# sstp_8875.dll-sstp_9168.dll Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
* [Modified](#modified)
	* [SstpWebReceiveResponseCompletion](#sstpwebreceiveresponsecompletion)
	* [wil_details_FeatureReporting_ReportUsageToServiceDirect](#wil_details_featurereporting_reportusagetoservicedirect)
	* [wil_details_FeatureReporting_ReportUsageToService](#wil_details_featurereporting_reportusagetoservice)
	* [Feature_1207409977__private_IsEnabledDeviceUsageNoInline](#feature_1207409977__private_isenableddeviceusagenoinline)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [ProxySendToRelatedCtx](#proxysendtorelatedctx)
	* [HttpThreadPoolRequestQueueCallback](#httpthreadpoolrequestqueuecallback)
	* [DisconnectServerHttpCallContext](#disconnectserverhttpcallcontext)
	* [wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath](#wil_details_featurestatecache_tryenabledeviceusagefastpath)
	* [IsProxyCall](#isproxycall)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection](#api-ms-win-core-synch-l1-1-0dllentercriticalsection)
	* [McTemplateU0z_EventWriteTransfer](#mctemplateu0z_eventwritetransfer)
	* [FormatRRASErrorString](#formatrraserrorstring)
	* [InitiateSstpResponse](#initiatesstpresponse)
	* [DereferenceRefCount](#dereferencerefcount)
	* [InitiateCallContextCleanup](#initiatecallcontextcleanup)
	* [IsProxyCall](#isproxycall)
	* [API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection](#api-ms-win-core-synch-l1-1-0dllleavecriticalsection)

# Visual Chart Diff



```mermaid

flowchart LR

SstpWebReceiveResponseCompletion-4-old<--Match 30%-->SstpWebReceiveResponseCompletion-4-new
wil_details_FeatureReporting_ReportUsageToServiceDirect-3-old<--Match 93%-->wil_details_FeatureReporting_ReportUsageToServiceDirect-3-new
wil_details_FeatureReporting_ReportUsageToService-3-old<--Match 94%-->wil_details_FeatureReporting_ReportUsageToService-3-new
Feature_1207409977__private_IsEnabledDeviceUsageNoInline-0-old<--Match 96%-->Feature_1207409977__private_IsEnabledDeviceUsageNoInline-0-new
wil_details_IsEnabledFallback-2-old<--Match 94%-->wil_details_IsEnabledFallback-2-new
ProxySendToRelatedCtx-4-old<--Match 90%-->ProxySendToRelatedCtx-4-new
HttpThreadPoolRequestQueueCallback-5-old<--Match 90%-->HttpThreadPoolRequestQueueCallback-5-new
DisconnectServerHttpCallContext-4-old<--Match 87%-->DisconnectServerHttpCallContext-4-new
wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath-2-old<--Match 90%-->wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath-2-new
IsProxyCall-1-old<--Match 26%-->Feature_2530182457__private_IsEnabledDeviceUsageNoInline-1-new

subgraph sstp_9168.dll
    SstpWebReceiveResponseCompletion-4-new
wil_details_FeatureReporting_ReportUsageToServiceDirect-3-new
wil_details_FeatureReporting_ReportUsageToService-3-new
Feature_1207409977__private_IsEnabledDeviceUsageNoInline-0-new
wil_details_IsEnabledFallback-2-new
ProxySendToRelatedCtx-4-new
HttpThreadPoolRequestQueueCallback-5-new
DisconnectServerHttpCallContext-4-new
wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath-2-new
Feature_2530182457__private_IsEnabledDeviceUsageNoInline-1-new
    
end

subgraph sstp_8875.dll
    SstpWebReceiveResponseCompletion-4-old
wil_details_FeatureReporting_ReportUsageToServiceDirect-3-old
wil_details_FeatureReporting_ReportUsageToService-3-old
Feature_1207409977__private_IsEnabledDeviceUsageNoInline-0-old
wil_details_IsEnabledFallback-2-old
ProxySendToRelatedCtx-4-old
HttpThreadPoolRequestQueueCallback-5-old
DisconnectServerHttpCallContext-4-old
wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath-2-old
IsProxyCall-1-old
    
end

```


```mermaid
pie showData
    title Function Matches - 100.0000%
"unmatched_funcs_len" : 0
"matched_funcs_len" : 1119
```



```mermaid
pie showData
    title Matched Function Similarity - 98.3914%
"matched_funcs_with_code_changes_len" : 10
"matched_funcs_with_non_code_changes_len" : 8
"matched_funcs_no_changes_len" : 1101
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 sstp_8875.dll sstp_9168.dll
```


#### Verbose Args


<details>

```
--old ['sstp_8875.dll'] --new [['sstp_9168.dll']] --engine VersionTrackingDiff --output-path sstp_out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/sstpsvc.dll/8BDAB75F2F000/sstpsvc.dll -O sstpsvc.dll.x64.10.0.26100.8875
wget https://msdl.microsoft.com/download/symbols/sstpsvc.dll/F73114F12F000/sstpsvc.dll -O sstpsvc.dll.x64.10.0.26100.9168
```


## Binary Metadata Diff


```diff
--- sstp_8875.dll Meta
+++ sstp_9168.dll Meta
@@ -1,44 +1,44 @@
-Program Name: sstp_8875.dll
+Program Name: sstp_9168.dll
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 180000000
 Maximum Address: ff0000184f
 # of Bytes: 198736
 # of Memory Blocks: 10
-# of Instructions: 21920
-# of Defined Data: 2122
-# of Functions: 559
-# of Symbols: 4500
+# of Instructions: 22099
+# of Defined Data: 2129
+# of Functions: 560
+# of Symbols: 4512
 # of Data Types: 510
 # of Data Type Categories: 38
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Fri Aug 21 23:50:18 SGT 2026
+Date Created: Fri Aug 21 23:50:22 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /tmp/sstp/sstp_8875.dll
-Executable MD5: 6e5e1f22f69a119fae24fc5bd9cd0348
-Executable SHA256: 416df55724c91f99087aa58f8dae317cc9851e8ebf7380ae0ccd9854567321d1
-FSRL: file:///tmp/sstp/sstp_8875.dll?MD5=6e5e1f22f69a119fae24fc5bd9cd0348
+Executable Location: /tmp/sstp/sstp_9168.dll
+Executable MD5: a7752b34daff4d147615fe875928e3b0
+Executable SHA256: ec9505519769d101b03ea6633b5ee013a08cda64de42249ee977d22a6ace00f6
+FSRL: file:///tmp/sstp/sstp_9168.dll?MD5=a7752b34daff4d147615fe875928e3b0
 PDB Age: 1
 PDB File: sstpsvc.pdb
-PDB GUID: 13199cac-cf56-d8b2-6603-5dac56989b3c
+PDB GUID: e4d5d24b-387e-8915-d6fa-7d82e6257d99
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN).
-PE Property[FileVersion]: 10.0.26100.8875 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.9168 (WinBuild.160101.0800)
 PE Property[InternalName]: sstpsvc.dll
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: sstpsvc.dll
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.8875
+PE Property[ProductVersion]: 10.0.26100.9168
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: true
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra sstp_8875.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra sstp_8875.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra sstp_8875.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra sstp_9168.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra sstp_9168.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra sstp_9168.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|0|
|deleted_funcs_len|0|
|modified_funcs_len|18|
|added_symbols_len|4|
|deleted_symbols_len|0|
|diff_time|4.4539079666137695|
|deleted_strings_len|0|
|added_strings_len|0|
|match_types|Counter({'SymbolsHash': 547, 'ExternalsName': 207, 'StructuralGraphHash': 4, 'ExactBytesFunctionHasher': 2, 'ExactInstructionsFunctionHasher': 1, 'Implied Match': 1})|
|items_to_process|22|
|diff_types|Counter({'address': 14, 'refcount': 10, 'code': 10, 'length': 10, 'called': 5, 'sig': 5, 'calling': 3, 'name': 1, 'fullname': 1})|
|unmatched_funcs_len|0|
|total_funcs_len|1119|
|matched_funcs_len|1119|
|matched_funcs_with_code_changes_len|10|
|matched_funcs_with_non_code_changes_len|8|
|matched_funcs_no_changes_len|1101|
|match_func_similarity_percent|98.3914%|
|func_match_overall_percent|100.0000%|
|first_matches|Counter({'SymbolsHash': 547, 'StructuralGraphHash': 4, 'ExactBytesFunctionHasher': 2, 'ExactInstructionsFunctionHasher': 1, 'Implied Match': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 547
"ExternalsName" : 207
"ExactBytesFunctionHasher" : 2
"ExactInstructionsFunctionHasher" : 1
"StructuralGraphHash" : 4
"Implied-Match" : 1
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 547
"ExactBytesFunctionHasher" : 2
"ExactInstructionsFunctionHasher" : 1
"StructuralGraphHash" : 4
"Implied-Match" : 1
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 0
"deleted_funcs_len" : 0
"modified_funcs_len" : 18
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 4
"deleted_symbols_len" : 0
```

