];
     do {
       LOCK();
       uVar1 = param_2[1];
       bVar7 = uVar4 == uVar1;
       if (bVar7) {
         param_2[1] = uVar4 | uVar3;
         uVar1 = uVar4;
       }
       uVar4 = uVar1;
       UNLOCK();
     } while (!bVar7);
     uVar4 = uVar3 & ~uVar4;
   }
   puVar5 = &local_40;
   if ((uVar4 & 1) != 0) {
     puVar5 = local_38;
     local_3c[0] = 2;
     local_3c[1] = 1;
     local_40 = param_1;
   }
   if ((uVar4 & 2) != 0) {
     *puVar5 = param_1;
     puVar5[1] = 0x10006;
     puVar5 = puVar5 + 2;
   }
   if ((uVar4 & 4) != 0) {
     *puVar5 = param_1;
     puVar5[1] = 0x10003;
     puVar5 = puVar5 + 2;
   }
   if (7 < uVar4) {
     *puVar5 = param_1;
     puVar5[1] = 0x10007;
     puVar5 = puVar5 + 2;
   }
   if ((uVar2 >> 5 & 0x1ff) != 0) {
     *puVar5 = param_1;
     *(ushort *)((longlong)puVar5 + 6) = (ushort)(uVar2 >> 5) & 0x1ff;
     *(ushort *)(puVar5 + 1) = ((ushort)(uVar2 >> 0xe) & 1) << 2;
     puVar5 = puVar5 + 2;
   }
   if ((uVar2 >> 0xf & 0x7f) != 0) {
     *puVar5 = param_1;
     *(ushort *)((longlong)puVar5 + 6) = (ushort)(uVar2 >> 0xf) & 0x7f;
     *(ushort *)(puVar5 + 1) = ((ushort)(uVar2 >> 0x16) & 1) * 4 + 1;
     puVar5 = puVar5 + 2;
   }
-  _Var6 = (longlong)puVar5 - (longlong)&local_40 >> 3;
-  if (0 < (longlong)_Var6) {
-    wil::details::WilApi_RecordFeatureUsageReports((__WIL_RTL_FEATURE_USAGE_DATA *)&local_40,_Var6);
+  lVar6 = (longlong)puVar5 - (longlong)&local_40 >> 3;
+  if (0 < lVar6) {
+    (*(code *)param_3)(&local_40,lVar6);
   }
   return;
 }
 

```


## KamDestroyTimer

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,length,sig,called|
|ratio|0.35|
|i_ratio|0.12|
|m_ratio|0.96|
|b_ratio|0.32|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|KamDestroyTimer|KamDestroyTimer|
|fullname|KamDestroyTimer|KamDestroyTimer|
|refcount|3|3|
|`length`|780|734|
|`called`|?FREE@@YAXPEAX@Z<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::SetThreadToken<br>McGenEventWrite_EventWriteTransfer<br>McTemplateU0zq_EventWriteTransfer<br>TIMEBROKERCLIENT.DLL::TbDeleteEvent<br>WPP_SF_<br>WPP_SF_D<br>__security_check_cookie|?FREE@@YAXPEAX@Z<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::SetThreadToken<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>Feature_939503929__private_IsEnabledDeviceUsageNoInline<br>McTemplateU0zq_EventWriteTransfer<br>TIMEBROKERCLIENT.DLL::TbDeleteEvent<br>WPP_SF_<br>WPP_SF_D|
|calling|CleanupContextHelper<br>RpcSrvStartBrokeredActivation|CleanupContextHelper<br>RpcSrvStartBrokeredActivation|
|paramcount|3|1|
|address|180009050|180009050|
|`sig`|undefined8 __fastcall KamDestroyTimer(longlong param_1, undefined8 param_2, undefined * param_3)|undefined8 __fastcall KamDestroyTimer(longlong param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### KamDestroyTimer Called Diff


```diff
--- KamDestroyTimer called
+++ KamDestroyTimer called
@@ -4 +4,3 @@
-McGenEventWrite_EventWriteTransfer
+API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection
+API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection
+Feature_939503929__private_IsEnabledDeviceUsageNoInline
@@ -9 +10,0 @@
-__security_check_cookie
```


### KamDestroyTimer Diff


```diff
--- KamDestroyTimer
+++ KamDestroyTimer
@@ -1,117 +1,146 @@
 
-/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
-
-undefined8 KamDestroyTimer(longlong param_1,undefined8 param_2,undefined *param_3)
+undefined8 KamDestroyTimer(longlong param_1)
 
 {
-  BOOL BVar1;
-  int iVar2;
-  DWORD DVar3;
-  longlong lVar4;
-  undefined8 uVar5;
-  undefined2 uVar6;
+  void *pvVar1;
+  uint uVar2;
+  BOOL BVar3;
+  int iVar4;
+  DWORD DVar5;
+  undefined8 uVar6;
+  undefined *puVar7;
+  undefined2 uVar8;
   HANDLE Token;
-  undefined8 uVar7;
-  undefined1 auStackY_a8 [32];
-  int local_78 [4];
-  undefined4 local_68;
-  undefined4 uStack_64;
-  undefined4 uStack_60;
-  undefined4 uStack_5c;
-  _EVENT_DATA_DESCRIPTOR local_58;
-  wchar_t *local_48;
-  int local_40;
-  undefined4 local_3c;
-  int *local_38;
-  undefined8 local_30;
-  ulonglong local_28;
+  undefined4 *puVar9;
+  undefined8 uVar10;
+  void *pvVar11;
+  undefined4 uVar12;
+  undefined4 uVar13;
+  undefined4 uVar14;
+  undefined4 uVar15;
+  undefined4 local_28;
+  undefined4 uStack_24;
+  undefined4 uStack_20;
+  undefined4 uStack_1c;
   
-  local_28 = __security_cookie ^ (ulonglong)auStackY_a8;
   if ((((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
       ((WPP_GLOBAL_Control[0x1c] & 1) != 0)) && (5 < (byte)WPP_GLOBAL_Control[0x19])) {
-    param_3 = &WPP_9a5d6e18e6df3235d52b8c1fc51e833d_Traceguids;
     WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),0x50,
-            &WPP_9a5d6e18e6df3235d52b8c1fc51e833d_Traceguids);
+            &WPP_3c3188f38ab9317f7aeb66f5b9a0da01_Traceguids);
+  }
+  uVar12 = 0;
+  uVar13 = 0;
+  uVar14 = 0;
+  uVar15 = 0;
+  uVar2 = Feature_939503929__private_IsEnabledDeviceUsageNoInline();
+  pvVar11 = (void *)0x0;
+  if (uVar2 != 0) {
+    EnterCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x18));
+    pvVar1 = *(void **)(param_1 + 0x180);
+    if (pvVar1 != (void *)0x0) {
+      *(undefined8 *)(param_1 + 0x180) = 0;
+      pvVar11 = pvVar1;
+    }
   }
   if (*(char *)(param_1 + 0x169) == '\0') {
+    uVar2 = Feature_939503929__private_IsEnabledDeviceUsageNoInline();
+    if (uVar2 != 0) {
+      LeaveCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x18));
+    }
     if ((((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
         ((WPP_GLOBAL_Control[0x1c] & 1) != 0)) && (4 < (byte)WPP_GLOBAL_Control[0x19])) {
       WPP_SF_(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),0x54,
-              &WPP_9a5d6e18e6df3235d52b8c1fc51e833d_Traceguids);
+              &WPP_3c3188f38ab9317f7aeb66f5b9a0da01_Traceguids);
     }
     goto LAB_0;
   }
+  uVar2 = Feature_939503929__private_IsEnabledDeviceUsageNoInline();
+  if (uVar2 != 0) {
+    uVar12 = *(undefined4 *)(param_1 + 0x134);
+    uVar13 = *(undefined4 *)(param_1 + 0x138);
+    uVar14 = *(undefined4 *)(param_1 + 0x13c);
+    uVar15 = *(undefined4 *)(param_1 + 0x140);
+    *(undefined1 *)(param_1 + 0x169) = 0;
+    LeaveCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x18));
+  }
   Token = *(HANDLE *)(param_1 + 0xe0);
-  uVar5 = 0;
-  BVar1 = SetThreadToken((PHANDLE)0x0,Token);
-  if (BVar1 == 0) {
-    DVar3 = GetLastError();
+  uVar6 = 0;
+  BVar3 = SetThreadToken((PHANDLE)0x0,Token);
+  if (BVar3 == 0) {
+    DVar5 = GetLastError();
     if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
       McTemplateU0zq_EventWriteTransfer
-                (uVar5,Token,L"Kam:KamDestroyTimer failed to impersonate",DVar3);
+                (uVar6,Token,L"Kam:KamDestroyTimer failed to impersonate",DVar5);
     }
     if ((((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
         ((WPP_GLOBAL_Control[0x1c] & 1) != 0)) && (1 < (byte)WPP_GLOBAL_Control[0x19])) {
-      uVar6 = 0x53;
+      uVar8 = 0x53;
 LAB_1:
-      WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),uVar6,
-               &WPP_9a5d6e18e6df3235d52b8c1fc51e833d_Traceguids,DVar3);
+      WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),uVar8,
+               &WPP_3c3188f38ab9317f7aeb66f5b9a0da01_Traceguids,DVar5);
     }
   }
   else {
-    local_68 = *(undefined4 *)(param_1 + 0x134);
-    uStack_64 = *(undefined4 *)(param_1 + 0x138);
-    uStack_60 = *(undefined4 *)(param_1 + 0x13c);
-    uStack_5c = *(undefined4 *)(param_1 + 0x140);
-    iVar2 = TbDeleteEvent();
-    if ((((iVar2 != 0) && ((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control)) &&
+    uVar2 = Feature_939503929__private_IsEnabledDeviceUsageNoInline();
+    puVar7 = *(undefined **)(param_1 + 0xf0);
+    puVar9 = &local_28;
+    local_28 = uVar12;
+    uStack_24 = uVar13;
+    uStack_20 = uVar14;
+    uStack_1c = uVar15;
+    if (uVar2 == 0) {
+      local_28 = *(undefined4 *)(param_1 + 0x134);
+      uStack_24 = *(undefined4 *)(param_1 + 0x138);
+      uStack_20 = *(undefined4 *)(param_1 + 0x13c);
+      uStack_1c = *(undefined4 *)(param_1 + 0x140);
+    }
+    iVar4 = TbDeleteEvent();
+    if ((((iVar4 != 0) &&
+         (puVar7 = WPP_GLOBAL_Control, (undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control)) &&
         ((WPP_GLOBAL_Control[0x1c] & 1) != 0)) && (2 < (byte)WPP_GLOBAL_Control[0x19])) {
-      param_3 = &WPP_9a5d6e18e6df3235d52b8c1fc51e833d_Traceguids;
-      WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),0x51,
-               &WPP_9a5d6e18e6df3235d52b8c1fc51e833d_Traceguids,iVar2);
+      puVar7 = *(undefined **)(WPP_GLOBAL_Control + 0x10);
+      puVar9 = (undefined4 *)0x51;
+      WPP_SF_D(puVar7,0x51,&WPP_3c3188f38ab9317f7aeb66f5b9a0da01_Traceguids,iVar4);
     }
     if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
-      lVar4 = -1;
-      do {
-        lVar4 = lVar4 + 1;
-      } while (L"Kam: TbDeleteEvent returned:"[lVar4] != L'\0');
-      local_40 = (int)lVar4 * 2 + 2;
-      local_48 = L"Kam: TbDeleteEvent returned:";
-      local_38 = local_78;
-      local_3c = 0;
-      local_30 = 4;
-      local_78[0] = iVar2;
-      McGenEventWrite_EventWriteTransfer
-                (L"Kam: TbDeleteEvent returned:",(PCEVENT_DESCRIPTOR)&NcbApiStatus,param_3,3,
-                 &local_58);
+      McTemplateU0zq_EventWriteTransfer(puVar7,puVar9,L"Kam: TbDeleteEvent returned:",iVar4);
     }
-    uVar7 = 0;
-    uVar5 = 0;
-    BVar1 = SetThreadToken((PHANDLE)0x0,(HANDLE)0x0);
-    if (BVar1 == 0) {
-      DVar3 = GetLastError();
+    uVar10 = 0;
+    uVar6 = 0;
+    BVar3 = SetThreadToken((PHANDLE)0x0,(HANDLE)0x0);
+    if (BVar3 == 0) {
+      DVar5 = GetLastError();
       if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
-        McTemplateU0zq_EventWriteTransfer(uVar5,uVar7,L"Kam:KamDestroyTimer failed to revert",DVar3)
-        ;
+        McTemplateU0zq_EventWriteTransfer
+                  (uVar6,uVar10,L"Kam:KamDestroyTimer failed to revert",DVar5);
       }
       if ((((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
           ((WPP_GLOBAL_Control[0x1c] & 1) != 0)) && (1 < (byte)WPP_GLOBAL_Control[0x19])) {
-        uVar6 = 0x52;
+        uVar8 = 0x52;
         goto LAB_1;
       }
     }
   }
-  *(undefined1 *)(param_1 + 0x169) = 0;
+  uVar2 = Feature_939503929__private_IsEnabledDeviceUsageNoInline();
+  if (uVar2 == 0) {
+    *(undefined1 *)(param_1 + 0x169) = 0;
+  }
 LAB_0:
-  if (*(void **)(param_1 + 0x180) != (void *)0x0) {
-    _FREE__YAXPEAX_Z(*(void **)(param_1 + 0x180));
-    *(undefined8 *)(param_1 + 0x180) = 0;
+  uVar2 = Feature_939503929__private_IsEnabledDeviceUsageNoInline();
+  if (uVar2 == 0) {
+    if (*(void **)(param_1 + 0x180) != (void *)0x0) {
+      _FREE__YAXPEAX_Z(*(void **)(param_1 + 0x180));
+      *(undefined8 *)(param_1 + 0x180) = 0;
+    }
+  }
+  else if (pvVar11 != (void *)0x0) {
+    _FREE__YAXPEAX_Z(pvVar11);
   }
   if ((((undefined **)WPP_GLOBAL_Control != &WPP_GLOBAL_Control) &&
       ((WPP_GLOBAL_Control[0x1c] & 1) != 0)) && (5 < (byte)WPP_GLOBAL_Control[0x19])) {
     WPP_SF_D(*(undefined8 *)(WPP_GLOBAL_Control + 0x10),0x55,
-             &WPP_9a5d6e18e6df3235d52b8c1fc51e833d_Traceguids,0);
+             &WPP_3c3188f38ab9317f7aeb66f5b9a0da01_Traceguids,0);
   }
   return 0;
 }
 

```


## wil::details::EnabledStateManager::RecordCachedUsageUnderLock

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.91|
|i_ratio|0.81|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|RecordCachedUsageUnderLock|RecordCachedUsageUnderLock|
|fullname|wil::details::EnabledStateManager::RecordCachedUsageUnderLock|wil::details::EnabledStateManager::RecordCachedUsageUnderLock|
|refcount|3|3|
|`length`|99|106|
|called|wil::details::WilApi_RecordFeatureUsage<br>wil_details_RecordCachedUsage|wil::details::WilApi_RecordFeatureUsage<br>wil_details_RecordCachedUsage|
|calling|wil::details::EnabledStateManager::OnTimer<br>wil::details::EnabledStateManager::ProcessShutdown|wil::details::EnabledStateManager::OnTimer<br>wil::details::EnabledStateManager::ProcessShutdown|
|paramcount|2|2|
|`address`|1800329b4|180033064|
|sig|void __thiscall RecordCachedUsageUnderLock(EnabledStateManager * this, unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_> * param_1)|void __thiscall RecordCachedUsageUnderLock(EnabledStateManager * this, unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_> * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::EnabledStateManager::RecordCachedUsageUnderLock Diff