## Strings


*No string differences found*

# Deleted

# Added

# Modified


*Modified functions contain code changes*
## SstpWebReceiveResponseCompletion

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.38|
|i_ratio|0.45|
|m_ratio|0.92|
|b_ratio|0.3|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|SstpWebReceiveResponseCompletion|SstpWebReceiveResponseCompletion|
|fullname|SstpWebReceiveResponseCompletion|SstpWebReceiveResponseCompletion|
|refcount|4|4|
|`length`|2877|3358|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CloseThreadpoolTimer<br>AcquireHostRouteInfoContext<br>CRYPT32.DLL::CertFreeCertificateContext<br>ConvertCorrelationIdToWideChar<br>DereferenceRefCount<br>FormatRRASErrorString<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>IsProxyCall</summary>LogEventWithErrorParameter<br>McTemplateU0z_EventWriteTransfer<br>NotifyMakeCallComplete<br>PRXYQRY.DLL::GetLinkSpeedForAddress<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>RTUTILS.DLL::RouterLogEventDataW<br>RTUTILS.DLL::RouterLogEventStringW<br>SSTPCFG.DLL::GetHashFromCertificate<br>SSTPCFG.DLL::IsCertificateEKUServerAuth<br>StringCbPrintfW<br>WEBIO.DLL::Ordinal_18<br>WEBIO.DLL::Ordinal_21<br>WEBIO.DLL::Ordinal_22<br>__security_check_cookie<br>memset</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CloseThreadpoolTimer<br>AcquireHostRouteInfoContext<br>CRYPT32.DLL::CertFreeCertificateContext<br>ConvertCorrelationIdToWideChar<br>DereferenceRefCount<br>Feature_2530182457__private_IsEnabledDeviceUsageNoInline<br>FormatRRASErrorString<br>InitiateCallContextCleanup<br>InitiateSstpResponse</summary>IsProxyCall<br>LogEventWithErrorParameter<br>McTemplateU0z_EventWriteTransfer<br>NotifyMakeCallComplete<br>PRXYQRY.DLL::GetLinkSpeedForAddress<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>RTUTILS.DLL::RouterLogEventDataW<br>RTUTILS.DLL::RouterLogEventStringW<br>SSTPCFG.DLL::GetHashFromCertificate<br>SSTPCFG.DLL::IsCertificateEKUServerAuth<br>StringCbPrintfW<br>WEBIO.DLL::Ordinal_18<br>WEBIO.DLL::Ordinal_21<br>WEBIO.DLL::Ordinal_22<br>__security_check_cookie<br>memset</details>|
|calling|SstpWebSendRequestCompletion|SstpWebSendRequestCompletion|
|paramcount|4|4|
|`address`|18000f870|18000f9c0|
|sig|undefined __fastcall SstpWebReceiveResponseCompletion(ulonglong param_1, uint param_2, undefined8 param_3, uint * param_4)|undefined __fastcall SstpWebReceiveResponseCompletion(ulonglong param_1, uint param_2, undefined8 param_3, uint * param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### SstpWebReceiveResponseCompletion Called Diff


```diff
--- SstpWebReceiveResponseCompletion called
+++ SstpWebReceiveResponseCompletion called
@@ -7,0 +8 @@
+Feature_2530182457__private_IsEnabledDeviceUsageNoInline
```


### SstpWebReceiveResponseCompletion Diff


```diff
--- SstpWebReceiveResponseCompletion
+++ SstpWebReceiveResponseCompletion
@@ -1,440 +1,526 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 void SstpWebReceiveResponseCompletion
                (ulonglong param_1,uint param_2,undefined8 param_3,uint *param_4)
 
 {
   LPCRITICAL_SECTION lpCriticalSection;
   longlong lVar1;
   bool bVar2;
-  char cVar3;
-  uint uVar4;
+  bool bVar3;
+  char cVar4;
   uint uVar5;
+  uint uVar6;
+  int iVar7;
   undefined7 extraout_var;
   undefined7 extraout_var_00;
   undefined7 extraout_var_01;
   undefined7 extraout_var_02;
-  undefined4 *puVar6;
-  wchar_t *pwVar7;
-  wchar_t *pwVar8;
-  PCCERT_CONTEXT *ppCVar9;
-  uint *puVar10;
-  undefined1 auStack_a28 [32];
-  undefined8 local_a08;
-  ulonglong local_a00;
-  undefined4 *local_9f8;
-  ushort local_9e8 [2];
-  undefined4 local_9e4;
-  int local_9e0 [2];
-  WCHAR *local_9d8;
-  wchar_t *local_9d0;
-  PCCERT_CONTEXT local_9c8;
-  WCHAR *local_9c0;
-  undefined8 local_9b8;
-  undefined1 local_9a8 [128];
-  ushort local_928 [64];
-  wchar_t local_8a8 [16];
+  undefined7 extraout_var_03;
+  undefined7 extraout_var_04;
+  undefined4 *puVar8;
+  wchar_t *pwVar9;
+  longlong lVar10;
+  wchar_t *pwVar11;
+  PCCERT_CONTEXT *ppCVar12;
+  uint *puVar13;
+  undefined1 auStack_b18 [32];
+  undefined8 local_af8;
+  ulonglong local_af0;
+  undefined4 *local_ae8;
+  ushort local_ad8 [2];
+  undefined4 local_ad4;
+  int local_ad0 [2];
+  WCHAR *local_ac8;
+  wchar_t *local_ac0;
+  PCCERT_CONTEXT local_ab8;
+  WCHAR *local_ab0;
+  undefined8 local_aa8;
+  undefined1 local_a98 [128];
+  ushort local_a18 [64];
+  wchar_t local_998 [16];
+  WCHAR local_978 [40];
+  WCHAR local_928 [40];
+  WCHAR local_8d8 [40];
   WCHAR local_888 [40];
   undefined8 local_838;
   ulonglong local_38;
   
-  local_38 = __security_cookie ^ (ulonglong)auStack_a28;
-  pwVar7 = (wchar_t *)0x0;
+  local_38 = __security_cookie ^ (ulonglong)auStack_b18;
+  pwVar9 = (wchar_t *)0x0;
   local_838._0_4_ = 0;
-  pwVar8 = (wchar_t *)0x7fc;
+  pwVar11 = (wchar_t *)0x7fc;
   memset((void *)((longlong)&local_838 + 4),0,0x7fc);
   lpCriticalSection = (LPCRITICAL_SECTION)(param_1 + 0x120);
   EnterCriticalSection(lpCriticalSection);
   *(undefined1 *)(param_1 + 0x1d0) = 1;
   CloseThreadpoolTimer(*(PTP_TIMER *)(param_1 + 0x1c8));
   *(undefined8 *)(param_1 + 0x1c8) = 0;
   if ((param_2 == 0) && (*(char *)(param_1 + 0x1b3) == '\0')) {
-    local_9e4 = 0;
-    local_9e8[0] = 0;
+    local_ad4 = 0;
+    local_ad8[0] = 0;
     LeaveCriticalSection(lpCriticalSection);
-    puVar6 = &local_9e4;
-    uVar4 = Ordinal_22(*(undefined8 *)(param_1 + 0x1c0));
-    puVar10 = (uint *)(ulonglong)uVar4;
-    if (uVar4 != 0) {
-      ppCVar9 = (PCCERT_CONTEXT *)(param_1 + 0x228);
-      pwVar8 = (wchar_t *)ppCVar9;
-      ConvertCorrelationIdToWideChar(local_888,puVar6,(LPCSTR)ppCVar9);
-      local_9d8 = local_888;
+    puVar8 = &local_ad4;
+    uVar5 = Ordinal_22(*(undefined8 *)(param_1 + 0x1c0));
+    puVar13 = (uint *)(ulonglong)uVar5;
+    if (uVar5 != 0) {
+      ppCVar12 = (PCCERT_CONTEXT *)(param_1 + 0x228);
+      pwVar11 = (wchar_t *)ppCVar12;
+      ConvertCorrelationIdToWideChar(local_978,puVar8,(LPCSTR)ppCVar12);
+      local_ac8 = local_978;
       if (*(longlong *)(SstpSvcGlobals + 0x48) != 0) {
-        local_9f8 = &local_9e4;
+        local_ae8 = &local_ad4;
         param_4 = (uint *)0x1;
-        pwVar8 = (wchar_t *)0x3;
-        local_a08 = (wchar_t *)&local_9d8;
-        local_a00 = CONCAT44(local_a00._4_4_,4);
+        pwVar11 = (wchar_t *)0x3;
+        local_af8 = (wchar_t *)&local_ac8;
+        local_af0 = CONCAT44(local_af0._4_4_,4);
         RouterLogEventDataW(*(longlong *)(SstpSvcGlobals + 0x48),1);
       }
       if ((DAT_0 & 8) != 0) {
         local_838._0_4_ = (uint)local_838 & 0xffff0000;
-        FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x180020000,(size_t *)ppCVar9,puVar10);
-        pwVar8 = (wchar_t *)ppCVar9;
-        param_4 = puVar10;
-        if ((DAT_0 & 8) != 0) {
-          pwVar8 = (wchar_t *)&local_838;
+        FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x180020000,(size_t *)ppCVar12,puVar13);
+        pwVar11 = (wchar_t *)ppCVar12;
+        param_4 = puVar13;
+        if ((DAT_0 & 8) != 0) {
+          pwVar11 = (wchar_t *)&local_838;
           McTemplateU0z_EventWriteTransfer
                     (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                     (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar8);
-          param_4 = puVar10;
+                     (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar11);
+          param_4 = puVar13;
         }
       }
 LAB_1:
-      bVar2 = IsProxyCall(param_1);
-      if (((int)CONCAT71(extraout_var,bVar2) != 0) && ((*(byte *)(param_1 + 0x268) & 1) != 0)) {
-        lVar1 = *(longlong *)(param_1 + 0x270);
-        EnterCriticalSection((LPCRITICAL_SECTION)(lVar1 + 0x120));
-        *(uint *)(lVar1 + 0xfc) = *(uint *)(lVar1 + 0xfc) & 0xffffffef;
-        LeaveCriticalSection((LPCRITICAL_SECTION)(lVar1 + 0x120));
-        DereferenceRefCount((int *)(lVar1 + 0xd0));
-      }
-      EnterCriticalSection(lpCriticalSection);
+      lVar10 = 0;
+      uVar6 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+      if (uVar6 == 0) {
+        bVar2 = IsProxyCall(param_1);
+        if (((int)CONCAT71(extraout_var_01,bVar2) != 0) && ((*(byte *)(param_1 + 0x268) & 1) != 0))
+        {
+          lVar10 = *(longlong *)(param_1 + 0x270);
+          EnterCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+          *(uint *)(lVar10 + 0xfc) = *(uint *)(lVar10 + 0xfc) & 0xffffffef;
+          LeaveCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+          goto LAB_2;
+        }
+      }
+      else {
+        EnterCriticalSection(lpCriticalSection);
+        bVar2 = IsProxyCall(param_1);
+        if ((((int)CONCAT71(extraout_var,bVar2) != 0) && ((*(byte *)(param_1 + 0x268) & 1) != 0)) &&
+           (lVar1 = *(longlong *)(param_1 + 0x270), lVar1 != 0)) {
+          LOCK();
+          *(int *)(lVar1 + 0xd0) = *(int *)(lVar1 + 0xd0) + 1;
+          UNLOCK();
+          lVar10 = lVar1;
+        }
+        LeaveCriticalSection(lpCriticalSection);
+        if (lVar10 != 0) {
+          EnterCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+          uVar6 = *(uint *)(lVar10 + 0xfc);
+          *(uint *)(lVar10 + 0xfc) = uVar6 & 0xffffffef;
+          LeaveCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+          if ((uVar6 & 0x10) != 0) {
+            DereferenceRefCount((int *)(lVar10 + 0xd0));
+          }
+LAB_2:
+          DereferenceRefCount((int *)(lVar10 + 0xd0));
+        }
+      }
+      EnterCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
       *(uint *)(param_1 + 0xfc) = *(uint *)(param_1 + 0xfc) & 0xfffeffff;
-      *(uint *)(param_1 + 0x10c) = uVar4;
-      goto LAB_2;
-    }
-    if (((ushort)local_9e4 != 1) && (local_9e4._2_2_ != 1)) {
-      ppCVar9 = (PCCERT_CONTEXT *)(param_1 + 0x228);
-      pwVar8 = (wchar_t *)ppCVar9;
-      ConvertCorrelationIdToWideChar(local_888,puVar6,(LPCSTR)ppCVar9);
-      local_9d8 = local_888;
-      uVar4 = 0x32;
+      *(uint *)(param_1 + 0x10c) = uVar5;
+      goto LAB_3;
+    }
+    if (((ushort)local_ad4 != 1) && (local_ad4._2_2_ != 1)) {
+      ppCVar12 = (PCCERT_CONTEXT *)(param_1 + 0x228);
+      pwVar11 = (wchar_t *)ppCVar12;
+      ConvertCorrelationIdToWideChar(local_928,puVar8,(LPCSTR)ppCVar12);
+      local_ac8 = local_928;
+      uVar5 = 0x32;
       if ((DAT_0 & 8) != 0) {
-        param_4 = (uint *)(ulonglong)(ushort)local_9e4;
-        local_a00 = CONCAT44(local_a00._4_4_,0x32);
-        local_a08 = (wchar_t *)CONCAT44(local_a08._4_4_,local_9e4 >> 0x10);
+        param_4 = (uint *)(ulonglong)(ushort)local_ad4;
+        local_af0 = CONCAT44(local_af0._4_4_,0x32);
+        local_af8 = (wchar_t *)CONCAT44(local_af8._4_4_,local_ad4 >> 0x10);
         local_838._0_4_ = (uint)local_838 & 0xffff0000;
-        FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x180020060,(size_t *)ppCVar9,param_4);
-        pwVar8 = (wchar_t *)ppCVar9;
-        if ((DAT_0 & 8) != 0) {
-          pwVar8 = (wchar_t *)&local_838;
+        FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x180020060,(size_t *)ppCVar12,param_4);
+        pwVar11 = (wchar_t *)ppCVar12;
+        if ((DAT_0 & 8) != 0) {
+          pwVar11 = (wchar_t *)&local_838;
           McTemplateU0z_EventWriteTransfer
                     (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                     (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar8);
+                     (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar11);
         }
       }
       if (*(longlong *)(SstpSvcGlobals + 0x48) != 0) {
-        local_9f8 = &local_9e4;
+        local_ae8 = &local_ad4;
         param_4 = (uint *)0x1;
-        pwVar8 = (wchar_t *)0x3;
-        local_a08 = (wchar_t *)&local_9d8;
-        local_a00 = CONCAT44(local_a00._4_4_,4);
+        pwVar11 = (wchar_t *)0x3;
+        local_af8 = (wchar_t *)&local_ac8;
+        local_af0 = CONCAT44(local_af0._4_4_,4);
         RouterLogEventDataW(*(longlong *)(SstpSvcGlobals + 0x48),1);
       }
       goto LAB_1;
     }
-    uVar4 = Ordinal_21(*(undefined8 *)(param_1 + 0x1c0),local_9e8);
-    param_4 = (uint *)(ulonglong)local_9e8[0];
-    pwVar8 = L"%-d";
-    pwVar7 = (wchar_t *)0x18;
-    puVar10 = (uint *)(ulonglong)uVar4;
-    StringCbPrintfW(local_8a8,0x18,L"%-d");
-    if (uVar4 != 0) {
-      local_9d8 = local_8a8;
+    uVar5 = Ordinal_21(*(undefined8 *)(param_1 + 0x1c0),local_ad8);
+    param_4 = (uint *)(ulonglong)local_ad8[0];
+    pwVar11 = L"%-d";
+    pwVar9 = (wchar_t *)0x18;
+    puVar13 = (uint *)(ulonglong)uVar5;
+    StringCbPrintfW(local_998,0x18,L"%-d");
+    bVar2 = false;
+    if (uVar5 != 0) {
+      local_ac8 = local_998;
       if (*(longlong *)(SstpSvcGlobals + 0x48) != 0) {
-        local_9f8 = (undefined4 *)0x0;
-        local_a08 = (wchar_t *)&local_9d8;
-        local_a00 = local_a00 & 0xffffffff00000000;
+        local_ae8 = (undefined4 *)0x0;
+        local_af8 = (wchar_t *)&local_ac8;
+        local_af0 = local_af0 & 0xffffffff00000000;
         param_4 = (uint *)0x1;
-        pwVar8 = (wchar_t *)0x4;
+        pwVar11 = (wchar_t *)0x4;
         RouterLogEventDataW(*(longlong *)(SstpSvcGlobals + 0x48),1);
       }
       if ((DAT_0 & 8) != 0) {
-        pwVar8 = (wchar_t *)(param_1 + 0x228);
+        pwVar11 = (wchar_t *)(param_1 + 0x228);
         local_838._0_4_ = (uint)local_838 & 0xffff0000;
-        FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x1800200d0,(size_t *)pwVar8,puVar10);
-        param_4 = puVar10;
-        if ((DAT_0 & 8) != 0) {
-          pwVar8 = (wchar_t *)&local_838;
+        FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x1800200d0,(size_t *)pwVar11,puVar13);
+        param_4 = puVar13;
+        if ((DAT_0 & 8) != 0) {