```diff
--- wil::details::EnabledStateManager::RecordCachedUsageUnderLock
+++ wil::details::EnabledStateManager::RecordCachedUsageUnderLock
@@ -1,31 +1,32 @@
 
 /* private: void __cdecl wil::details::EnabledStateManager::RecordCachedUsageUnderLock(class
    wil::unique_any_t<class wil::details::unique_storage<struct wil::details::resource_policy<struct
    _RTL_SRWLOCK * __ptr64,void (__cdecl*)(struct _RTL_SRWLOCK * __ptr64),&void __cdecl
    ReleaseSRWLockExclusive(struct _RTL_SRWLOCK * __ptr64),struct wistd::integral_constant<unsigned
    __int64,1>,struct _RTL_SRWLOCK * __ptr64,struct _RTL_SRWLOCK * __ptr64,0,std::nullptr_t> > >
    const & __ptr64) __ptr64 */
 
 void __thiscall
 wil::details::EnabledStateManager::RecordCachedUsageUnderLock
           (EnabledStateManager *this,
           unique_any_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>_>
           *param_1)
 
 {
   undefined4 *puVar1;
   undefined4 *puVar2;
   char *in_R9;
   
   puVar1 = *(undefined4 **)(this + 0x28);
   puVar2 = *(undefined4 **)(this + 0x20);
   if (0xf < (ulonglong)((longlong)puVar1 - (longlong)puVar2)) {
     for (; puVar2 != puVar1; puVar2 = puVar2 + 4) {
-      wil_details_RecordCachedUsage(*puVar2,*(uint **)(puVar2 + 2));
+      wil_details_RecordCachedUsage(*puVar2,*(uint **)(puVar2 + 2),WilApi_RecordFeatureUsageReports)
+      ;
     }
     *(undefined8 *)(this + 0x28) = *(undefined8 *)(this + 0x20);
     WilApi_RecordFeatureUsage(0,0xfe,0,in_R9);
   }
   return;
 }
 

```


## wil_details_FeatureReporting_ReportUsageToServiceDirect

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.44|
|i_ratio|0.44|
|m_ratio|0.81|
|b_ratio|0.75|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToServiceDirect|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|fullname|wil_details_FeatureReporting_ReportUsageToServiceDirect|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|refcount|2|2|
|`length`|134|197|
|`called`|__security_check_cookie<br>wil_RtlStagingConfig_RecordFeatureUsage<br>wil_details_FeatureReporting_RecordUsageInCache|__security_check_cookie<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil_RtlStagingConfig_RecordFeatureUsage<br>wil_details_FeatureReporting_RecordUsageInCache|
|calling|wil_details_FeatureReporting_ReportUsageToService|wil_details_FeatureReporting_ReportUsageToService|
|paramcount|4|4|
|`address`|180021e88|180021034|
|sig|bool __fastcall wil_details_FeatureReporting_ReportUsageToServiceDirect(longlong param_1, undefined8 param_2, uint param_3, uint param_4)|bool __fastcall wil_details_FeatureReporting_ReportUsageToServiceDirect(longlong param_1, undefined8 param_2, uint param_3, uint param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_FeatureReporting_ReportUsageToServiceDirect Called Diff


```diff
--- wil_details_FeatureReporting_ReportUsageToServiceDirect called
+++ wil_details_FeatureReporting_ReportUsageToServiceDirect called
@@ -1,0 +2 @@
+_guard_dispatch_icall$thunk$10345483385596137414
```


### wil_details_FeatureReporting_ReportUsageToServiceDirect Diff


```diff
--- wil_details_FeatureReporting_ReportUsageToServiceDirect
+++ wil_details_FeatureReporting_ReportUsageToServiceDirect
@@ -1,25 +1,39 @@
 
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 bool wil_details_FeatureReporting_ReportUsageToServiceDirect
                (longlong param_1,undefined8 param_2,uint param_3,uint param_4)
 
 {
   uint *puVar1;
-  undefined1 auStackY_88 [32];
-  uint local_58 [10];
-  undefined8 local_30;
-  ulonglong local_28;
+  undefined1 auStackY_a8 [32];
+  uint local_78 [6];
+  uint local_60;
+  uint uStack_5c;
+  uint uStack_58;
+  uint uStack_54;
+  undefined8 local_50;
+  ulonglong local_48;
   
-  local_28 = __security_cookie ^ (ulonglong)auStackY_88;
+  local_48 = __security_cookie ^ (ulonglong)auStackY_a8;
   puVar1 = wil_details_FeatureReporting_RecordUsageInCache
-                     (local_58,*(uint **)(param_1 + 8),param_3,(uint)((ulonglong)param_2 >> 0x20),
+                     (local_78,*(uint **)(param_1 + 8),param_3,(uint)((ulonglong)param_2 >> 0x20),
                       param_4);
-  local_30 = *(undefined8 *)(puVar1 + 4);
+  local_60 = *puVar1;
+  uStack_5c = puVar1[1];
+  uStack_58 = puVar1[2];
+  uStack_54 = puVar1[3];
+  local_50 = *(undefined8 *)(puVar1 + 4);
+  if (g_wil_details_recordFeatureUsage != (code *)0x0) {
+    (*g_wil_details_recordFeatureUsage)
+              (*(undefined4 *)(param_1 + 0x18),param_3,param_4,*(undefined8 *)(param_1 + 8));
+  }
   if ((((uint)param_2 >> 10 & 1) != 0) && (param_3 != 0xfe)) {
     wil_RtlStagingConfig_RecordFeatureUsage
               (*(undefined4 *)(param_1 + 0x18),(short)param_3,(uint)param_2 >> 0xb & 1);
   }
-  return (int)local_30 == 0;
+  return (int)local_50 == 0;
 }
 

```


## wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.38|
|i_ratio|0.08|
|m_ratio|0.56|
|b_ratio|0.56|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>|~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>|
|fullname|wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>|wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>|
|refcount|2|2|
|`length`|64|22|
|`called`|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_GetNtDllProcedureAddress|wil_details_RtlUnregisterFeatureConfigurationChangeNotification|
|calling|wil::details::FeatureStateManager::~FeatureStateManager|wil::details::FeatureStateManager::~FeatureStateManager|
|paramcount|1|1|
|`address`|180030224|1800308f4|
|sig|void __thiscall ~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>(unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> * this)|void __thiscall ~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>(unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> Called Diff


```diff
--- wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> called
+++ wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> called
@@ -1,2 +1 @@
-_guard_dispatch_icall$thunk$10345483385596137414
-wil_details_GetNtDllProcedureAddress
+wil_details_RtlUnregisterFeatureConfigurationChangeNotification
```


### wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> Diff


```diff
--- wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>
+++ wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>
@@ -1,39 +1,25 @@
 
-/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
-   guard_dispatch_icall */
 /* public: __cdecl wil::details::unique_storage<struct wil::details::resource_policy<void *
    __ptr64,void (__cdecl*)(void * __ptr64),&void __cdecl
    wil::details::UnregisterWilFeatureConfigurationChange(void * __ptr64),struct
    wistd::integral_constant<unsigned __int64,0>,void * __ptr64,void * __ptr64,0,std::nullptr_t>
    >::~unique_storage<struct wil::details::resource_policy<void * __ptr64,void (__cdecl*)(void *
    __ptr64),&void __cdecl wil::details::UnregisterWilFeatureConfigurationChange(void *
    __ptr64),struct wistd::integral_constant<unsigned __int64,0>,void * __ptr64,void *
    __ptr64,0,std::nullptr_t> >(void) __ptr64 */
 
 void __thiscall
 wil::details::
 unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>
 ::
 ~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>
           (unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>
            *this)
 