+          pwVar11 = (wchar_t *)&local_838;
           McTemplateU0z_EventWriteTransfer
                     (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                     (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar8);
-          param_4 = puVar10;
+                     (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar11);
+          param_4 = puVar13;
         }
       }
       goto LAB_1;
     }
-    if (local_9e8[0] == 200) {
-      local_9d8 = (WCHAR *)0x0;
-      memset(local_9a8,0,0x100);
-      local_a08 = (wchar_t *)&local_9d8;
+    if (local_ad8[0] == 200) {
+      local_ac8 = (WCHAR *)0x0;
+      memset(local_a98,0,0x100);
+      local_af8 = (wchar_t *)&local_ac8;
       param_4 = (uint *)0x100;
-      local_9c8 = (PCCERT_CONTEXT)0x0;
-      pwVar8 = (wchar_t *)0x16;
-      uVar4 = Ordinal_18(*(undefined8 *)(param_1 + 0x1c0),0x16,local_9a8);
-      if (uVar4 == 0) {
-        uVar4 = GetLinkSpeedForAddress
-                          (local_9a8,(longlong *)(param_1 + 0x1d8),(ulonglong *)(param_1 + 0x1e0));
-        if ((DAT_0 & 8) != 0) {
-          local_a00 = *(ulonglong *)(param_1 + 0x1e0);
-          local_a08 = *(wchar_t **)(param_1 + 0x1d8);
-          param_4 = (uint *)(ulonglong)uVar4;
+      local_ab8 = (PCCERT_CONTEXT)0x0;
+      pwVar11 = (wchar_t *)0x16;
+      uVar5 = Ordinal_18(*(undefined8 *)(param_1 + 0x1c0),0x16,local_a98);
+      if (uVar5 == 0) {
+        uVar5 = GetLinkSpeedForAddress
+                          (local_a98,(longlong *)(param_1 + 0x1d8),(ulonglong *)(param_1 + 0x1e0));
+        if ((DAT_0 & 8) != 0) {
+          local_af0 = *(ulonglong *)(param_1 + 0x1e0);
+          local_af8 = *(wchar_t **)(param_1 + 0x1d8);
+          param_4 = (uint *)(ulonglong)uVar5;
           local_838._0_4_ = (uint)local_838 & 0xffff0000;
           FormatRRASErrorString
                     ((STRSAFE_LPWSTR)&local_838,0x18001f530,(size_t *)(param_1 + 0x228),param_4);
           if ((DAT_0 & 8) != 0) {
             McTemplateU0z_EventWriteTransfer
                       (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                        (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)&local_838);
           }
         }
       }
       else {
         if ((DAT_0 & 8) != 0) {
           local_838._0_4_ = (uint)local_838 & 0xffff0000;
-          pwVar8 = L"CoId=%hs:Unable to query the endpoint addr: %d";
+          pwVar11 = L"CoId=%hs:Unable to query the endpoint addr: %d";
           FormatRRASErrorString
                     ((STRSAFE_LPWSTR)&local_838,0x180020260,(size_t *)(param_1 + 0x228),
-                     (ulonglong)uVar4);
+                     (ulonglong)uVar5);
           if ((DAT_0 & 8) != 0) {
-            pwVar8 = L"㚰က\x02";
+            pwVar11 = L"㚰က\x02";
             McTemplateU0z_EventWriteTransfer
                       (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                        (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)&local_838);
           }
         }
         param_4 = (uint *)0x0;
-        LogEventWithErrorParameter(0xf,pwVar8,uVar4,(LPCSTR)0x0);
-      }
-      pwVar8 = (wchar_t *)(param_1 + 0x260);
-      pwVar7 = (wchar_t *)(param_1 + 0x220);
-      uVar4 = AcquireHostRouteInfoContext
-                        (local_928,(undefined8 *)pwVar7,(PNET_IFINDEX)pwVar8,param_4);
-      ppCVar9 = (PCCERT_CONTEXT *)(ulonglong)uVar4;
-      if (uVar4 != 0) {
+        LogEventWithErrorParameter(0xf,pwVar11,uVar5,(LPCSTR)0x0);
+      }
+      pwVar11 = (wchar_t *)(param_1 + 0x260);
+      pwVar9 = (wchar_t *)(param_1 + 0x220);
+      uVar5 = AcquireHostRouteInfoContext
+                        (local_a18,(undefined8 *)pwVar9,(PNET_IFINDEX)pwVar11,param_4);
+      ppCVar12 = (PCCERT_CONTEXT *)(ulonglong)uVar5;
+      if (uVar5 != 0) {
         if ((DAT_0 & 8) != 0) {
           local_838._0_4_ = (uint)local_838 & 0xffff0000;
-          pwVar7 = L"CoId=%hs: AcquireHostRouteInfoContext failed with error=%d";
+          pwVar9 = L"CoId=%hs: AcquireHostRouteInfoContext failed with error=%d";
           FormatRRASErrorString
                     ((STRSAFE_LPWSTR)&local_838,0x1800202c0,(size_t *)(param_1 + 0x228),
-                     (ulonglong)uVar4);
+                     (ulonglong)uVar5);
           if ((DAT_0 & 8) != 0) {
-            pwVar7 = L"㚰က\x02";
+            pwVar9 = L"㚰က\x02";
             McTemplateU0z_EventWriteTransfer
                       (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                        (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)&local_838);
           }
         }
         param_4 = (uint *)0x0;
-        LogEventWithErrorParameter(0xe,pwVar7,uVar4,(LPCSTR)0x0);
-        pwVar8 = (wchar_t *)ppCVar9;
+        LogEventWithErrorParameter(0xe,pwVar9,uVar5,(LPCSTR)0x0);
+        pwVar11 = (wchar_t *)ppCVar12;
       }
       if (*(int *)(param_1 + 0x264) != 0) {
-        local_a08 = (wchar_t *)&local_9d8;
+        local_af8 = (wchar_t *)&local_ac8;
         param_4 = (uint *)0x8;
-        pwVar8 = (wchar_t *)&local_9c8;
-        pwVar7 = (wchar_t *)0x13;
-        uVar4 = Ordinal_18(*(undefined8 *)(param_1 + 0x1c0));
-        if (uVar4 == 0) {
-          pwVar7 = (wchar_t *)local_9e0;
-          local_9e0[0] = 0;
-          IsCertificateEKUServerAuth(local_9c8);
-          if (local_9e0[0] == 0) {
-            pwVar8 = (wchar_t *)(param_1 + 0x228);
-            ConvertCorrelationIdToWideChar(local_888,pwVar7,(LPCSTR)pwVar8);
-            local_9c0 = local_888;
-            local_9b8 = 0;
-            uVar4 = 0x80090349;
+        pwVar11 = (wchar_t *)&local_ab8;
+        pwVar9 = (wchar_t *)0x13;
+        uVar5 = Ordinal_18(*(undefined8 *)(param_1 + 0x1c0));
+        if (uVar5 == 0) {
+          pwVar9 = (wchar_t *)local_ad0;
+          local_ad0[0] = 0;
+          IsCertificateEKUServerAuth(local_ab8);
+          if (local_ad0[0] == 0) {
+            pwVar11 = (wchar_t *)(param_1 + 0x228);
+            ConvertCorrelationIdToWideChar(local_888,pwVar9,(LPCSTR)pwVar11);
+            local_ab0 = local_888;
+            local_aa8 = 0;
+            uVar5 = 0x80090349;
             if (*(longlong *)(SstpSvcGlobals + 0x48) != 0) {
-              local_9f8 = (undefined4 *)((ulonglong)local_9f8 & 0xffffffff00000000);
-              local_a08 = (wchar_t *)&local_9c0;
-              local_a00 = CONCAT44(local_a00._4_4_,0x80090349);
+              local_ae8 = (undefined4 *)((ulonglong)local_ae8 & 0xffffffff00000000);
+              local_af8 = (wchar_t *)&local_ab0;
+              local_af0 = CONCAT44(local_af0._4_4_,0x80090349);
               param_4 = (uint *)0x1;
-              pwVar8 = (wchar_t *)0x10;
-              pwVar7 = (wchar_t *)0x1;
+              pwVar11 = (wchar_t *)0x10;
+              pwVar9 = (wchar_t *)0x1;
               RouterLogEventStringW();
             }
             if ((DAT_0 & 8) != 0) {
               param_4 = (uint *)0x80090349;
-              pwVar7 = 
+              pwVar9 = 
               L"CoId=%hs: Invalid EKU for server certificate, CertUsage=CERT_EKU_NON_SSTP, Status=%d"
               ;
-              uVar4 = 0x80090349;
-LAB_3:
-              pwVar8 = (wchar_t *)(param_1 + 0x228);
+              uVar5 = 0x80090349;
+LAB_4:
+              pwVar11 = (wchar_t *)(param_1 + 0x228);
               local_838._0_4_ = (uint)local_838 & 0xffff0000;
               FormatRRASErrorString
-                        ((STRSAFE_LPWSTR)&local_838,(size_t)pwVar7,(size_t *)pwVar8,param_4);
+                        ((STRSAFE_LPWSTR)&local_838,(size_t)pwVar9,(size_t *)pwVar11,param_4);
               if ((DAT_0 & 8) != 0) {
-                pwVar8 = (wchar_t *)&local_838;
-                pwVar7 = L"㚰က\x02";
+                pwVar11 = (wchar_t *)&local_838;
+                pwVar9 = L"㚰က\x02";
                 McTemplateU0z_EventWriteTransfer
                           (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                           (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar8);
+                           (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar11);
               }
             }
           }
           else {
             param_4 = (uint *)(param_1 + 0x1fd);
-            pwVar8 = (wchar_t *)(param_1 + 0x1e9);
+            pwVar11 = (wchar_t *)(param_1 + 0x1e9);
             *(undefined1 *)(param_1 + 0x1e8) = 2;
-            pwVar7 = (wchar_t *)CONCAT71((int7)((ulonglong)pwVar7 >> 8),3);
-            uVar5 = GetHashFromCertificate(local_9c8);
-            if ((uVar5 != 0) && (*(undefined1 *)(param_1 + 0x1e8) = 0, (DAT_0 & 8) != 0)) {
-              param_4 = (uint *)(ulonglong)uVar5;
-              pwVar7 = L"CoId=%hs:GetHashFromCertificate fails with error %d";
-              goto LAB_3;
+            pwVar9 = (wchar_t *)CONCAT71((int7)((ulonglong)pwVar9 >> 8),3);
+            uVar6 = GetHashFromCertificate(local_ab8);
+            if ((uVar6 != 0) && (*(undefined1 *)(param_1 + 0x1e8) = 0, (DAT_0 & 8) != 0)) {
+              param_4 = (uint *)(ulonglong)uVar6;
+              pwVar9 = L"CoId=%hs:GetHashFromCertificate fails with error %d";
+              goto LAB_4;
             }
           }
-          CertFreeCertificateContext(local_9c8);
+          CertFreeCertificateContext(local_ab8);
         }
         else if ((DAT_0 & 8) != 0) {
-          pwVar8 = (wchar_t *)(param_1 + 0x228);
+          pwVar11 = (wchar_t *)(param_1 + 0x228);
           local_838._0_4_ = (uint)local_838 & 0xffff0000;
-          param_4 = (uint *)(ulonglong)uVar4;
-          pwVar7 = L"CoId=%hs:Unable to query the server certificate: %d";
-          FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x180020340,(size_t *)pwVar8,param_4);
+          param_4 = (uint *)(ulonglong)uVar5;
+          pwVar9 = L"CoId=%hs:Unable to query the server certificate: %d";
+          FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x180020340,(size_t *)pwVar11,param_4);
           if ((DAT_0 & 8) != 0) {
-            pwVar8 = (wchar_t *)&local_838;
-            pwVar7 = L"㚰က\x02";
-            McTemplateU0z_EventWriteTransfer
-                      (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                       (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar8);
+            pwVar11 = (wchar_t *)&local_838;
+            pwVar9 = L"㚰က\x02";
+            McTemplateU0z_EventWriteTransfer
+                      (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
+                       (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar11);
           }
         }
       }
     }
     else {
       param_4 = (uint *)0x197;
-      if (local_9e8[0] == 0x197) {
-        uVar5 = 0x17;
+      if (local_ad8[0] == 0x197) {
+        uVar6 = 0x17;
         if ((DAT_0 & 8) != 0) {
           local_838._0_4_ = (uint)local_838._2_2_ << 0x10;
-          pwVar7 = 
+          pwVar9 = 
           L"CoId=%hs:Received error from the remote site: %d. Mapping it to ERROR_ACCESS_DENIED.";
           FormatRRASErrorString
                     ((STRSAFE_LPWSTR)&local_838,0x180020140,(size_t *)(param_1 + 0x228),0x197);
           if ((DAT_0 & 8) != 0) {
-            pwVar7 = L"㚰က\x02";
+            pwVar9 = L"㚰က\x02";
             McTemplateU0z_EventWriteTransfer
                       (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                        (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)&local_838);
           }
         }
-        uVar4 = 5;
+        uVar5 = 5;
       }
       else {
-        uVar5 = 4;
-        if ((DAT_0 & 8) != 0) {
-          param_4 = (uint *)(ulonglong)local_9e8[0];
+        uVar6 = 4;
+        if ((DAT_0 & 8) != 0) {
+          param_4 = (uint *)(ulonglong)local_ad8[0];
           local_838._0_4_ = (uint)local_838._2_2_ << 0x10;
-          pwVar7 = L"CoId=%hs:Received error from the remote site: %d";
+          pwVar9 = L"CoId=%hs:Received error from the remote site: %d";
           FormatRRASErrorString
                     ((STRSAFE_LPWSTR)&local_838,0x1800201f0,(size_t *)(param_1 + 0x228),param_4);
           if ((DAT_0 & 8) != 0) {
-            pwVar7 = L"㚰က\x02";
+            pwVar9 = L"㚰က\x02";
             McTemplateU0z_EventWriteTransfer
                       (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                        (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)&local_838);
           }
         }
-        uVar4 = 0x4d4;
-      }
-      pwVar8 = (wchar_t *)(param_1 + 0x228);
-      ConvertCorrelationIdToWideChar(local_888,pwVar7,(LPCSTR)pwVar8);
-      local_9d8 = local_888;
-      local_9d0 = local_8a8;
+        uVar5 = 0x4d4;
+      }
+      pwVar11 = (wchar_t *)(param_1 + 0x228);
+      ConvertCorrelationIdToWideChar(local_8d8,pwVar9,(LPCSTR)pwVar11);
+      local_ac8 = local_8d8;
+      local_ac0 = local_998;
       if (*(longlong *)(SstpSvcGlobals + 0x48) != 0) {
-        local_9f8 = (undefined4 *)0x0;
-        local_a08 = (wchar_t *)&local_9d8;
-        local_a00 = local_a00 & 0xffffffff00000000;
+        local_ae8 = (undefined4 *)0x0;
+        local_af8 = (wchar_t *)&local_ac8;
+        local_af0 = local_af0 & 0xffffffff00000000;
         param_4 = (uint *)0x2;
-        pwVar8 = (wchar_t *)(ulonglong)uVar5;
-        pwVar7 = (wchar_t *)0x1;
+        pwVar11 = (wchar_t *)(ulonglong)uVar6;
+        pwVar9 = (wchar_t *)0x1;
         RouterLogEventDataW();
       }
     }
-    if (uVar4 != 0) goto LAB_1;
+    if (uVar5 != 0) goto LAB_1;
+    uVar5 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+    if (uVar5 == 0) {
+      bVar2 = IsProxyCall(param_1);
+      if ((int)CONCAT71(extraout_var_04,bVar2) != 0) {
+        if ((*(byte *)(param_1 + 0x268) & 1) == 0) goto LAB_5;
+        lVar10 = *(longlong *)(param_1 + 0x270);
+        EnterCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+        if ((DAT_0 & 0x10) != 0) {
+          pwVar11 = (wchar_t *)(lVar10 + 0x228);
+          local_838._0_4_ = (uint)local_838 & 0xffff0000;
+          pwVar9 = L"CoId=%hs:Incoming call accepted";
+          FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x18001dc20,(size_t *)pwVar11,param_4);
+          if ((DAT_0 & 0x10) != 0) {
+            pwVar11 = (wchar_t *)&local_838;
+            pwVar9 = L"㚱က\x04";
+            McTemplateU0z_EventWriteTransfer
+                      (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
+                       (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,pwVar11);
+          }
+        }
+        *(uint *)(lVar10 + 0xfc) = *(uint *)(lVar10 + 0xfc) & 0xffffffef | 0x20;
+        LeaveCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+        InitiateSstpResponse(lVar10,pwVar9,pwVar11,param_4);
+        goto LAB_6;
+      }
+LAB_7:
+      PostSendNotificationRequest(param_1,pwVar9,pwVar11,(ulonglong)param_4);
+    }
+    else {
+      EnterCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
+      bVar3 = IsProxyCall(param_1);
+      iVar7 = (int)CONCAT71(extraout_var_00,bVar3);
+      lVar10 = 0;
+      if (((iVar7 != 0) && ((*(byte *)(param_1 + 0x268) & 1) != 0)) &&
+         (lVar1 = *(longlong *)(param_1 + 0x270), lVar10 = 0, lVar1 != 0)) {
+        LOCK();
+        *(int *)(lVar1 + 0xd0) = *(int *)(lVar1 + 0xd0) + 1;
+        UNLOCK();
+        lVar10 = lVar1;
+      }
+      LeaveCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
+      if (lVar10 == 0) {
+        if (iVar7 == 0) goto LAB_7;
+      }
+      else {
+        EnterCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+        if ((*(byte *)(lVar10 + 0xfc) & 0x10) != 0) {
+          if ((DAT_0 & 0x10) != 0) {
+            pwVar11 = (wchar_t *)(lVar10 + 0x228);
+            local_838._0_4_ = (uint)local_838 & 0xffff0000;
+            pwVar9 = L"CoId=%hs:Incoming call accepted";
+            FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x18001dc20,(size_t *)pwVar11,param_4);
+            if ((DAT_0 & 0x10) != 0) {
+              pwVar11 = (wchar_t *)&local_838;
+              pwVar9 = L"㚱က\x04";
+              McTemplateU0z_EventWriteTransfer
+                        (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
+                         (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,pwVar11);
+            }
+          }
+          *(uint *)(lVar10 + 0xfc) = *(uint *)(lVar10 + 0xfc) & 0xffffffef;
+          *(uint *)(lVar10 + 0xfc) = *(uint *)(lVar10 + 0xfc) | 0x20;
+          bVar2 = true;
+        }
+        LeaveCriticalSection((LPCRITICAL_SECTION)(lVar10 + 0x120));
+        if (bVar2) {
+          InitiateSstpResponse(lVar10,pwVar9,pwVar11,param_4);
+          DereferenceRefCount((int *)(lVar10 + 0xd0));
+        }
+LAB_6:
+        DereferenceRefCount((int *)(lVar10 + 0xd0));
+      }
+    }
+LAB_5:
+    PostReceiveOnCall(param_1,pwVar9,pwVar11,param_4);
+    EnterCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
+    puVar13 = (uint *)(param_1 + 0xfc);
+    *puVar13 = *puVar13 & 0xfffeffff;
     bVar2 = IsProxyCall(param_1);
-    if ((int)CONCAT71(extraout_var_00,bVar2) == 0) {
-      PostSendNotificationRequest(param_1,pwVar7,pwVar8,(ulonglong)param_4);
-    }
-    else if ((*(byte *)(param_1 + 0x268) & 1) != 0) {
-      lVar1 = *(longlong *)(param_1 + 0x270);
-      EnterCriticalSection((LPCRITICAL_SECTION)(lVar1 + 0x120));
-      if ((DAT_0 & 0x10) != 0) {
-        pwVar8 = (wchar_t *)(lVar1 + 0x228);
-        local_838._0_4_ = (uint)local_838 & 0xffff0000;
-        pwVar7 = L"CoId=%hs:Incoming call accepted";
-        FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x18001dc20,(size_t *)pwVar8,param_4);
-        if ((DAT_0 & 0x10) != 0) {
-          pwVar8 = (wchar_t *)&local_838;
-          pwVar7 = L"㚱က\x04";
-          McTemplateU0z_EventWriteTransfer
-                    (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                     (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,pwVar8);
-        }
-      }
-      *(uint *)(lVar1 + 0xfc) = *(uint *)(lVar1 + 0xfc) & 0xffffffef | 0x20;
-      LeaveCriticalSection((LPCRITICAL_SECTION)(lVar1 + 0x120));
-      InitiateSstpResponse(lVar1,pwVar7,pwVar8,param_4);
-      DereferenceRefCount((int *)(lVar1 + 0xd0));
-    }
-    PostReceiveOnCall(param_1,pwVar7,pwVar8,param_4);
-    EnterCriticalSection(lpCriticalSection);
-    puVar10 = (uint *)(param_1 + 0xfc);
-    *puVar10 = *puVar10 & 0xfffeffff;
-    bVar2 = IsProxyCall(param_1);
-    if ((int)CONCAT71(extraout_var_01,bVar2) == 0) {
-      *puVar10 = *puVar10 & 0xfffffff7;
-    }
-    *puVar10 = *puVar10 | 0x4000;
+    if ((int)CONCAT71(extraout_var_02,bVar2) == 0) {
+      *puVar13 = *puVar13 & 0xfffffff7;
+    }
+    *puVar13 = *puVar13 | 0x4000;
     LeaveCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
     bVar2 = IsProxyCall(param_1);
-    if ((int)CONCAT71(extraout_var_02,bVar2) != 0) {
-LAB_4:
+    if ((int)CONCAT71(extraout_var_03,bVar2) != 0) {
+LAB_8:
       EnterCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
-      uVar4 = *puVar10;
-      *puVar10 = uVar4 & 0xffffbfff;
+      uVar5 = *puVar13;
+      *puVar13 = uVar5 & 0xffffbfff;
       if (*(char *)(param_1 + 0x1b3) == '\0') {
-        *(uint *)(param_1 + 0xfc) = uVar4 & 0xffffbfff | 0x20;
+        *(uint *)(param_1 + 0xfc) = uVar5 & 0xffffbfff | 0x20;
         LeaveCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
-        goto LAB_5;
-      }
-      goto LAB_2;
-    }
-    pwVar8 = (wchar_t *)(param_1 + 0x250);
-    cVar3 = NotifyMakeCallComplete(param_1,0,(ULONG_PTR *)pwVar8,param_4);
-    if (cVar3 != '\0') goto LAB_4;
+        goto LAB_9;
+      }
+      goto LAB_3;
+    }
+    pwVar11 = (wchar_t *)(param_1 + 0x250);
+    cVar4 = NotifyMakeCallComplete(param_1,0,(ULONG_PTR *)pwVar11,param_4);
+    if (cVar4 != '\0') goto LAB_8;
     EnterCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
-    *puVar10 = *puVar10 & 0xffffbfff;
-    uVar4 = 0;
+    *puVar13 = *puVar13 & 0xffffbfff;
+    uVar5 = 0;
   }
   else {
     if ((DAT_0 & 8) != 0) {
-      local_a08 = L"TRUE";
+      local_af8 = L"TRUE";
       local_838._0_4_ = (uint)local_838 & 0xffff0000;
       if (*(char *)(param_1 + 0x1b3) != '\x01') {
-        local_a08 = L"FALSE";
-      }
-      pwVar8 = (wchar_t *)(param_1 + 0x228);
-      pwVar7 = L"CoId=%hs:SstpWebReceiveResponseCompletion completes with %d [Disconnect=%ws]";
+        local_af8 = L"FALSE";
+      }
+      pwVar11 = (wchar_t *)(param_1 + 0x228);
+      pwVar9 = L"CoId=%hs:SstpWebReceiveResponseCompletion completes with %d [Disconnect=%ws]";
       param_4 = (uint *)(ulonglong)param_2;
-      FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x18001ff60,(size_t *)pwVar8,param_4);
+      FormatRRASErrorString((STRSAFE_LPWSTR)&local_838,0x18001ff60,(size_t *)pwVar11,param_4);
       if ((DAT_0 & 8) != 0) {
-        pwVar8 = (wchar_t *)&local_838;
-        pwVar7 = L"㚰က\x02";
+        pwVar11 = (wchar_t *)&local_838;
+        pwVar9 = L"㚰က\x02";
         McTemplateU0z_EventWriteTransfer
                   (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                   (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar8);
+                   (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar11);
       }
     }
     *(uint *)(param_1 + 0xfc) = *(uint *)(param_1 + 0xfc) & 0xfffeffff;
     if (param_2 != 0) {
       param_4 = (uint *)(param_1 + 0x228);
       *(uint *)(param_1 + 0x10c) = param_2;
-      pwVar8 = (wchar_t *)(ulonglong)param_2;
-      LogEventWithErrorParameter(2,pwVar7,param_2,(LPCSTR)param_4);
-    }
-LAB_2:
-    uVar4 = 2;
+      pwVar11 = (wchar_t *)(ulonglong)param_2;
+      LogEventWithErrorParameter(2,pwVar9,param_2,(LPCSTR)param_4);
+    }
+LAB_3:
+    uVar5 = 2;
   }
-  InitiateCallContextCleanup(param_1,uVar4,pwVar8,(ulonglong)param_4);
-LAB_5:
+  InitiateCallContextCleanup(param_1,uVar5,pwVar11,(ulonglong)param_4);
+LAB_9:
   DereferenceRefCount((int *)(param_1 + 0xd0));
   return;
 }
 