 {
-  longlong lVar1;
-  
-  lVar1 = *(longlong *)this;
-  if (lVar1 != 0) {
-    if ((g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification ==
-         (_func___int64 *)0x0) &&
-       (g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification =
-             wil_details_GetNtDllProcedureAddress
-                       ("RtlUnregisterFeatureConfigurationChangeNotification"),
-       g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification == (_func___int64 *)0x0)
-       ) {
-      return;
-    }
-    (*g_wil_details_pfnRtlUnregisterFeatureConfigurationChangeNotification)(lVar1);
+  if (*(longlong *)this != 0) {
+    wil_details_RtlUnregisterFeatureConfigurationChangeNotification(*(longlong *)this);
   }
   return;
 }
 

```


## StartNcbService

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.8|
|i_ratio|0.43|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|StartNcbService|StartNcbService|
|fullname|StartNcbService|StartNcbService|
|refcount|2|2|
|`length`|717|727|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateEventW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::SetEvent<br>API-MS-WIN-CORE-THREADPOOL-LEGACY-L1-1-0.DLL::UnregisterWaitEx<br>CleanupSocketBroker<br>EXT-MS-WIN-NETWORKING-RADIOMONITOR-L1-1-0.DLL::RadioDeviceStart<br>EXT-MS-WIN-NETWORKING-RADIOMONITOR-L1-1-0.DLL::RadioDeviceStop<br>InitializeSocketBroker<br>KamInitialize<br>KamUninitialize</summary>McTemplateU0z_EventWriteTransfer<br>McTemplateU0zq_EventWriteTransfer<br>SetNcbServiceStatus<br>WS2_32.DLL::Ordinal_115<br>WS2_32.DLL::Ordinal_116<br>__security_check_cookie<br>_guard_dispatch_icall$thunk$10345483385596137414<br>memset</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateEventW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::SetEvent<br>API-MS-WIN-CORE-THREADPOOL-LEGACY-L1-1-0.DLL::UnregisterWaitEx<br>CleanupSocketBroker<br>EXT-MS-WIN-NETWORKING-RADIOMONITOR-L1-1-0.DLL::RadioDeviceStart<br>EXT-MS-WIN-NETWORKING-RADIOMONITOR-L1-1-0.DLL::RadioDeviceStop<br>InitializeSocketBroker<br>KamInitialize<br>KamUninitialize</summary>McTemplateU0z_EventWriteTransfer<br>McTemplateU0zq_EventWriteTransfer<br>SetNcbServiceStatus<br>WS2_32.DLL::Ordinal_115<br>WS2_32.DLL::Ordinal_116<br>__security_check_cookie<br>_guard_dispatch_icall$thunk$10345483385596137414<br>memset<br>wil_InitializeFeatureStaging<br>wil_UninitializeFeatureStaging</details>|
|calling|ServiceMain|ServiceMain|
|paramcount|0|0|
|`address`|180017cf0|18001bd18|
|sig|ulong __fastcall StartNcbService(void)|ulong __fastcall StartNcbService(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### StartNcbService Called Diff


```diff
--- StartNcbService called
+++ StartNcbService called
@@ -19,0 +20,2 @@
+wil_InitializeFeatureStaging
+wil_UninitializeFeatureStaging
```


### StartNcbService Diff


```diff
--- StartNcbService
+++ StartNcbService
@@ -1,132 +1,135 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 ulong StartNcbService(void)
 
 {
   ulong uVar1;
   int iVar2;
-  undefined8 uVar3;
-  undefined8 *puVar4;
-  HANDLE pvVar5;
-  wchar_t *pwVar6;
+  undefined8 *puVar3;
+  HANDLE pvVar4;
+  wchar_t *pwVar5;
+  undefined8 uVar6;
   wchar_t *pwVar7;
   wchar_t *pwVar8;
   undefined1 auStack_1f8 [32];
   undefined8 local_1d8;
   undefined4 local_1d0;
   wchar_t local_1b8 [208];
   ulonglong local_18;
   ulong uStack_10;
   
   local_18 = __security_cookie ^ (ulonglong)auStack_1f8;
-  pwVar6 = (wchar_t *)0x0;
+  pwVar5 = (wchar_t *)0x0;
   pwVar8 = local_1b8;
+  uVar6 = 0x198;
   memset(pwVar8,0,0x198);
-  uVar1 = InitializeSocketBroker(pwVar8,pwVar6);
+  wil_InitializeFeatureStaging(pwVar8,pwVar5,uVar6);
+  uVar1 = InitializeSocketBroker(pwVar8,pwVar5);
   if (uVar1 == 0) {
     pwVar8 = (wchar_t *)0x0;
-    pwVar6 = (wchar_t *)0x1;
+    pwVar5 = (wchar_t *)0x1;
     g_StopHandles = CreateEventW((LPSECURITY_ATTRIBUTES)0x0,1,0,(LPCWSTR)0x0);
     if (g_StopHandles == (wchar_t *)0x0) {
       uVar1 = GetLastError();
       if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) == 0)
       goto LAB_0;
       pwVar7 = L"StartNcbService: Failed to create StopServiceEvent.";
     }
     else {
       pwVar7 = (wchar_t *)0x0;
-      pwVar6 = (wchar_t *)0x0;
+      pwVar5 = (wchar_t *)0x0;
       pwVar8 = (wchar_t *)0x0;
       DAT_1 = CreateEventW((LPSECURITY_ATTRIBUTES)0x0,0,0,(LPCWSTR)0x0);
       if (DAT_1 != (HANDLE)0x0) {
         SetNcbServiceStatus(2,0);
-        uVar3 = 2;
-        pwVar6 = local_1b8;
+        uVar6 = 2;
+        pwVar5 = local_1b8;
         iVar2 = Ordinal_115();
         if (iVar2 == 0) {
-          uVar1 = KamInitialize(uVar3,(LONG *)pwVar6,pwVar7);
+          uVar1 = KamInitialize(uVar6,(LONG *)pwVar5,pwVar7);
           if (uVar1 == 0) {
             iVar2 = RadioDeviceStart();
             if (iVar2 < 0) {
               RadioDeviceStop();
             }
-            pwVar6 = L"NcbService";
+            pwVar5 = L"NcbService";
             local_1d0 = 0x18;
-            puVar4 = &DAT_2;
+            puVar3 = &DAT_2;
             local_1d8 = 0;
             pwVar8 = g_StopHandles;
             uVar1 = (**(code **)(g_NcbSvcHostGlobalData + 0xc0))();
             if (uVar1 == 0) {
-              uVar3 = 0;
+              uVar6 = 0;
               _DAT_3 = 0x81;
               SetNcbServiceStatus(4,0);
-              pvVar5 = DAT_1;
+              pvVar4 = DAT_1;
               SetEvent(DAT_1);
               if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) == 0) {
                 return uStack_10;
               }
               McTemplateU0z_EventWriteTransfer
-                        (pvVar5,uVar3,L"StartNcbService: Started successfully.");
+                        (pvVar4,uVar6,L"StartNcbService: Started successfully.");
               return uStack_10;
             }
             if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
               pwVar8 = L"StartNcbService: Failed to register stop callback";
               McTemplateU0zq_EventWriteTransfer
-                        (puVar4,pwVar6,L"StartNcbService: Failed to register stop callback",uVar1);
+                        (puVar3,pwVar5,L"StartNcbService: Failed to register stop callback",uVar1);
             }
-            KamUninitialize(puVar4,(int *)pwVar6,pwVar8);
+            KamUninitialize(puVar3,(int *)pwVar5,pwVar8);
           }
           else if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
             McTemplateU0zq_EventWriteTransfer
-                      (uVar3,pwVar6,L"StartNcbService: KAM failed to initialize",uVar1);
+                      (uVar6,pwVar5,L"StartNcbService: KAM failed to initialize",uVar1);
           }
           Ordinal_116();
         }
         else {
           uVar1 = 0x426;
           if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
-            McTemplateU0z_EventWriteTransfer(uVar3,pwVar6,L"StartNcbService: Failed WSAStartup");
+            McTemplateU0z_EventWriteTransfer(uVar6,pwVar5,L"StartNcbService: Failed WSAStartup");
           }
         }
         goto LAB_0;
       }
       uVar1 = GetLastError();
       if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) == 0)
       goto LAB_0;
       pwVar7 = L"StartNcbService: Failed to create StartServiceCompleteEvent.";
     }
   }
   else {
     if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) == 0) goto LAB_0;
     pwVar7 = L"StartNcbService: InitializeSocketBroker failed.";
   }
-  McTemplateU0zq_EventWriteTransfer(pwVar8,pwVar6,pwVar7,uVar1);
+  McTemplateU0zq_EventWriteTransfer(pwVar8,pwVar5,pwVar7,uVar1);
 LAB_0:
   if (g_StopHandles != (wchar_t *)0x0) {
     CloseHandle(g_StopHandles);
     g_StopHandles = (wchar_t *)0x0;
   }
   if (DAT_2 != (HANDLE)0x0) {
-    pwVar6 = (wchar_t *)0x0;
+    pwVar5 = (wchar_t *)0x0;
     UnregisterWaitEx(DAT_2,(HANDLE)0x0);
     DAT_2 = (HANDLE)0x0;
   }
-  pvVar5 = DAT_1;
+  pvVar4 = DAT_1;
   if (DAT_1 != (HANDLE)0x0) {
     CloseHandle(DAT_1);
     DAT_1 = (HANDLE)0x0;
   }
   RadioDeviceStop();
   CleanupSocketBroker();
+  wil_UninitializeFeatureStaging();
   g_ErrorCode = uVar1;
   if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
     McTemplateU0zq_EventWriteTransfer
-              (pvVar5,pwVar6,L"StartNcbService: Failed to start service.",uVar1);
+              (pvVar4,pwVar5,L"StartNcbService: Failed to start service.",uVar1);
   }
   return uStack_10;
 }
 

```


## InitiateStopNcbService

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.99|
|i_ratio|0.3|
|m_ratio|0.99|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|InitiateStopNcbService|InitiateStopNcbService|
|fullname|InitiateStopNcbService|InitiateStopNcbService|
|refcount|3|3|
|`length`|302|307|
|`called`|API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-THREADPOOL-LEGACY-L1-1-0.DLL::UnregisterWaitEx<br>CleanupSocketBroker<br>EXT-MS-WIN-NETWORKING-RADIOMONITOR-L1-1-0.DLL::RadioDeviceStop<br>KamUninitialize<br>McGenEventUnregister_EventUnregister<br>McTemplateU0z_EventWriteTransfer<br>SetNcbServiceStatus<br>WS2_32.DLL::Ordinal_116|API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-THREADPOOL-LEGACY-L1-1-0.DLL::UnregisterWaitEx<br>CleanupSocketBroker<br>EXT-MS-WIN-NETWORKING-RADIOMONITOR-L1-1-0.DLL::RadioDeviceStop<br>KamUninitialize<br>McGenEventUnregister_EventUnregister<br>McTemplateU0z_EventWriteTransfer<br>SetNcbServiceStatus<br>WS2_32.DLL::Ordinal_116<br>wil_UninitializeFeatureStaging|
|calling|||
|paramcount|3|3|
|`address`|180023f30|180023f90|
|sig|ulonglong __fastcall InitiateStopNcbService(undefined8 param_1, int * param_2, wchar_t * param_3)|ulonglong __fastcall InitiateStopNcbService(undefined8 param_1, int * param_2, wchar_t * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### InitiateStopNcbService Called Diff


```diff
--- InitiateStopNcbService called
+++ InitiateStopNcbService called
@@ -9,0 +10 @@
+wil_UninitializeFeatureStaging
```


### InitiateStopNcbService Diff


```diff
--- InitiateStopNcbService
+++ InitiateStopNcbService
@@ -1,65 +1,66 @@
 
 ulonglong InitiateStopNcbService(undefined8 param_1,int *param_2,wchar_t *param_3)
 