```


## wil_details_FeatureReporting_ReportUsageToServiceDirect

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.44|
|i_ratio|0.63|
|m_ratio|0.96|
|b_ratio|0.93|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToServiceDirect|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|fullname|wil_details_FeatureReporting_ReportUsageToServiceDirect|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|refcount|2|2|
|`length`|137|127|
|called|__security_check_cookie<br>wil_RtlStagingConfig_RecordFeatureUsage<br>wil_details_FeatureReporting_RecordUsageInCache|__security_check_cookie<br>wil_RtlStagingConfig_RecordFeatureUsage<br>wil_details_FeatureReporting_RecordUsageInCache|
|calling|wil_details_FeatureReporting_ReportUsageToService|wil_details_FeatureReporting_ReportUsageToService|
|paramcount|3|3|
|`address`|18000b5a4|18000b644|
|`sig`|bool __fastcall wil_details_FeatureReporting_ReportUsageToServiceDirect(undefined8 param_1, undefined8 param_2, undefined8 param_3)|bool __fastcall wil_details_FeatureReporting_ReportUsageToServiceDirect(longlong param_1, undefined8 param_2, undefined8 param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_FeatureReporting_ReportUsageToServiceDirect Diff


```diff
--- wil_details_FeatureReporting_ReportUsageToServiceDirect
+++ wil_details_FeatureReporting_ReportUsageToServiceDirect
@@ -1,24 +1,24 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 bool wil_details_FeatureReporting_ReportUsageToServiceDirect
-               (undefined8 param_1,undefined8 param_2,undefined8 param_3)
+               (longlong param_1,undefined8 param_2,undefined8 param_3)
 
 {
   uint *puVar1;
-  undefined1 auStack_78 [48];
-  uint local_48 [10];
-  undefined8 local_20;
-  ulonglong local_18;
+  undefined1 auStack_88 [48];
+  uint local_58 [10];
+  undefined8 local_30;
+  ulonglong local_28;
   
-  local_18 = __security_cookie ^ (ulonglong)auStack_78;
+  local_28 = __security_cookie ^ (ulonglong)auStack_88;
   puVar1 = wil_details_FeatureReporting_RecordUsageInCache
-                     (local_48,(uint *)&Feature_1207409977__private_reporting,param_3,
-                      (uint)((ulonglong)param_2 >> 0x20));
-  local_20 = *(undefined8 *)(puVar1 + 4);
+                     (local_58,*(uint **)(param_1 + 8),param_3,(uint)((ulonglong)param_2 >> 0x20));
+  local_30 = *(undefined8 *)(puVar1 + 4);
   if ((((uint)param_2 >> 10 & 1) != 0) && ((int)param_3 != 0xfe)) {
-    wil_RtlStagingConfig_RecordFeatureUsage(0x3bba30f,(short)param_3,(uint)param_2 >> 0xb & 1);
+    wil_RtlStagingConfig_RecordFeatureUsage
+              (*(undefined4 *)(param_1 + 0x18),(short)param_3,(uint)param_2 >> 0xb & 1);
   }
-  return (int)local_20 == 0;
+  return (int)local_30 == 0;
 }
 

```


## wil_details_FeatureReporting_ReportUsageToService

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.63|
|i_ratio|0.56|
|m_ratio|0.94|
|b_ratio|0.94|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToService|wil_details_FeatureReporting_ReportUsageToService|
|fullname|wil_details_FeatureReporting_ReportUsageToService|wil_details_FeatureReporting_ReportUsageToService|
|refcount|2|2|
|`length`|114|125|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_MapReportingKind|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_MapReportingKind|
|calling|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|paramcount|3|3|
|`address`|18000b528|18000b5c0|
|`sig`|undefined __fastcall wil_details_FeatureReporting_ReportUsageToService(undefined8 param_1, undefined8 param_2, uint param_3)|undefined __fastcall wil_details_FeatureReporting_ReportUsageToService(longlong param_1, undefined8 param_2, int param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_FeatureReporting_ReportUsageToService Diff


```diff
--- wil_details_FeatureReporting_ReportUsageToService
+++ wil_details_FeatureReporting_ReportUsageToService
@@ -1,28 +1,27 @@
 
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
 
 void wil_details_FeatureReporting_ReportUsageToService
-               (undefined8 param_1,undefined8 param_2,uint param_3)
+               (longlong param_1,undefined8 param_2,int param_3)
 
 {
   bool bVar1;
   uint uVar2;
   undefined7 extraout_var;
-  ulonglong uVar3;
-  uint uVar4;
-  uint local_res18 [4];
+  uint uVar3;
+  int local_res18 [4];
   
-  uVar4 = (uint)param_2 & 1;
-  uVar3 = (ulonglong)param_3;
+  uVar3 = (uint)param_2 & 1;
   local_res18[0] = param_3;
-  uVar2 = wil_details_MapReportingKind(param_3,uVar4);
-  bVar1 = wil_details_FeatureReporting_ReportUsageToServiceDirect(uVar3,param_2,(ulonglong)uVar2);
+  uVar2 = wil_details_MapReportingKind(param_3,uVar3);
+  bVar1 = wil_details_FeatureReporting_ReportUsageToServiceDirect(param_1,param_2,(ulonglong)uVar2);
   if (((int)CONCAT71(extraout_var,bVar1) != 0) &&
      (g_wil_details_pfnFeatureLoggingHook != (code *)0x0)) {
     (*g_wil_details_pfnFeatureLoggingHook)
-              (0x3bba30f,&Feature_1207409977_logged_traits,0,uVar4,local_res18,0,0,1);
+              (*(undefined4 *)(param_1 + 0x18),*(undefined8 *)(param_1 + 0x10),0,uVar3,local_res18,0
+               ,0,1);
   }
   return;
 }
 

```


## Feature_1207409977__private_IsEnabledDeviceUsageNoInline

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.75|
|i_ratio|0.7|
|m_ratio|0.96|
|b_ratio|0.96|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|Feature_1207409977__private_IsEnabledDeviceUsageNoInline|Feature_1207409977__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_1207409977__private_IsEnabledDeviceUsageNoInline|Feature_1207409977__private_IsEnabledDeviceUsageNoInline|
|refcount|6|6|
|`length`|44|51|
|called|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|calling|AllocateAndInitializeCallContext<br>CleanupCallCtx<br>InitiateCallContextCleanup<br>SstpThreadPoolRequestQueueCallback|AllocateAndInitializeCallContext<br>CleanupCallCtx<br>InitiateCallContextCleanup<br>SstpThreadPoolRequestQueueCallback|
|paramcount|0|0|
|`address`|18000ac8c|18000ad1c|
|sig|uint __fastcall Feature_1207409977__private_IsEnabledDeviceUsageNoInline(void)|uint __fastcall Feature_1207409977__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### Feature_1207409977__private_IsEnabledDeviceUsageNoInline Diff


```diff
--- Feature_1207409977__private_IsEnabledDeviceUsageNoInline
+++ Feature_1207409977__private_IsEnabledDeviceUsageNoInline
@@ -1,15 +1,15 @@
 
 uint Feature_1207409977__private_IsEnabledDeviceUsageNoInline(void)
 
 {
   uint uVar1;
-  undefined8 local_res8;
+  ulonglong local_res8;
   
-  local_res8 = (undefined4 *)(ulonglong)Feature_1207409977__private_featureState;
+  local_res8 = (ulonglong)Feature_1207409977__private_featureState;
   if ((Feature_1207409977__private_featureState & 0x10) != 0) {
     return Feature_1207409977__private_featureState & 1;
   }
-  uVar1 = wil_details_IsEnabledFallback(local_res8,3);
+  uVar1 = wil_details_IsEnabledFallback(local_res8,3,&Feature_1207409977__private_descriptor);
   return uVar1;
 }
 

```


## wil_details_IsEnabledFallback

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,refcount,length,sig,address,calling|
|ratio|0.48|
|i_ratio|0.43|
|m_ratio|0.96|
|b_ratio|0.94|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|`refcount`|2|3|
|`length`|135|140|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|`calling`|Feature_1207409977__private_IsEnabledDeviceUsageNoInline|Feature_1207409977__private_IsEnabledDeviceUsageNoInline<br>Feature_2530182457__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|3|
|`address`|18000b8f8|18000b9a0|
|`sig`|uint __fastcall wil_details_IsEnabledFallback(undefined4 * param_1, uint param_2)|uint __fastcall wil_details_IsEnabledFallback(ulonglong param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_IsEnabledFallback Calling Diff


```diff
--- wil_details_IsEnabledFallback calling
+++ wil_details_IsEnabledFallback calling
@@ -1,0 +2 @@
+Feature_2530182457__private_IsEnabledDeviceUsageNoInline
```


### wil_details_IsEnabledFallback Diff


```diff
--- wil_details_IsEnabledFallback
+++ wil_details_IsEnabledFallback
@@ -1,26 +1,22 @@
 
-uint wil_details_IsEnabledFallback(undefined4 *param_1,uint param_2)
+uint wil_details_IsEnabledFallback(ulonglong param_1,int param_2,undefined8 *param_3)
 
 {
   uint uVar1;
-  undefined4 *puVar2;
-  ulonglong local_res18;
+  ulonglong local_res8;
   
   uVar1 = (uint)param_1;
-  local_res18 = (ulonglong)param_1 & 0xffffffff;
-  if (((ulonglong)param_1 & 2) == 0) {
-    puVar2 = &Feature_1207409977__private_featureState;
-    local_res18 = wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
-                            (&Feature_1207409977__private_featureState,(ulonglong)param_1,
-                             0x180026d20);
-    param_1 = puVar2;
-    uVar1 = (uint)local_res18;
+  local_res8 = param_1 & 0xffffffff;
+  if ((param_1 & 2) == 0) {
+    local_res8 = wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+                           ((uint *)*param_3,param_1,(longlong)param_3);
+    uVar1 = (uint)local_res8;
   }
   if ((param_2 != 0) &&
-     (wil_details_FeatureReporting_ReportUsageToService(param_1,local_res18,param_2),
-     param_2 - 3 < 2)) {
-    wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath((uint)local_res18,param_2);
+     (wil_details_FeatureReporting_ReportUsageToService((longlong)param_3,local_res8,param_2),
+     param_2 - 3U < 2)) {
+    wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath((uint)local_res8,param_2,param_3);
   }
   return uVar1 & 1;
 }
 