 {
   ulonglong uVar1;
   HANDLE pvVar2;
   bool bVar3;
   
   uVar1 = 0;
   LOCK();
   bVar3 = g_Stopping == 0;
   if (bVar3) {
     g_Stopping = 1;
   }
   else {
     uVar1 = (ulonglong)g_Stopping;
   }
   UNLOCK();
   if (bVar3) {
     KamUninitialize(param_1,param_2,param_3);
     if (DAT_0 != (HANDLE)0x0) {
       param_2 = (int *)0x0;
       pvVar2 = DAT_0;
       UnregisterWaitEx(DAT_0,(HANDLE)0x0);
       DAT_0 = (HANDLE)0x0;
       if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
         McTemplateU0z_EventWriteTransfer(pvVar2,param_2,L"StopServiceWaitObject uninitialized");
       }
     }
     if (g_StopHandles != (HANDLE)0x0) {
       pvVar2 = g_StopHandles;
       CloseHandle(g_StopHandles);
       g_StopHandles = (HANDLE)0x0;
       if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
         McTemplateU0z_EventWriteTransfer(pvVar2,param_2,L"StopServiceEvent uninitialized");
       }
     }
     pvVar2 = DAT_1;
     if (DAT_1 != (HANDLE)0x0) {
       CloseHandle(DAT_1);
       DAT_1 = (HANDLE)0x0;
       if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
         McTemplateU0z_EventWriteTransfer(pvVar2,param_2,L"StartServiceCompleteEvent uninitialized");
       }
     }
     CleanupSocketBroker();
     RadioDeviceStop();
     Ordinal_116();
     if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
       McTemplateU0z_EventWriteTransfer
                 (pvVar2,param_2,L"NcbService will stop immediately following this log.");
     }
     if (g_TracingEnabled != 0) {
       McGenEventUnregister_EventUnregister();
     }
+    wil_UninitializeFeatureStaging();
     uVar1 = SetNcbServiceStatus(1,(ulonglong)g_ErrorCode);
   }
   else if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) != 0) {
     uVar1 = McTemplateU0z_EventWriteTransfer
                       (param_1,param_2,L"The serivce has already tried to stop once.");
     return uVar1;
   }
   return uVar1;
 }
 

```


## InitializeSocketBroker

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,called|
|ratio|0.17|
|i_ratio|0.11|
|m_ratio|0.95|
|b_ratio|0.34|
|match_types|Implied Match|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|`name`|InitializeSocketBroker|wil_InitializeFeatureStaging|
|`fullname`|InitializeSocketBroker|wil_InitializeFeatureStaging|
|refcount|2|2|
|`length`|173|181|
|`called`|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSection<br>BIHelper::Initialize<br>McTemplateU0zq_EventWriteTransfer<br>SocketBrokerConfig::ReadConfig<br>WnsNotifications::RegisterForWnfNotifications<br>operator_new|wil_details_FeatureDescriptors_SkipPadding<br>wil_details_InitializeFeatureStagingUsageReporting<br>wil_details_RtlRegisterFeatureConfigurationChangeNotification|
|calling|StartNcbService|StartNcbService|
|paramcount|2|3|
|`address`|18001d08c|1800241a0|
|`sig`|ulong __fastcall InitializeSocketBroker(undefined8 param_1, undefined8 param_2)|uint __fastcall wil_InitializeFeatureStaging(undefined8 param_1, undefined8 param_2, undefined8 param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### InitializeSocketBroker Called Diff


```diff
--- InitializeSocketBroker called
+++ wil_InitializeFeatureStaging called
@@ -1,6 +1,3 @@
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::InitializeCriticalSection
-BIHelper::Initialize
-McTemplateU0zq_EventWriteTransfer
-SocketBrokerConfig::ReadConfig
-WnsNotifications::RegisterForWnfNotifications
-operator_new
+wil_details_FeatureDescriptors_SkipPadding
+wil_details_InitializeFeatureStagingUsageReporting
+wil_details_RtlRegisterFeatureConfigurationChangeNotification
```


### InitializeSocketBroker Diff


```diff
--- InitializeSocketBroker
+++ wil_InitializeFeatureStaging
@@ -1,42 +1,48 @@
 
-ulong InitializeSocketBroker(undefined8 param_1,undefined8 param_2)
+uint wil_InitializeFeatureStaging(undefined8 param_1,undefined8 param_2,undefined8 param_3)
 
 {
-  ulong uVar1;
-  SocketBrokerConfig *this;
-  LPCRITICAL_SECTION lpCriticalSection;
-  BIHelper *this_00;
-  wchar_t *pwVar2;
+  bool bVar1;
+  uint uVar2;
+  longlong *plVar3;
+  undefined8 uVar4;
+  undefined **ppuVar5;
   
-  this = operator_new(0xc);
-  SocketBrokerConfig::ReadConfig(this);
-  g_SocketBrokerConfig = this;
-  lpCriticalSection = operator_new(0x58);
-  InitializeCriticalSection(lpCriticalSection);
-  this_00 = (BIHelper *)0x8;
-  *(undefined1 *)&lpCriticalSection[2].DebugInfo = 0;
-  g_SocketBrokerTable = (SocketBrokerTable *)lpCriticalSection;
-  g_BIHelper = operator_new(8);
-  *(undefined8 *)g_BIHelper = 0;
-  uVar1 = BIHelper::Initialize(this_00);
-  if (uVar1 == 0) {
-    param_2 = 0x4195003aa3bc0875;
-    uVar1 = WnsNotifications::RegisterForWnfNotifications();
-    if (uVar1 == 0) {
+  bVar1 = false;
+  if (g_wil_details_isFeatureStagingInitialized == 0) {
+    g_wil_details_isFeatureStagingInitialized = 1;
+    ppuVar5 = &Feature_939503929__private_descriptor;
+    while (plVar3 = wil_details_FeatureDescriptors_SkipPadding((longlong *)ppuVar5),
+          plVar3 != (longlong *)0x0) {
+      if (((*(char *)((longlong)plVar3 + 0x1d) == '\0') &&
+          (*(char *)((longlong)plVar3 + 0x1e) == '\0')) &&
+         (*(char *)((longlong)plVar3 + 0x1c) == '\0')) {
+        uVar4 = wil_details_RtlRegisterFeatureConfigurationChangeNotification
+                          (wil_details_InvalidateOnFeatureConfigurationChange,0,param_3,
+                           &g_wil_details_featureChangeNotification);
+        if ((int)uVar4 == 0) {
+          bVar1 = true;
+          g_wil_details_ensureSubscribedToFeatureConfigurationChanges =
+               wil_details_EnsureSubscribedToFeatureConfigurationChanges;
+          g_wil_details_subscribeFeatureStateCacheToConfigurationChanges =
+               wil_details_SubscribeFeatureStateCacheToConfigurationChanges;
+          g_wil_details_featureStateInvalidationEpoch = 1;
+        }
+        else {
+          g_wil_details_featureChangeNotification = 0;
+        }
+        break;
+      }
+      ppuVar5 = (undefined **)(plVar3 + 7);
+    }
+    uVar2 = wil_details_InitializeFeatureStagingUsageReporting();
+    if (uVar2 != 0) {
+      if (!bVar1) {
+        return uVar2;
+      }
       return 0;
     }
-    if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) == 0) {
-      return uVar1;
-    }
-    pwVar2 = L"WnsNotifications intialize failed";
   }
-  else {
-    if (((byte)Microsoft_Windows_Network_Connection_BrokerEnableBits & 1) == 0) {
-      return uVar1;
-    }
-    pwVar2 = L"BIHelper:Initialize failed";
-  }
-  McTemplateU0zq_EventWriteTransfer(this_00,param_2,pwVar2,uVar1);
-  return uVar1;
+  return 0;
 }
 

```


## CleanupSocketBroker

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|code,name,fullname,length,sig,address,called|
|ratio|0.32|
|i_ratio|0.24|
|m_ratio|0.92|
|b_ratio|0.47|
|match_types|Implied Match|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|`name`|CleanupSocketBroker|wil_UninitializeFeatureStaging|
|`fullname`|CleanupSocketBroker|wil_UninitializeFeatureStaging|
|refcount|3|3|
|`length`|137|115|
|`called`|BIHelper::Cleanup<br>SocketBrokerTable::~SocketBrokerTable<br>WnsNotifications::UnInitialize<br>operator_delete[]|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_FlushFeatureUsageCache<br>wil_details_GetKernelBaseProcAddress<br>wil_details_RtlUnregisterFeatureConfigurationChangeNotification|
|calling|InitiateStopNcbService<br>StartNcbService|InitiateStopNcbService<br>StartNcbService|
|paramcount|0|0|
|`address`|180027cc0|18002425c|
|`sig`|undefined __fastcall CleanupSocketBroker(void)|undefined __fastcall wil_UninitializeFeatureStaging(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### CleanupSocketBroker Called Diff


```diff
--- CleanupSocketBroker called
+++ wil_UninitializeFeatureStaging called
@@ -1,4 +1,4 @@
-BIHelper::Cleanup
-SocketBrokerTable::~SocketBrokerTable
-WnsNotifications::UnInitialize
-operator_delete[]
+_guard_dispatch_icall$thunk$10345483385596137414
+wil_details_FlushFeatureUsageCache
+wil_details_GetKernelBaseProcAddress
+wil_details_RtlUnregisterFeatureConfigurationChangeNotification
```


### CleanupSocketBroker Diff


```diff
--- CleanupSocketBroker
+++ wil_UninitializeFeatureStaging
@@ -1,27 +1,32 @@
 
-void CleanupSocketBroker(void)
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+void wil_UninitializeFeatureStaging(void)
 
 {
-  SocketBrokerTable *pSVar1;
-  BIHelper *pBVar2;
+  longlong lVar1;
   
-  WnsNotifications::UnInitialize(&g_WnsNotifications);
-  pSVar1 = g_SocketBrokerTable;
-  if (g_SocketBrokerTable != (SocketBrokerTable *)0x0) {
-    SocketBrokerTable::~SocketBrokerTable(g_SocketBrokerTable);
-    operator_delete__(pSVar1);
-    g_SocketBrokerTable = (SocketBrokerTable *)0x0;
+  if (g_wil_details_featureChangeNotification != 0) {
+    wil_details_RtlUnregisterFeatureConfigurationChangeNotification
+              (g_wil_details_featureChangeNotification);
+    g_wil_details_featureChangeNotification = 0;
   }
-  pBVar2 = g_BIHelper;
-  if (g_BIHelper != (BIHelper *)0x0) {
-    BIHelper::Cleanup(g_BIHelper);
-    operator_delete__(pBVar2);
-    g_BIHelper = (BIHelper *)0x0;
+  lVar1 = g_wil_details_featureUsageSubscription;
+  if (g_wil_details_featureUsageSubscription == 0) goto LAB_0;
+  if (g_wil_details_pfnUnsubscribeFeatureUsageFlush == (FARPROC)0x0) {
+    g_wil_details_pfnUnsubscribeFeatureUsageFlush =
+         wil_details_GetKernelBaseProcAddress("UnsubscribeFeatureUsageFlush");
+    if (g_wil_details_pfnUnsubscribeFeatureUsageFlush != (FARPROC)0x0) goto LAB_1;
   }
-  if (g_SocketBrokerConfig != (SocketBrokerConfig *)0x0) {
-    operator_delete__(g_SocketBrokerConfig);
-    g_SocketBrokerConfig = (SocketBrokerConfig *)0x0;
+  else {
+LAB_1:
+    (*g_wil_details_pfnUnsubscribeFeatureUsageFlush)(lVar1);
   }
+  g_wil_details_featureUsageSubscription = 0;
+LAB_0:
+  wil_details_FlushFeatureUsageCache();
+  g_wil_details_isFeatureStagingInitialized = 0;
   return;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## __GSHandlerCheck

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|__GSHandlerCheck|__GSHandlerCheck|
|fullname|__GSHandlerCheck|__GSHandlerCheck|
|`refcount`|105|104|
|length|29|29|
|called|__GSHandlerCheckCommon|__GSHandlerCheckCommon|
|calling|||
|paramcount|4|4|
|`address`|1800351dc|1800356d4|
|sig|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|GetModuleHandleW|GetModuleHandleW|
|fullname|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW|
|`refcount`|9|10|
|length|0|0|
|called|||
|`calling`|ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CRegKey::DeleteSubKey<br>wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetNtDllModuleHandle<br>wil_details_GetNtDllProcedureAddress|ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CRegKey::DeleteSubKey<br>wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetNtDllModuleHandle<br>wil_details_GetNtDllProcedureAddress|
|paramcount|1|1|
|`address`|EXTERNAL:000000a2|EXTERNAL:00000084|
|sig|HMODULE __stdcall GetModuleHandleW(LPCWSTR lpModuleName)|HMODULE __stdcall GetModuleHandleW(LPCWSTR lpModuleName)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW Calling Diff


```diff
--- API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW calling
+++ API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetModuleHandleW calling
@@ -6,0 +7 @@
+wil_details_GetKernelBaseProcAddress
```


## WilApi_RecordFeatureUsageReports

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|WilApi_RecordFeatureUsageReports|WilApi_RecordFeatureUsageReports|
|fullname|wil::details::WilApi_RecordFeatureUsageReports|wil::details::WilApi_RecordFeatureUsageReports|
|`refcount`|2|3|
|length|59|59|
|called|wil::details::WilApi_RecordFeatureUsage|wil::details::WilApi_RecordFeatureUsage|
|`calling`|wil_details_RecordCachedUsage||
|paramcount|2|2|
|`address`|1800344c4|180034b80|
|sig|void __cdecl WilApi_RecordFeatureUsageReports(__WIL_RTL_FEATURE_USAGE_DATA * param_1, __uint64 param_2)|void __cdecl WilApi_RecordFeatureUsageReports(__WIL_RTL_FEATURE_USAGE_DATA * param_1, __uint64 param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WilApi_RecordFeatureUsageReports Calling Diff


```diff
--- wil::details::WilApi_RecordFeatureUsageReports calling
+++ wil::details::WilApi_RecordFeatureUsageReports calling
@@ -1 +0,0 @@
-wil_details_RecordCachedUsage
```


## ?FREE@@YAXPEAX@Z

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|0.87|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|?FREE@@YAXPEAX@Z|?FREE@@YAXPEAX@Z|
|fullname|?FREE@@YAXPEAX@Z|?FREE@@YAXPEAX@Z|
|`refcount`|80|81|
|length|51|51|
|called|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree|API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree|
|calling|<details><summary>Expand for full list:<br>CleanupContextHelper<br>CopySampleHelperTemplate<br>CreateDefaultSampleSetHelperTemplate<br>FindOrCreateControlChannelTriggerContext<br>FreeSampleSetHelperTemplate<br>KamDestroyTimer<br>KapiDeliverKaUpdate<br>KapiDeliverKaUpdateWorkItem<br>KapiDestroyProvider<br>KapiProcessUpdateRequest<br>NcbCCResetGetProcessInformation</summary>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbUtilsGetClientUserSid<br>NcbUtilsGetPackageFullNameAndAppName<br>NcbUtilsMergeSocketInformation<br>RpcSrvRegisterControlChannelReset<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBEnumSockets<br>RpcSrvSBRetrieveContext<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvUnregisterControlChannelReset<br>SharedSocket::Cleanup<br>SharedSocket::FreeDnsRegistrationData<br>SharedSocket::FreeSocketBrokerSslContext<br>SharedSocket::FreeSslContext<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::~SharedSocket<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::~SocketBrokerContext<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::GetHash<br>StubNlmCacheInitialize<br>TcpListener::RetrieveAllSockets<br>VpnAllowedPluginDeclarationGetSecurityDescriptor<br>VpnAllowedPluginDeclarationShutdown<br>VpnExpandEnvironmentStrings<br>WakeTimer::CreateWakeTimer</details>|<details><summary>Expand for full list:<br>CleanupContextHelper<br>CopySampleHelperTemplate<br>CreateDefaultSampleSetHelperTemplate<br>FindOrCreateControlChannelTriggerContext<br>FreeSampleSetHelperTemplate<br>KamDestroyTimer<br>KapiDeliverKaUpdate<br>KapiDeliverKaUpdateWorkItem<br>KapiDestroyProvider<br>KapiProcessUpdateRequest<br>NcbCCResetGetProcessInformation</summary>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbUtilsGetClientUserSid<br>NcbUtilsGetPackageFullNameAndAppName<br>NcbUtilsMergeSocketInformation<br>RpcSrvRegisterControlChannelReset<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBEnumSockets<br>RpcSrvSBRetrieveContext<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvUnregisterControlChannelReset<br>SharedSocket::Cleanup<br>SharedSocket::FreeDnsRegistrationData<br>SharedSocket::FreeSocketBrokerSslContext<br>SharedSocket::FreeSslContext<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::~SharedSocket<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::~SocketBrokerContext<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::GetHash<br>StubNlmCacheInitialize<br>TcpListener::RetrieveAllSockets<br>VpnAllowedPluginDeclarationGetSecurityDescriptor<br>VpnAllowedPluginDeclarationShutdown<br>VpnExpandEnvironmentStrings<br>WakeTimer::CreateWakeTimer</details>|
|paramcount|1|1|
|address|180004c10|180004c10|
|sig|void __stdcall ?FREE@@YAXPEAX@Z(void * param_1)|void __stdcall ?FREE@@YAXPEAX@Z(void * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## McTemplateU0zq_EventWriteTransfer

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.77|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|McTemplateU0zq_EventWriteTransfer|McTemplateU0zq_EventWriteTransfer|
|fullname|McTemplateU0zq_EventWriteTransfer|McTemplateU0zq_EventWriteTransfer|
|`refcount`|240|241|
|length|170|170|
|called|McGenEventWrite_EventWriteTransfer<br>__security_check_cookie|McGenEventWrite_EventWriteTransfer<br>__security_check_cookie|
|calling|<details><summary>Expand for full list:<br>AppUserModelIdFromAppNameAndPackage<br>BIHelper::Cleanup<br>BIHelper::Initialize<br>BIHelper::OnCreateEvent<br>BIHelper::TriggerAppPrivate<br>CONTEXT_HANDLE_rundown<br>FindEventForPackage<br>FindOrCreateControlChannelTriggerContext<br>InitializeSocketBroker<br>KamDecreaseKeepAliveIntervalTime<br>KamDestroyTimer</summary>KamInitialize<br>KamSetKeepAliveIntervalTime<br>KamSupressKeepaliveTimer<br>KampCreateTimeEvent<br>KampNetworkStateChangeTpCallback<br>KampProxyNotificationCallback<br>KampReadConfiguredKeepaliveFloorTime<br>KampRegisterForProxyNotifications<br>KampUpdateTimeEventHelper<br>NcbCCResetCapabilityCheck<br>NcbCCResetDeleteEventHelper<br>NcbCCResetGetProcessInformation<br>NcbCCResetInitialize<br>NcbCCResetOnRestoreEvent<br>NcbCCResetSignalEventId<br>NcbCCResetUninitialize<br>NcbPolicyAddUserLockscreenAppsUnderLock<br>NcbPolicyCreatePolicy<br>NcbPolicyEnumerateUserLockscreenApps<br>NcbPolicyFindMatchingPolicyUnderLock<br>NcbPolicyInitialize<br>NcbPolicyIsInteractiveUserLogonSession<br>NcbPolicyIsPackageSidAllowed<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenAddHandlerUnderLock<br>NcbPolicyOnAppLockScreenRemoveHandler<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPopulatePolicies<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicySubscribeToWnfEvents<br>NcbPolicySubscribeToWnfHelper<br>NcbPolicyUninitialize<br>NcbPolicyUnsubscribeFromWnfHelper<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarAuthorizeOrCleanupContexts<br>NcbRegistrarInitialize<br>NcbRegistrarReadSlotTestOverride<br>NcbRegistrarUninitialize<br>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbRegistrarpOpenControlSocket<br>NcbRegistrarpSignalKeepAliveEvent<br>NcbSqmKeepaliveStream<br>NcbUtilsAllocCopyString<br>NcbUtilsAllocateEnumSocketInformation<br>NcbUtilsCopySBAppContext<br>NcbUtilsGetClientUserSid<br>NcbUtilsGetPackageFullNameAndAppName<br>NcbUtilsGetProcessImageFileName<br>NcbUtilsMergeSocketInformation<br>NcbpRegistrarCheckExtensionPolicy<br>PackageFullNameToSid<br>RpcHelperRetriveSbContext<br>RpcSrvCreateSession<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvDestroySession<br>RpcSrvGetCurrentKeepAliveInterval<br>RpcSrvIndicateSlotAllocation<br>RpcSrvRegisterControlChannelReset<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBEnumSockets<br>RpcSrvSBRetrieveContext<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvStartBrokeredActivation<br>RpcSrvUnregisterControlChannelReset<br>RpcSrvUsingTransport<br>SetNcbServiceStatus<br>SharedSocket::CopyDnsRegistrationData<br>SharedSocket::CreateCleanupTimer<br>SharedSocket::CreateKeepAliveTimer<br>SharedSocket::CreateRetryTriggerMonitor<br>SharedSocket::DeleteKeepAliveTimer<br>SharedSocket::DeleteRetryTriggerTimer<br>SharedSocket::DnsServiceDeregistration<br>SharedSocket::DuplicateSocketHelper<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::GetSslContext<br>SharedSocket::ImportSslContext<br>SharedSocket::Initialize<br>SharedSocket::InitializeSecurityFunctions<br>SharedSocket::RegistrationCompletion<br>SocketBrokerConfig::ReadConfig<br>SocketBrokerContext::CompleteRetrieveSocket<br>SocketBrokerContext::CreateBrokerContext<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::DeletePushEnableContext<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::Impersonate<br>SocketBrokerContext::Initialize<br>SocketBrokerContext::IsLimitExceeded<br>SocketBrokerContext::NotifyApp<br>SocketBrokerContext::RetrieveContext<br>SocketBrokerContext::RetrieveSocket<br>SocketBrokerContext::TransferOwnership<br>SocketBrokerTable::Add<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::Initialize<br>SocketBrokerTable::Remove<br>SocketIoMonitor::GetDuplicatedSocket<br>SocketIoMonitor::HandleWaitCallback<br>SocketIoMonitor::Initialize<br>SocketIoMonitor::ResetNonBlockingIO<br>StartNcbCCResetRpcServer<br>StartNcbRpcServer<br>StartNcbService<br>TcpListener::CreateAcceptSocket<br>TcpListener::DuplicateConnectedSocket<br>TcpListener::HandleInComingConnection<br>TcpListener::Initialize<br>TcpListener::PostAccept<br>TcpListener::RetrieveAllSockets<br>TcpListener::RetrieveConnectedSocket<br>TriggerBackgroundEvent<br>WakeTimer::CreateWakeTimer<br>WnsNotifications::RegisterForWnfNotifications</details>|<details><summary>Expand for full list:<br>AppUserModelIdFromAppNameAndPackage<br>BIHelper::Cleanup<br>BIHelper::Initialize<br>BIHelper::OnCreateEvent<br>BIHelper::TriggerAppPrivate<br>CONTEXT_HANDLE_rundown<br>FindEventForPackage<br>FindOrCreateControlChannelTriggerContext<br>InitializeSocketBroker<br>KamDecreaseKeepAliveIntervalTime<br>KamDestroyTimer</summary>KamInitialize<br>KamSetKeepAliveIntervalTime<br>KamSupressKeepaliveTimer<br>KampCreateTimeEvent<br>KampNetworkStateChangeTpCallback<br>KampProxyNotificationCallback<br>KampReadConfiguredKeepaliveFloorTime<br>KampRegisterForProxyNotifications<br>KampUpdateTimeEventHelper<br>NcbCCResetCapabilityCheck<br>NcbCCResetDeleteEventHelper<br>NcbCCResetGetProcessInformation<br>NcbCCResetInitialize<br>NcbCCResetOnRestoreEvent<br>NcbCCResetSignalEventId<br>NcbCCResetUninitialize<br>NcbPolicyAddUserLockscreenAppsUnderLock<br>NcbPolicyCreatePolicy<br>NcbPolicyEnumerateUserLockscreenApps<br>NcbPolicyFindMatchingPolicyUnderLock<br>NcbPolicyInitialize<br>NcbPolicyIsInteractiveUserLogonSession<br>NcbPolicyIsPackageSidAllowed<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenAddHandlerUnderLock<br>NcbPolicyOnAppLockScreenRemoveHandler<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPopulatePolicies<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicySubscribeToWnfEvents<br>NcbPolicySubscribeToWnfHelper<br>NcbPolicyUninitialize<br>NcbPolicyUnsubscribeFromWnfHelper<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarAuthorizeOrCleanupContexts<br>NcbRegistrarInitialize<br>NcbRegistrarReadSlotTestOverride<br>NcbRegistrarUninitialize<br>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbRegistrarpOpenControlSocket<br>NcbRegistrarpSignalKeepAliveEvent<br>NcbSqmKeepaliveStream<br>NcbUtilsAllocCopyString<br>NcbUtilsAllocateEnumSocketInformation<br>NcbUtilsCopySBAppContext<br>NcbUtilsGetClientUserSid<br>NcbUtilsGetPackageFullNameAndAppName<br>NcbUtilsGetProcessImageFileName<br>NcbUtilsMergeSocketInformation<br>NcbpRegistrarCheckExtensionPolicy<br>PackageFullNameToSid<br>RpcHelperRetriveSbContext<br>RpcSrvCreateSession<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvDestroySession<br>RpcSrvGetCurrentKeepAliveInterval<br>RpcSrvIndicateSlotAllocation<br>RpcSrvRegisterControlChannelReset<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBEnumSockets<br>RpcSrvSBRetrieveContext<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvStartBrokeredActivation<br>RpcSrvUnregisterControlChannelReset<br>RpcSrvUsingTransport<br>SetNcbServiceStatus<br>SharedSocket::CopyDnsRegistrationData<br>SharedSocket::CreateCleanupTimer<br>SharedSocket::CreateKeepAliveTimer<br>SharedSocket::CreateRetryTriggerMonitor<br>SharedSocket::DeleteKeepAliveTimer<br>SharedSocket::DeleteRetryTriggerTimer<br>SharedSocket::DnsServiceDeregistration<br>SharedSocket::DuplicateSocketHelper<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::GetSslContext<br>SharedSocket::ImportSslContext<br>SharedSocket::Initialize<br>SharedSocket::InitializeSecurityFunctions<br>SharedSocket::RegistrationCompletion<br>SocketBrokerConfig::ReadConfig<br>SocketBrokerContext::CompleteRetrieveSocket<br>SocketBrokerContext::CreateBrokerContext<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::DeletePushEnableContext<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::Impersonate<br>SocketBrokerContext::Initialize<br>SocketBrokerContext::IsLimitExceeded<br>SocketBrokerContext::NotifyApp<br>SocketBrokerContext::RetrieveContext<br>SocketBrokerContext::RetrieveSocket<br>SocketBrokerContext::TransferOwnership<br>SocketBrokerTable::Add<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::Initialize<br>SocketBrokerTable::Remove<br>SocketIoMonitor::GetDuplicatedSocket<br>SocketIoMonitor::HandleWaitCallback<br>SocketIoMonitor::Initialize<br>SocketIoMonitor::ResetNonBlockingIO<br>StartNcbCCResetRpcServer<br>StartNcbRpcServer<br>StartNcbService<br>TcpListener::CreateAcceptSocket<br>TcpListener::DuplicateConnectedSocket<br>TcpListener::HandleInComingConnection<br>TcpListener::Initialize<br>TcpListener::PostAccept<br>TcpListener::RetrieveAllSockets<br>TcpListener::RetrieveConnectedSocket<br>TriggerBackgroundEvent<br>WakeTimer::CreateWakeTimer<br>WnsNotifications::RegisterForWnfNotifications</details>|
|paramcount|4|4|
|`address`|18000d6a0|18000d670|
|sig|undefined __fastcall McTemplateU0zq_EventWriteTransfer(undefined8 param_1, undefined8 param_2, wchar_t * param_3, undefined4 param_4)|undefined __fastcall McTemplateU0zq_EventWriteTransfer(undefined8 param_1, undefined8 param_2, wchar_t * param_3, undefined4 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## __security_check_cookie