```


## ProxySendToRelatedCtx

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.36|
|i_ratio|0.73|
|m_ratio|0.92|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|ProxySendToRelatedCtx|ProxySendToRelatedCtx|
|fullname|ProxySendToRelatedCtx|ProxySendToRelatedCtx|
|refcount|4|4|
|`length`|861|985|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>FormatRRASErrorString<br>FreeBufferToPool<br>HTTPAPI.DLL::HttpSendResponseEntityBody<br>InitiateCallContextCleanup<br>IsProxyCall<br>McTemplateU0z_EventWriteTransfer<br>SstpWebSendRequestEntityCompletion</summary>WEBIO.DLL::Ordinal_26<br>__security_check_cookie<br>memset</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>DereferenceRefCount<br>Feature_2530182457__private_IsEnabledDeviceUsageNoInline<br>FormatRRASErrorString<br>FreeBufferToPool<br>HTTPAPI.DLL::HttpSendResponseEntityBody<br>InitiateCallContextCleanup<br>IsProxyCall</summary>McTemplateU0z_EventWriteTransfer<br>SstpWebSendRequestEntityCompletion<br>WEBIO.DLL::Ordinal_26<br>__security_check_cookie<br>memset</details>|
|calling|HttpThreadPoolRequestQueueCallback<br>PostReceiveOnCall<br>SstpWebReceiveResponseEntityCompletion|HttpThreadPoolRequestQueueCallback<br>PostReceiveOnCall<br>SstpWebReceiveResponseEntityCompletion|
|paramcount|4|4|
|`address`|18000658c|1800087d8|
|sig|undefined __fastcall ProxySendToRelatedCtx(undefined8 * param_1, undefined8 param_2, undefined8 param_3, ulonglong param_4)|undefined __fastcall ProxySendToRelatedCtx(undefined8 * param_1, undefined8 param_2, undefined8 param_3, ulonglong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### ProxySendToRelatedCtx Called Diff


```diff
--- ProxySendToRelatedCtx called
+++ ProxySendToRelatedCtx called
@@ -4,0 +5,2 @@
+DereferenceRefCount
+Feature_2530182457__private_IsEnabledDeviceUsageNoInline
```


### ProxySendToRelatedCtx Diff


```diff
--- ProxySendToRelatedCtx
+++ ProxySendToRelatedCtx
@@ -1,147 +1,170 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 void ProxySendToRelatedCtx
                (undefined8 *param_1,undefined8 param_2,undefined8 param_3,ulonglong param_4)
 
 {
-  LPCRITICAL_SECTION lpCriticalSection;
-  longlong lVar1;
+  LPCRITICAL_SECTION p_Var1;
   bool bVar2;
   uint uVar3;
   int iVar4;
   undefined7 extraout_var;
-  wchar_t *pwVar5;
-  ulonglong uVar6;
+  undefined7 extraout_var_00;
+  longlong lVar5;
+  wchar_t *pwVar6;
+  ulonglong uVar7;
   undefined1 auStack_898 [32];
   code *local_878;
   undefined8 *local_870;
   undefined8 local_868;
   undefined4 local_860;
   undefined8 *local_858;
   undefined8 local_850;
   undefined8 local_848;
   undefined8 *local_840;
   uint local_838;
   undefined8 local_834;
   uint local_828;
   undefined1 local_824 [2044];
   ulonglong local_28;
   
   local_28 = __security_cookie ^ (ulonglong)auStack_898;
+  lVar5 = param_1[7];
   local_828 = 0;
-  pwVar5 = (wchar_t *)0x7fc;
+  pwVar6 = (wchar_t *)0x7fc;
   memset(local_824,0,0x7fc);
   if ((DAT_0 & 0x10) != 0) {
-    pwVar5 = L"ProxySendToNetworkWorker";
+    pwVar6 = L"ProxySendToNetworkWorker";
     local_828 = local_828 & 0xffff0000;
     FormatRRASErrorString
               ((STRSAFE_LPWSTR)&local_828,0x18001caa0,(size_t *)L"ProxySendToNetworkWorker",param_4)
     ;
     if ((DAT_0 & 0x10) != 0) {
-      pwVar5 = (wchar_t *)&local_828;
+      pwVar6 = (wchar_t *)&local_828;
       McTemplateU0z_EventWriteTransfer
                 (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,(PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,
-                 pwVar5);
+                 pwVar6);
     }
   }
-  bVar2 = IsProxyCall(param_1[7]);
-  if ((int)CONCAT71(extraout_var,bVar2) != 0) {
-    lVar1 = *(longlong *)(param_1[7] + 0x270);
-    lpCriticalSection = (LPCRITICAL_SECTION)(lVar1 + 0x120);
-    EnterCriticalSection(lpCriticalSection);
-    *(uint *)(lVar1 + 0xfc) = *(uint *)(lVar1 + 0xfc) | 0x80;
-    if (*(char *)(lVar1 + 0x1b3) == '\0') {
-      LeaveCriticalSection(lpCriticalSection);
-      if (*(int *)((longlong)param_1 + 0x5c) == 0) {
-        pwVar5 = (wchar_t *)CONCAT71((int7)((ulonglong)pwVar5 >> 8),1);
-        FreeBufferToPool((uint *)(SstpSvcGlobals + 0x1a8),(longlong)param_1,'\x01');
-      }
-      else {
-        *(undefined4 *)(param_1 + 4) = 0x4572;
-        *param_1 = 0;
-        param_1[1] = 0;
-        param_1[2] = 0;
-        param_1[3] = 0;
-        uVar3 = *(uint *)((longlong)param_1 + 0x5c);
-        if (*(char *)(lVar1 + 0xf8) == '\0') {
-          local_848 = 0;
-          local_834 = 0;
-          local_840 = param_1 + 0xc;
-          local_838 = uVar3;
-          StartThreadpoolIo(*(PTP_IO *)(SstpSvcGlobals + 0xa8));
-          local_878 = (code *)&local_848;
-          param_4 = 1;
-          local_850 = 0;
-          local_860 = 0;
-          pwVar5 = (wchar_t *)0x2;
-          local_868 = 0;
-          local_870 = (undefined8 *)0x0;
-          local_858 = param_1;
-          uVar3 = HttpSendResponseEntityBody
-                            (*(undefined8 *)(SstpSvcGlobals + 0x40),*(undefined8 *)(lVar1 + 0x110));
-          uVar6 = (ulonglong)uVar3;
-          if ((uVar3 != 0x3e5) && (uVar3 != 0)) {
-            pwVar5 = (wchar_t *)CONCAT71((int7)((ulonglong)pwVar5 >> 8),1);
-            FreeBufferToPool((uint *)(SstpSvcGlobals + 0x1a8),(longlong)param_1,'\x01');
-            CancelThreadpoolIo(*(PTP_IO *)(SstpSvcGlobals + 0xa8));
+  uVar3 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+  if (uVar3 == 0) {
+    bVar2 = IsProxyCall(param_1[7]);
+    if ((int)CONCAT71(extraout_var_00,bVar2) == 0) goto LAB_1;
+    lVar5 = *(longlong *)(param_1[7] + 0x270);
+  }
+  else {
+    p_Var1 = (LPCRITICAL_SECTION)(lVar5 + 0x120);
+    EnterCriticalSection(p_Var1);
+    bVar2 = IsProxyCall(lVar5);
+    if (((int)CONCAT71(extraout_var,bVar2) == 0) ||
+       (lVar5 = *(longlong *)(lVar5 + 0x270), lVar5 == 0)) {
+      LeaveCriticalSection(p_Var1);
+      goto LAB_1;
+    }
+    LOCK();
+    *(int *)(lVar5 + 0xd0) = *(int *)(lVar5 + 0xd0) + 1;
+    UNLOCK();
+    LeaveCriticalSection(p_Var1);
+  }
+  p_Var1 = (LPCRITICAL_SECTION)(lVar5 + 0x120);
+  EnterCriticalSection(p_Var1);
+  *(uint *)(lVar5 + 0xfc) = *(uint *)(lVar5 + 0xfc) | 0x80;
+  if (*(char *)(lVar5 + 0x1b3) == '\0') {
+    LeaveCriticalSection(p_Var1);
+    if (*(int *)((longlong)param_1 + 0x5c) == 0) {
+      pwVar6 = (wchar_t *)CONCAT71((int7)((ulonglong)pwVar6 >> 8),1);
+      FreeBufferToPool((uint *)(SstpSvcGlobals + 0x1a8),(longlong)param_1,'\x01');
+    }
+    else {
+      *(undefined4 *)(param_1 + 4) = 0x4572;
+      *param_1 = 0;
+      param_1[1] = 0;
+      param_1[2] = 0;
+      param_1[3] = 0;
+      uVar3 = *(uint *)((longlong)param_1 + 0x5c);
+      if (*(char *)(lVar5 + 0xf8) == '\0') {
+        local_848 = 0;
+        local_834 = 0;
+        local_840 = param_1 + 0xc;
+        local_838 = uVar3;
+        StartThreadpoolIo(*(PTP_IO *)(SstpSvcGlobals + 0xa8));
+        local_878 = (code *)&local_848;
+        param_4 = 1;
+        local_850 = 0;
+        local_860 = 0;
+        pwVar6 = (wchar_t *)0x2;
+        local_868 = 0;
+        local_870 = (undefined8 *)0x0;
+        local_858 = param_1;
+        uVar3 = HttpSendResponseEntityBody
+                          (*(undefined8 *)(SstpSvcGlobals + 0x40),*(undefined8 *)(lVar5 + 0x110));
+        uVar7 = (ulonglong)uVar3;
+        if ((uVar3 != 0x3e5) && (uVar3 != 0)) {
+          pwVar6 = (wchar_t *)CONCAT71((int7)((ulonglong)pwVar6 >> 8),1);
+          FreeBufferToPool((uint *)(SstpSvcGlobals + 0x1a8),(longlong)param_1,'\x01');
+          CancelThreadpoolIo(*(PTP_IO *)(SstpSvcGlobals + 0xa8));
+          if ((DAT_0 & 8) != 0) {
+            pwVar6 = (wchar_t *)(lVar5 + 0x228);
+            local_828 = local_828 & 0xffff0000;
+            local_878 = (code *)CONCAT44(local_878._4_4_,uVar3);
+            FormatRRASErrorString((STRSAFE_LPWSTR)&local_828,0x18001e620,(size_t *)pwVar6,uVar7);
+            param_4 = uVar7;
             if ((DAT_0 & 8) != 0) {
-              pwVar5 = (wchar_t *)(lVar1 + 0x228);
-              local_828 = local_828 & 0xffff0000;
-              local_878 = (code *)CONCAT44(local_878._4_4_,uVar3);
-              FormatRRASErrorString((STRSAFE_LPWSTR)&local_828,0x18001e620,(size_t *)pwVar5,uVar6);
-              param_4 = uVar6;
-              if ((DAT_0 & 8) != 0) {
-                pwVar5 = (wchar_t *)&local_828;
-                McTemplateU0z_EventWriteTransfer
-                          (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                           (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar5);
-                param_4 = uVar6;
-              }
+              pwVar6 = (wchar_t *)&local_828;
+              McTemplateU0z_EventWriteTransfer
+                        (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
+                         (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar6);
+              param_4 = uVar7;
             }
           }
         }
-        else {
-          pwVar5 = (wchar_t *)(param_1 + 8);
-          pwVar5[0] = L'\0';
-          pwVar5[1] = L'\0';
-          param_1[9] = param_1 + 0xc;
-          param_1[10] = (ulonglong)uVar3;
-          LOCK();
-          *(int *)(lVar1 + 0xd0) = *(int *)(lVar1 + 0xd0) + 1;
-          UNLOCK();
-          param_1[7] = lVar1;
-          local_878 = SstpWebSendRequestEntityCompletion;
-          param_4 = 1;
-          local_870 = param_1;
-          iVar4 = Ordinal_26(*(undefined8 *)(lVar1 + 0x1c0));
-          if (iVar4 != 0x3e5) {
-            pwVar5 = (wchar_t *)0x0;
-            SstpWebSendRequestEntityCompletion((longlong)param_1,iVar4,0,param_4);
-          }
+      }
+      else {
+        pwVar6 = (wchar_t *)(param_1 + 8);
+        pwVar6[0] = L'\0';
+        pwVar6[1] = L'\0';
+        param_1[9] = param_1 + 0xc;
+        param_1[10] = (ulonglong)uVar3;
+        LOCK();
+        *(int *)(lVar5 + 0xd0) = *(int *)(lVar5 + 0xd0) + 1;
+        UNLOCK();
+        param_1[7] = lVar5;
+        local_878 = SstpWebSendRequestEntityCompletion;
+        param_4 = 1;
+        local_870 = param_1;
+        iVar4 = Ordinal_26(*(undefined8 *)(lVar5 + 0x1c0));
+        if (iVar4 != 0x3e5) {
+          pwVar6 = (wchar_t *)0x0;
+          SstpWebSendRequestEntityCompletion((longlong)param_1,iVar4,0,param_4);
         }
       }
-      EnterCriticalSection(lpCriticalSection);
     }
-    *(uint *)(lVar1 + 0xfc) = *(uint *)(lVar1 + 0xfc) & 0xffffff7f;
-    if (*(char *)(lVar1 + 0x1b3) == '\0') {
-      LeaveCriticalSection(lpCriticalSection);
-    }
-    else {
-      InitiateCallContextCleanup(lVar1,2,pwVar5,param_4);
-    }
+    EnterCriticalSection(p_Var1);
   }
+  *(uint *)(lVar5 + 0xfc) = *(uint *)(lVar5 + 0xfc) & 0xffffff7f;
+  if (*(char *)(lVar5 + 0x1b3) == '\0') {
+    LeaveCriticalSection(p_Var1);
+  }
+  else {
+    InitiateCallContextCleanup(lVar5,2,pwVar6,param_4);
+  }
+  uVar3 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+  if (uVar3 != 0) {
+    DereferenceRefCount((int *)(lVar5 + 0xd0));
+  }
+LAB_1:
   if ((DAT_0 & 0x10) != 0) {
     local_828 = local_828 & 0xffff0000;
     FormatRRASErrorString
               ((STRSAFE_LPWSTR)&local_828,0x18001cb50,(size_t *)L"ProxySendToNetworkWorker",param_4)
     ;
     if ((DAT_0 & 0x10) != 0) {
       McTemplateU0z_EventWriteTransfer
                 (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,(PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,
                  (wchar_t *)&local_828);
     }
   }
   return;
 }
 