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|__security_check_cookie|__security_check_cookie|
|fullname|__security_check_cookie|__security_check_cookie|
|`refcount`|131|130|
|length|30|30|
|called|__report_gsfailure|__report_gsfailure|
|`calling`|<details><summary>Expand for full list:<br>ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CRegKey::RecurseDeleteKey<br>ATL::CRegObject::RegisterFromResource<br>ATL::CRegParser::AddValue<br>ATL::CRegParser::PreProcessBuffer<br>ATL::CRegParser::RegisterBuffer<br>ATL::CRegParser::RegisterSubkeys<br>ATL::CRegParser::SkipAssignment<br>AppUserModelIdFromAppNameAndPackage<br>BIHelper::TriggerAppPrivate</summary>CleanupContext<br>CleanupContextHelper<br>DereferenceContextEx<br>FindEventForPackage<br>FindOrCreateControlChannelTriggerContext<br>FirewallHelper::AddAppRoutePolicyRules<br>FirewallHelper::AddProvider<br>FirewallHelper::DeleteAppRoutePolicyFiltersByLayerKey<br>FirewallHelper::DeleteAppRoutePolicyRulesByProviderId<br>FirewallHelper::IsWin32AppId<br>FirewallHelper::RemovePfnBlockRulesWithRemoteNameFlags<br>FirewallHelper::SetFirewallRule<br>GetAllConnectedNetworkIdsEx<br>InitializeNcbRegistry<br>IsNetworkReachableOverMbb<br>IsOSServerSku<br>IsVpnClientAccessCheck<br>IterateOverRegistryKey<br>KamDestroyTimer<br>KamSetKeepAliveIntervalTime<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampMakeNlmCacheKey<br>KampNetworkStateChangeWnfCallback<br>KapiLookupProviderByHandle<br>KapiNetworkConnectivityChangeNotificationInternal<br>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiUpdateKaSample<br>McTemplateU0jz_EventWriteTransfer<br>McTemplateU0jzd_EventWriteTransfer<br>McTemplateU0jzddd_EventWriteTransfer<br>McTemplateU0jzz_EventWriteTransfer<br>McTemplateU0pq_EventWriteTransfer<br>McTemplateU0pqsq_EventWriteTransfer<br>McTemplateU0z_EventWriteTransfer<br>McTemplateU0zdd_EventWriteTransfer<br>McTemplateU0zq_EventWriteTransfer<br>McTemplateU0zqqqq_EventWriteTransfer<br>McTemplateU0zt_EventWriteTransfer<br>NcbCCResetSignalHelper<br>NcbPolicyCreatePolicy<br>NcbPolicyEnumerateUserLockscreenApps<br>NcbPolicyIsInteractiveUserLogonSession<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenAddHandlerUnderLock<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPolicyChangeCallback<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandler<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicySubscribeToWnfEvents<br>NcbPolicySubscribeToWnfHelper<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarPolicyIsContextAllowed<br>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbRegistrarpOpenControlSocket<br>NcbRegistrarpSignalKeepAliveEvent<br>NcbRegpCreateOrUpdateWPMContext<br>NcbSqmKeepaliveStream<br>NcbUtilsGetClientUserSid<br>NcbUtilsGetProcessImageFileName<br>NcbpRegistrarpGetAppUserModelIdForContext<br>PackageFullNameToSid<br>ReferenceContextEx<br>RpcSrvCreateSession<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvDestroySession<br>RpcSrvIndicateSlotAllocation<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBEnumSockets<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvSetServerKeepAliveInterval<br>RpcSrvStartBrokeredActivation<br>ServiceHandler<br>SharedSocket::Initialize<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::DeletePushEnableContext<br>SocketIoMonitor::HandleWaitCallback<br>StartNcbService<br>StubNlmCacheDeletePersistentStoreEntryWorkItem<br>StubNlmCacheStorePersistentStoreEntryWorkItem<br>TcpListener::PostAccept<br>TraceLoggingRegisterEx_EventRegister_EventSetInformation<br>TriggerBackgroundEvent<br>WakeTimer::CreateWakeTimer<br>WnsNotifications::RegisterForWnfNotifications<br>__GSHandlerCheckCommon<br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByRef<16>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<4>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>_><br>wil::GetFailureLogString<br>wil::ResultException::what<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::GetModuleInformation<br>wil::details::ReportFailure_CaughtException<1><br>wil::details::ReportFailure_Return<1><br>wil::details::ReportFailure_Return<2><br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::SemaphoreValue::CreateFromValueInternal<br>wil::details_abi::SemaphoreValue::TryGetValueInternal<br>wil::details_abi::UsageIndexes::Record<br>wil_RtlStagingConfig_QueryFeatureState<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_RecordCachedUsage<br>wil_details_WriteSRUMWnfUsageBuffer</details>|<details><summary>Expand for full list:<br>ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CAtlModule::UpdateRegistryFromResourceS<br>ATL::CRegKey::RecurseDeleteKey<br>ATL::CRegObject::RegisterFromResource<br>ATL::CRegParser::AddValue<br>ATL::CRegParser::PreProcessBuffer<br>ATL::CRegParser::RegisterBuffer<br>ATL::CRegParser::RegisterSubkeys<br>ATL::CRegParser::SkipAssignment<br>AppUserModelIdFromAppNameAndPackage<br>BIHelper::TriggerAppPrivate</summary>CleanupContext<br>CleanupContextHelper<br>DereferenceContextEx<br>FindEventForPackage<br>FindOrCreateControlChannelTriggerContext<br>FirewallHelper::AddAppRoutePolicyRules<br>FirewallHelper::AddProvider<br>FirewallHelper::DeleteAppRoutePolicyFiltersByLayerKey<br>FirewallHelper::DeleteAppRoutePolicyRulesByProviderId<br>FirewallHelper::IsWin32AppId<br>FirewallHelper::RemovePfnBlockRulesWithRemoteNameFlags<br>FirewallHelper::SetFirewallRule<br>GetAllConnectedNetworkIdsEx<br>InitializeNcbRegistry<br>IsNetworkReachableOverMbb<br>IsOSServerSku<br>IsVpnClientAccessCheck<br>IterateOverRegistryKey<br>KamSetKeepAliveIntervalTime<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampMakeNlmCacheKey<br>KampNetworkStateChangeWnfCallback<br>KapiLookupProviderByHandle<br>KapiNetworkConnectivityChangeNotificationInternal<br>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiUpdateKaSample<br>McTemplateU0jz_EventWriteTransfer<br>McTemplateU0jzd_EventWriteTransfer<br>McTemplateU0jzddd_EventWriteTransfer<br>McTemplateU0jzz_EventWriteTransfer<br>McTemplateU0pq_EventWriteTransfer<br>McTemplateU0pqsq_EventWriteTransfer<br>McTemplateU0z_EventWriteTransfer<br>McTemplateU0zdd_EventWriteTransfer<br>McTemplateU0zq_EventWriteTransfer<br>McTemplateU0zqqqq_EventWriteTransfer<br>McTemplateU0zt_EventWriteTransfer<br>NcbCCResetSignalHelper<br>NcbPolicyCreatePolicy<br>NcbPolicyEnumerateUserLockscreenApps<br>NcbPolicyIsInteractiveUserLogonSession<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenAddHandlerUnderLock<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPolicyChangeCallback<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandler<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicySubscribeToWnfEvents<br>NcbPolicySubscribeToWnfHelper<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarPolicyIsContextAllowed<br>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbRegistrarpOpenControlSocket<br>NcbRegistrarpSignalKeepAliveEvent<br>NcbRegpCreateOrUpdateWPMContext<br>NcbSqmKeepaliveStream<br>NcbUtilsGetClientUserSid<br>NcbUtilsGetProcessImageFileName<br>NcbpRegistrarpGetAppUserModelIdForContext<br>PackageFullNameToSid<br>ReferenceContextEx<br>RpcSrvCreateSession<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvDestroySession<br>RpcSrvIndicateSlotAllocation<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBEnumSockets<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvSetServerKeepAliveInterval<br>RpcSrvStartBrokeredActivation<br>ServiceHandler<br>SharedSocket::Initialize<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::DeletePushEnableContext<br>SocketIoMonitor::HandleWaitCallback<br>StartNcbService<br>StubNlmCacheDeletePersistentStoreEntryWorkItem<br>StubNlmCacheStorePersistentStoreEntryWorkItem<br>TcpListener::PostAccept<br>TraceLoggingRegisterEx_EventRegister_EventSetInformation<br>TriggerBackgroundEvent<br>WakeTimer::CreateWakeTimer<br>WnsNotifications::RegisterForWnfNotifications<br>__GSHandlerCheckCommon<br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByRef<16>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapSz<unsigned_short>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>,struct__tlgWrapperByVal<4>,struct__tlgWrapperByVal<4>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByRef<16>_><br>_tlgWriteTemplate<long___cdecl(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),&long___cdecl__tlgWriteTransfer_EventWriteTransfer(struct__tlgProvider_t_const*___ptr64,void_const*___ptr64,struct__GUID_const*___ptr64,struct__GUID_const*___ptr64,unsigned_int,struct__EVENT_DATA_DESCRIPTOR*___ptr64),struct__GUID_const*___ptr64,struct__GUID_const*___ptr64>::Write<struct__tlgWrapperByVal<4>,struct__tlgWrapSz<unsigned_short>,struct__tlgWrapperByVal<4>,struct__tlgWrapSz<char>_><br>wil::GetFailureLogString<br>wil::ResultException::what<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::GetModuleInformation<br>wil::details::ReportFailure_CaughtException<1><br>wil::details::ReportFailure_Return<1><br>wil::details::ReportFailure_Return<2><br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::SemaphoreValue::CreateFromValueInternal<br>wil::details_abi::SemaphoreValue::TryGetValueInternal<br>wil::details_abi::UsageIndexes::Record<br>wil_RtlStagingConfig_QueryFeatureState<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_RecordCachedUsage<br>wil_details_WriteSRUMWnfUsageBuffer</details>|
|paramcount|1|1|
|`address`|18001d8d0|18001d8b0|
|sig|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### __security_check_cookie Calling Diff


```diff
--- __security_check_cookie calling
+++ __security_check_cookie calling
@@ -30 +29,0 @@
-KamDestroyTimer
```


## API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|GetProcAddress|GetProcAddress|
|fullname|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress|
|`refcount`|9|10|
|length|0|0|
|called|||
|`calling`|ATL::CRegKey::DeleteSubKey<br>MicrosoftTelemetryAssertTriggeredNoArgs<br>wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetNtDllProcedureAddress|ATL::CRegKey::DeleteSubKey<br>MicrosoftTelemetryAssertTriggeredNoArgs<br>wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetNtDllProcedureAddress|
|paramcount|2|2|
|`address`|EXTERNAL:000000a3|EXTERNAL:00000087|
|sig|FARPROC __stdcall GetProcAddress(HMODULE hModule, LPCSTR lpProcName)|FARPROC __stdcall GetProcAddress(HMODULE hModule, LPCSTR lpProcName)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress Calling Diff


```diff
--- API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress calling
+++ API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress calling
@@ -5,0 +6 @@
+wil_details_GetKernelBaseProcAddress
```


## McGenEventWrite_EventWriteTransfer

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.78|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|McGenEventWrite_EventWriteTransfer|McGenEventWrite_EventWriteTransfer|
|fullname|McGenEventWrite_EventWriteTransfer|McGenEventWrite_EventWriteTransfer|
|`refcount`|73|72|
|length|90|90|
|called|API-MS-WIN-EVENTING-PROVIDER-L1-1-0.DLL::EventWriteTransfer|API-MS-WIN-EVENTING-PROVIDER-L1-1-0.DLL::EventWriteTransfer|
|`calling`|<details><summary>Expand for full list:<br>CleanupContext<br>CleanupContextHelper<br>DereferenceContextEx<br>FindOrCreateControlChannelTriggerContext<br>KamDestroyTimer<br>KamSetKeepAliveIntervalTime<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampMakeNlmCacheKey<br>KampNetworkStateChangeWnfCallback<br>KapiLookupProviderByHandle</summary>KapiNetworkConnectivityChangeNotificationInternal<br>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiUpdateKaSample<br>McTemplateU0jz_EventWriteTransfer<br>McTemplateU0jzd_EventWriteTransfer<br>McTemplateU0jzddd_EventWriteTransfer<br>McTemplateU0jzz_EventWriteTransfer<br>McTemplateU0pq_EventWriteTransfer<br>McTemplateU0pqsq_EventWriteTransfer<br>McTemplateU0z_EventWriteTransfer<br>McTemplateU0zdd_EventWriteTransfer<br>McTemplateU0zq_EventWriteTransfer<br>McTemplateU0zqqqq_EventWriteTransfer<br>McTemplateU0zt_EventWriteTransfer<br>NcbCCResetSignalHelper<br>NcbPolicyEnumerateUserLockscreenApps<br>NcbPolicyIsInteractiveUserLogonSession<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenAddHandlerUnderLock<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPolicyChangeCallback<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandler<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarPolicyIsContextAllowed<br>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbRegpCreateOrUpdateWPMContext<br>NcbUtilsGetClientUserSid<br>NcbpRegistrarpGetAppUserModelIdForContext<br>ReferenceContextEx<br>RpcSrvCreateSession<br>RpcSrvIndicateSlotAllocation<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvSetServerKeepAliveInterval<br>RpcSrvStartBrokeredActivation<br>ServiceHandler</details>|<details><summary>Expand for full list:<br>CleanupContext<br>CleanupContextHelper<br>DereferenceContextEx<br>FindOrCreateControlChannelTriggerContext<br>KamSetKeepAliveIntervalTime<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampMakeNlmCacheKey<br>KampNetworkStateChangeWnfCallback<br>KapiLookupProviderByHandle<br>KapiNetworkConnectivityChangeNotificationInternal</summary>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiUpdateKaSample<br>McTemplateU0jz_EventWriteTransfer<br>McTemplateU0jzd_EventWriteTransfer<br>McTemplateU0jzddd_EventWriteTransfer<br>McTemplateU0jzz_EventWriteTransfer<br>McTemplateU0pq_EventWriteTransfer<br>McTemplateU0pqsq_EventWriteTransfer<br>McTemplateU0z_EventWriteTransfer<br>McTemplateU0zdd_EventWriteTransfer<br>McTemplateU0zq_EventWriteTransfer<br>McTemplateU0zqqqq_EventWriteTransfer<br>McTemplateU0zt_EventWriteTransfer<br>NcbCCResetSignalHelper<br>NcbPolicyEnumerateUserLockscreenApps<br>NcbPolicyIsInteractiveUserLogonSession<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenAddHandlerUnderLock<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPolicyChangeCallback<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandler<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarPolicyIsContextAllowed<br>NcbRegistrarpGetApplicationPackageSid<br>NcbRegistrarpGetApplicationParams<br>NcbRegpCreateOrUpdateWPMContext<br>NcbUtilsGetClientUserSid<br>NcbpRegistrarpGetAppUserModelIdForContext<br>ReferenceContextEx<br>RpcSrvCreateSession<br>RpcSrvIndicateSlotAllocation<br>RpcSrvSBCompleteRetrieveSocket<br>RpcSrvSBCreatePushEnabledContext<br>RpcSrvSBRetrieveSocket<br>RpcSrvSBTransferOwnership<br>RpcSrvSetServerKeepAliveInterval<br>RpcSrvStartBrokeredActivation<br>ServiceHandler</details>|
|paramcount|5|5|
|`address`|18000d760|18000d730|
|sig|undefined __fastcall McGenEventWrite_EventWriteTransfer(undefined8 param_1, PCEVENT_DESCRIPTOR param_2, undefined8 param_3, ULONG param_4, PEVENT_DATA_DESCRIPTOR param_5)|undefined __fastcall McGenEventWrite_EventWriteTransfer(undefined8 param_1, PCEVENT_DESCRIPTOR param_2, undefined8 param_3, ULONG param_4, PEVENT_DATA_DESCRIPTOR param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### McGenEventWrite_EventWriteTransfer Calling Diff


```diff
--- McGenEventWrite_EventWriteTransfer calling
+++ McGenEventWrite_EventWriteTransfer calling
@@ -5 +4,0 @@
-KamDestroyTimer
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|EnterCriticalSection|EnterCriticalSection|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection|
|`refcount`|125|126|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>ATL::CComSafeDeleteCriticalSection::Lock<br>AcceptSocketList::CleanAll<br>AcceptSocketList::ForEach<br>AcceptSocketList::Remove<br>AppResurrectionManager::ShouldEventBeFired<br>CONTEXT_HANDLE_kapi_rundown<br>EnqueueWorkQueueItem<br>FindAndRemoveContextFromList<br>FindOrCreateControlChannelTriggerContext<br>KamDecreaseKeepAliveIntervalTime<br>KamGetSocketBrokerKeepAliveTime</summary>KamSetKeepAliveIntervalTime<br>KamSupressKeepaliveTimer<br>KamUpdateTimeEvent<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampNetworkStateChangeTpCallback<br>KampUpdateTimeEventHelper<br>KapiDeliverKaUpdate<br>KapiInitialize<br>KapiNetworkConnectivityChangeNotificationInternal<br>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiRegisterProvider<br>KapiUninitialize<br>KapiUpdateKaSample<br>NcbPolicyCleanupPolicies<br>NcbPolicyIsPackageSidAllowed<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenRemoveHandler<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicyWnfAppLockScreenUpdateHandler<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarAuthorizeOrCleanupContexts<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvGetCurrentKeepAliveInterval<br>RpcSrvIndicateSlotAllocation<br>RpcSrvStartBrokeredActivation<br>RpcSrvUsingTransport<br>SharedSocket::Cleanup<br>SharedSocket::CreateCleanupTimer<br>SharedSocket::CreateKeepAliveTimer<br>SharedSocket::CreateRetryTriggerMonitor<br>SharedSocket::DeleteCleanupTimer<br>SharedSocket::DeleteKeepAliveTimer<br>SharedSocket::DeleteRetryTriggerTimer<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::GetSocketType<br>SharedSocket::HandleKeepAliveCallback<br>SharedSocket::HandleRetryTrigger<br>SharedSocket::Initialize<br>SharedSocket::InitializeSecurityFunctions<br>SharedSocket::UpdateKeepAliveTimer<br>SocketBrokerContext::AddSocketToList<br>SocketBrokerContext::CleanupSocket<br>SocketBrokerContext::CleanupSockets<br>SocketBrokerContext::CompleteRetrieveSocket<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::FindSocket<br>SocketBrokerContext::HandleWnsConnectNotifications<br>SocketBrokerContext::HandleWnsDisconnectNotifications<br>SocketBrokerContext::Initialize<br>SocketBrokerContext::IsLimitExceeded<br>SocketBrokerContext::NotifyApp<br>SocketBrokerContext::RetrieveContext<br>SocketBrokerContext::RetrieveSocket<br>SocketBrokerContext::SetBIEvent<br>SocketBrokerContext::TransferOwnership<br>SocketBrokerTable::Add<br>SocketBrokerTable::CleanAll<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::HandleWnsNotifications<br>SocketBrokerTable::Initialize<br>SocketBrokerTable::Remove<br>SocketBrokerTable::UpdateKeepAliveTimeout<br>SocketIoMonitor::Cleanup<br>SocketIoMonitor::GetDuplicatedSocket<br>SocketIoMonitor::HandleWaitCallback<br>SocketIoMonitor::Initialize<br>StubNlmCacheDeleteStoredValue<br>StubNlmCacheRetrieveStoredValue<br>StubNlmCacheStoreValue<br>TcpListener::CancelPendingIO<br>TcpListener::Cleanup<br>TcpListener::CreateAcceptSocket<br>TcpListener::HandleInComingConnection<br>TcpListener::Initialize<br>TcpListener::PostAccept<br>TcpListener::RetrieveAllSockets<br>TcpListener::RetrieveConnectedSocket<br>WorkQueueCallback<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|<details><summary>Expand for full list:<br>ATL::CComSafeDeleteCriticalSection::Lock<br>AcceptSocketList::CleanAll<br>AcceptSocketList::ForEach<br>AcceptSocketList::Remove<br>AppResurrectionManager::ShouldEventBeFired<br>CONTEXT_HANDLE_kapi_rundown<br>EnqueueWorkQueueItem<br>FindAndRemoveContextFromList<br>FindOrCreateControlChannelTriggerContext<br>KamDecreaseKeepAliveIntervalTime<br>KamDestroyTimer</summary>KamGetSocketBrokerKeepAliveTime<br>KamSetKeepAliveIntervalTime<br>KamSupressKeepaliveTimer<br>KamUpdateTimeEvent<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampNetworkStateChangeTpCallback<br>KampUpdateTimeEventHelper<br>KapiDeliverKaUpdate<br>KapiInitialize<br>KapiNetworkConnectivityChangeNotificationInternal<br>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiRegisterProvider<br>KapiUninitialize<br>KapiUpdateKaSample<br>NcbPolicyCleanupPolicies<br>NcbPolicyIsPackageSidAllowed<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenRemoveHandler<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicyWnfAppLockScreenUpdateHandler<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarAuthorizeOrCleanupContexts<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvGetCurrentKeepAliveInterval<br>RpcSrvIndicateSlotAllocation<br>RpcSrvStartBrokeredActivation<br>RpcSrvUsingTransport<br>SharedSocket::Cleanup<br>SharedSocket::CreateCleanupTimer<br>SharedSocket::CreateKeepAliveTimer<br>SharedSocket::CreateRetryTriggerMonitor<br>SharedSocket::DeleteCleanupTimer<br>SharedSocket::DeleteKeepAliveTimer<br>SharedSocket::DeleteRetryTriggerTimer<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::GetSocketType<br>SharedSocket::HandleKeepAliveCallback<br>SharedSocket::HandleRetryTrigger<br>SharedSocket::Initialize<br>SharedSocket::InitializeSecurityFunctions<br>SharedSocket::UpdateKeepAliveTimer<br>SocketBrokerContext::AddSocketToList<br>SocketBrokerContext::CleanupSocket<br>SocketBrokerContext::CleanupSockets<br>SocketBrokerContext::CompleteRetrieveSocket<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::FindSocket<br>SocketBrokerContext::HandleWnsConnectNotifications<br>SocketBrokerContext::HandleWnsDisconnectNotifications<br>SocketBrokerContext::Initialize<br>SocketBrokerContext::IsLimitExceeded<br>SocketBrokerContext::NotifyApp<br>SocketBrokerContext::RetrieveContext<br>SocketBrokerContext::RetrieveSocket<br>SocketBrokerContext::SetBIEvent<br>SocketBrokerContext::TransferOwnership<br>SocketBrokerTable::Add<br>SocketBrokerTable::CleanAll<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::HandleWnsNotifications<br>SocketBrokerTable::Initialize<br>SocketBrokerTable::Remove<br>SocketBrokerTable::UpdateKeepAliveTimeout<br>SocketIoMonitor::Cleanup<br>SocketIoMonitor::GetDuplicatedSocket<br>SocketIoMonitor::HandleWaitCallback<br>SocketIoMonitor::Initialize<br>StubNlmCacheDeleteStoredValue<br>StubNlmCacheRetrieveStoredValue<br>StubNlmCacheStoreValue<br>TcpListener::CancelPendingIO<br>TcpListener::Cleanup<br>TcpListener::CreateAcceptSocket<br>TcpListener::HandleInComingConnection<br>TcpListener::Initialize<br>TcpListener::PostAccept<br>TcpListener::RetrieveAllSockets<br>TcpListener::RetrieveConnectedSocket<br>WorkQueueCallback<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|
|paramcount|1|1|
|`address`|EXTERNAL:00000064|EXTERNAL:0000005b|
|sig|void __stdcall EnterCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall EnterCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection calling
@@ -10,0 +11 @@
+KamDestroyTimer
```


## wil_details_IsEnabledFallback

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|3|4|
|length|146|146|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_2500799800__private_IsEnabledDeviceUsageNoInline<br>Feature_PackagedComElevationSupport_v2__private_IsEnabledFallback|Feature_2500799800__private_IsEnabledDeviceUsageNoInline<br>Feature_939503929__private_IsEnabledDeviceUsageNoInline<br>Feature_PackagedComElevationSupport_v2__private_IsEnabledFallback|
|paramcount|3|3|
|`address`|180022218|180021400|
|sig|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -1,0 +2 @@
+Feature_939503929__private_IsEnabledDeviceUsageNoInline
```


## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|LeaveCriticalSection|LeaveCriticalSection|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection|
|`refcount`|135|137|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>ATL::CRegObject::AddReplacement<br>ATL::CRegObject::ClearReplacements<br>ATL::CRegObject::StrFromMap<br>AppResurrectionManager::ShouldEventBeFired<br>CONTEXT_HANDLE_kapi_rundown<br>EnqueueWorkQueueItem<br>FindAndRemoveContextFromList<br>FindOrCreateControlChannelTriggerContext<br>KamDecreaseKeepAliveIntervalTime<br>KamGetSocketBrokerKeepAliveTime<br>KamSetKeepAliveIntervalTime</summary>KamSupressKeepaliveTimer<br>KamUpdateTimeEvent<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampNetworkStateChangeTpCallback<br>KampUpdateTimeEventHelper<br>KapiDeliverKaUpdate<br>KapiInitialize<br>KapiNetworkConnectivityChangeNotificationInternal<br>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiRegisterProvider<br>KapiUninitialize<br>KapiUpdateKaSample<br>NcbPolicyIsPackageSidAllowed<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenRemoveHandler<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicyWnfAppLockScreenUpdateHandler<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarAuthorizeOrCleanupContexts<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvGetCurrentKeepAliveInterval<br>RpcSrvIndicateSlotAllocation<br>RpcSrvStartBrokeredActivation<br>RpcSrvUsingTransport<br>SharedSocket::CreateCleanupTimer<br>SharedSocket::CreateKeepAliveTimer<br>SharedSocket::CreateRetryTriggerMonitor<br>SharedSocket::DeleteCleanupTimer<br>SharedSocket::DeleteKeepAliveTimer<br>SharedSocket::DeleteRetryTriggerTimer<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::GetSocketType<br>SharedSocket::HandleKeepAliveCallback<br>SharedSocket::Initialize<br>SharedSocket::InitializeSecurityFunctions<br>SocketBrokerContext::CompleteRetrieveSocket<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::FindSocket<br>SocketBrokerContext::Initialize<br>SocketBrokerContext::IsLimitExceeded<br>SocketBrokerContext::RetrieveContext<br>SocketBrokerContext::RetrieveSocket<br>SocketBrokerContext::TransferOwnership<br>SocketBrokerTable::Add<br>SocketBrokerTable::CleanAll<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::HandleWnsNotifications<br>SocketBrokerTable::Initialize<br>SocketBrokerTable::Remove<br>SocketBrokerTable::UpdateKeepAliveTimeout<br>SocketIoMonitor::GetDuplicatedSocket<br>SocketIoMonitor::HandleWaitCallback<br>SocketIoMonitor::Initialize<br>StubNlmCacheDeleteStoredValue<br>StubNlmCacheRetrieveStoredValue<br>StubNlmCacheStoreValue<br>TcpListener::CancelPendingIO<br>TcpListener::Cleanup<br>TcpListener::CreateAcceptSocket<br>TcpListener::HandleInComingConnection<br>TcpListener::Initialize<br>TcpListener::PostAccept<br>TcpListener::RetrieveAllSockets<br>TcpListener::RetrieveConnectedSocket<br>WorkQueueCallback<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(struct__RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_CRITICAL_SECTION*___ptr64,struct__RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(struct__RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_CRITICAL_SECTION*___ptr64,struct__RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_></details>|<details><summary>Expand for full list:<br>ATL::CRegObject::AddReplacement<br>ATL::CRegObject::ClearReplacements<br>ATL::CRegObject::StrFromMap<br>AppResurrectionManager::ShouldEventBeFired<br>CONTEXT_HANDLE_kapi_rundown<br>EnqueueWorkQueueItem<br>FindAndRemoveContextFromList<br>FindOrCreateControlChannelTriggerContext<br>KamDecreaseKeepAliveIntervalTime<br>KamDestroyTimer<br>KamGetSocketBrokerKeepAliveTime</summary>KamSetKeepAliveIntervalTime<br>KamSupressKeepaliveTimer<br>KamUpdateTimeEvent<br>KampCreateTimeEvent<br>KampKapiUpdateCallback<br>KampNetworkStateChangeTpCallback<br>KampUpdateTimeEventHelper<br>KapiDeliverKaUpdate<br>KapiInitialize<br>KapiNetworkConnectivityChangeNotificationInternal<br>KapiNotifyProviderAndCollectNotificationsRequestsUnderLock<br>KapiProcessUpdateRequest<br>KapiReceiveKaUpdateRequest<br>KapiRegisterProvider<br>KapiUninitialize<br>KapiUpdateKaSample<br>NcbPolicyIsPackageSidAllowed<br>NcbPolicyIsSlotTypeAvailable<br>NcbPolicyOnAppLockScreenRemoveHandler<br>NcbPolicyOnUserLogonHandler<br>NcbPolicyPowerStateChangeCallback<br>NcbPolicySessionChangeHandlerHelper<br>NcbPolicyWnfAppLockScreenUpdateHandler<br>NcbPolicyWnfUserLogonHandler<br>NcbRegistrarAuthorizeOrCleanupContexts<br>RpcSrvDecreaseKeepAliveInterval<br>RpcSrvGetCurrentKeepAliveInterval<br>RpcSrvIndicateSlotAllocation<br>RpcSrvStartBrokeredActivation<br>RpcSrvUsingTransport<br>SharedSocket::CreateCleanupTimer<br>SharedSocket::CreateKeepAliveTimer<br>SharedSocket::CreateRetryTriggerMonitor<br>SharedSocket::DeleteCleanupTimer<br>SharedSocket::DeleteKeepAliveTimer<br>SharedSocket::DeleteRetryTriggerTimer<br>SharedSocket::GetDuplicatedSocketPrivate<br>SharedSocket::GetSocketType<br>SharedSocket::HandleKeepAliveCallback<br>SharedSocket::Initialize<br>SharedSocket::InitializeSecurityFunctions<br>SocketBrokerContext::CompleteRetrieveSocket<br>SocketBrokerContext::CreatePushEnabledContext<br>SocketBrokerContext::EnumSockets<br>SocketBrokerContext::FindSocket<br>SocketBrokerContext::Initialize<br>SocketBrokerContext::IsLimitExceeded<br>SocketBrokerContext::RetrieveContext<br>SocketBrokerContext::RetrieveSocket<br>SocketBrokerContext::TransferOwnership<br>SocketBrokerTable::Add<br>SocketBrokerTable::CleanAll<br>SocketBrokerTable::EnumSockets<br>SocketBrokerTable::Find<br>SocketBrokerTable::HandleWnsNotifications<br>SocketBrokerTable::Initialize<br>SocketBrokerTable::Remove<br>SocketBrokerTable::UpdateKeepAliveTimeout<br>SocketIoMonitor::GetDuplicatedSocket<br>SocketIoMonitor::HandleWaitCallback<br>SocketIoMonitor::Initialize<br>StubNlmCacheDeleteStoredValue<br>StubNlmCacheRetrieveStoredValue<br>StubNlmCacheStoreValue<br>TcpListener::CancelPendingIO<br>TcpListener::Cleanup<br>TcpListener::CreateAcceptSocket<br>TcpListener::HandleInComingConnection<br>TcpListener::Initialize<br>TcpListener::PostAccept<br>TcpListener::RetrieveAllSockets<br>TcpListener::RetrieveConnectedSocket<br>WorkQueueCallback<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(struct__RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_CRITICAL_SECTION*___ptr64,struct__RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_CRITICAL_SECTION*___ptr64,void_(__cdecl*)(struct__RTL_CRITICAL_SECTION*___ptr64),&void___cdecl_LeaveCriticalSection(struct__RTL_CRITICAL_SECTION*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_CRITICAL_SECTION*___ptr64,struct__RTL_CRITICAL_SECTION*___ptr64,0,std::nullptr_t>_></details>|
|paramcount|1|1|
|`address`|EXTERNAL:0000005a|EXTERNAL:00000058|
|sig|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection Calling Diff


```diff
--- API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection calling
+++ API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection calling
@@ -9,0 +10 @@
+KamDestroyTimer
```


## wil_details_GetNtDllProcedureAddress

### Match Info



|Key|ncb_8972.dll - ncb_9168.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ncb_8972.dll|ncb_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_GetNtDllProcedureAddress|wil_details_GetNtDllProcedureAddress|
|fullname|wil_details_GetNtDllProcedureAddress|wil_details_GetNtDllProcedureAddress|
|`refcount`|7|5|
|length|39|39|
|called|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress<br>wil_details_GetNtDllModuleHandle|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress<br>wil_details_GetNtDllModuleHandle|
|`calling`|wil::details::RtlDllShutdownInProgress<br>wil::details::RtlNtStatusToDosErrorNoTeb<br>wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_><br>wil_details_NtQueryWnfStateData<br>wil_details_NtUpdateWnfStateData<br>wil_details_RtlRegisterFeatureConfigurationChangeNotification|wil::details::RtlDllShutdownInProgress<br>wil::details::RtlNtStatusToDosErrorNoTeb<br>wil_details_NtQueryWnfStateData<br>wil_details_NtUpdateWnfStateData|
|paramcount|1|1|
|`address`|18002b028|18002b6f8|
|sig|_func___int64 * __cdecl wil_details_GetNtDllProcedureAddress(char * param_1)|_func___int64 * __cdecl wil_details_GetNtDllProcedureAddress(char * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### wil_details_GetNtDllProcedureAddress Calling Diff


```diff
--- wil_details_GetNtDllProcedureAddress calling
+++ wil_details_GetNtDllProcedureAddress calling
@@ -3 +2,0 @@
-wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>
@@ -6 +4,0 @@
-wil_details_RtlRegisterFeatureConfigurationChangeNotification
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-21T23:25:53</sub>