```


## HttpThreadPoolRequestQueueCallback

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.63|
|i_ratio|0.67|
|m_ratio|0.99|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|HttpThreadPoolRequestQueueCallback|HttpThreadPoolRequestQueueCallback|
|fullname|HttpThreadPoolRequestQueueCallback|HttpThreadPoolRequestQueueCallback|
|refcount|3|3|
|`length`|2505|2539|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>DereferenceRefCount<br>FindSstpGatewayByGroup<br>FormatRRASErrorString<br>ForwardMakeCallRequest</summary>FreeBufferToPool<br>GetSstpConfigFlag<br>HTTPAPI.DLL::HttpReceiveHttpRequest<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>IsProxyCall<br>McTemplateU0z_EventWriteTransfer<br>PRXYQRY.DLL::GetSstpDestinationInfo<br>PRXYQRY.DLL::GetSstpGroupIDFromQueryString<br>PostNewHttpRequest<br>PostReceiveOnCall<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedHttpRequest<br>ProxySendToRelatedCtx<br>SyncDeviceControl<br>__chkstk<br>__security_check_cookie<br>memcpy<br>memset</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>DereferenceRefCount<br>Feature_2530182457__private_IsEnabledDeviceUsageNoInline<br>FindSstpGatewayByGroup<br>FormatRRASErrorString</summary>ForwardMakeCallRequest<br>FreeBufferToPool<br>GetSstpConfigFlag<br>HTTPAPI.DLL::HttpReceiveHttpRequest<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>IsProxyCall<br>McTemplateU0z_EventWriteTransfer<br>PRXYQRY.DLL::GetSstpDestinationInfo<br>PRXYQRY.DLL::GetSstpGroupIDFromQueryString<br>PostNewHttpRequest<br>PostReceiveOnCall<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedHttpRequest<br>ProxySendToRelatedCtx<br>SyncDeviceControl<br>__chkstk<br>__security_check_cookie<br>memcpy<br>memset</details>|
|calling|||
|paramcount|5|5|
|`address`|18000bc20|18000bd50|
|sig|undefined __fastcall HttpThreadPoolRequestQueueCallback(undefined8 param_1, undefined8 param_2, undefined8 * param_3, _OVERLAPPED * param_4, undefined4 param_5)|undefined __fastcall HttpThreadPoolRequestQueueCallback(undefined8 param_1, undefined8 param_2, undefined8 * param_3, _OVERLAPPED * param_4, undefined4 param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### HttpThreadPoolRequestQueueCallback Called Diff


```diff
--- HttpThreadPoolRequestQueueCallback called
+++ HttpThreadPoolRequestQueueCallback called
@@ -8,0 +9 @@
+Feature_2530182457__private_IsEnabledDeviceUsageNoInline
```


### HttpThreadPoolRequestQueueCallback Diff


```diff
--- HttpThreadPoolRequestQueueCallback
+++ HttpThreadPoolRequestQueueCallback
@@ -1,413 +1,419 @@
 
 /* WARNING: Function: __chkstk replaced with injection: alloca_probe */
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 void HttpThreadPoolRequestQueueCallback
                (undefined8 param_1,undefined8 param_2,undefined8 *param_3,_OVERLAPPED *param_4,
                undefined4 param_5)
 
 {
-  LPCRITICAL_SECTION p_Var1;
-  uint *puVar2;
+  uint *puVar1;
+  LPCRITICAL_SECTION p_Var2;
   longlong lVar3;
   bool bVar4;
-  DWORD DVar5;
-  int iVar6;
-  uint uVar7;
+  uint uVar5;
+  DWORD DVar6;
+  int iVar7;
   undefined7 extraout_var;
   undefined7 extraout_var_00;
   undefined7 extraout_var_01;
   ushort *puVar8;
   HANDLE hHeap;
   ulonglong uVar9;
   undefined7 extraout_var_02;
-  undefined8 *puVar10;
-  _union_540 *p_Var11;
-  wchar_t *pwVar12;
-  LPOVERLAPPED p_Var13;
-  _OVERLAPPED *p_Var14;
-  wchar_t *pwVar15;
+  _union_540 *p_Var10;
+  wchar_t *pwVar11;
+  LPOVERLAPPED p_Var12;
+  _OVERLAPPED *p_Var13;
+  wchar_t *pwVar14;
+  undefined8 uVar15;
   ULONG_PTR *pUVar16;
   void *pvVar17;
   _OVERLAPPED *p_Var18;
   _OVERLAPPED *p_Var19;
   undefined1 auStackY_2ac8 [32];
   DWORD local_2a78 [2];
   void *local_2a70;
   GUID local_2a68;
   undefined1 local_2a58 [8];
   uint local_2a50;
   undefined1 local_2a4c [8196];
   undefined8 local_a48;
   wchar_t local_248;
   undefined1 local_246 [510];
   ulonglong local_48;
   undefined8 uStack_40;
   
-  uStack_40 = 0x18000bc42;
+  uStack_40 = 0x18000bd72;
   local_48 = __security_cookie ^ (ulonglong)auStackY_2ac8;
-  pwVar15 = (wchar_t *)0x7fc;
-  pwVar12 = (wchar_t *)0x0;
+  pwVar14 = (wchar_t *)0x7fc;
+  pwVar11 = (wchar_t *)0x0;
   local_a48._0_4_ = 0;
-  p_Var14 = (_OVERLAPPED *)((ulonglong)param_4 & 0xffffffff);
+  p_Var13 = (_OVERLAPPED *)((ulonglong)param_4 & 0xffffffff);
   p_Var18 = param_4;
   memset((void *)((longlong)&local_a48 + 4),0,0x7fc);
   if ((DAT_0 & 0x10) != 0) {
-    pwVar15 = L"HttpThreadPoolRequestQueueCallback";
+    pwVar14 = L"HttpThreadPoolRequestQueueCallback";
     local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
-    pwVar12 = L"Entering %ws";
+    pwVar11 = L"Entering %ws";
     FormatRRASErrorString
               ((STRSAFE_LPWSTR)&local_a48,0x18001caa0,
                (size_t *)L"HttpThreadPoolRequestQueueCallback",p_Var18);
     if ((DAT_0 & 0x10) != 0) {
-      pwVar15 = (wchar_t *)&local_a48;
-      pwVar12 = L"㚱က\x04";
+      pwVar14 = (wchar_t *)&local_a48;
+      pwVar11 = L"㚱က\x04";
       McTemplateU0z_EventWriteTransfer
                 (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,(PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,
-                 pwVar15);
+                 pwVar14);
     }
   }
   if (param_3 == (undefined8 *)0x0) {
-    if ((DAT_0 & 8) == 0) goto LAB_18000c575;
-    pwVar15 = L"NULL overlapped received";
-    p_Var14 = p_Var18;
+    if ((DAT_0 & 8) == 0) goto LAB_18000c6c7;
+    pwVar14 = L"NULL overlapped received";
+    p_Var13 = p_Var18;
 LAB_2:
     McTemplateU0z_EventWriteTransfer
               (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,(PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,
-               pwVar15);
-    p_Var18 = p_Var14;
+               pwVar14);
+    p_Var18 = p_Var13;
     goto LAB_1;
   }
-  uVar7 = *(uint *)(param_3 + 4);
+  uVar5 = *(uint *)(param_3 + 4);
   if ((DAT_0 & 0x10) != 0) {
-    pwVar15 = (wchar_t *)(ulonglong)uVar7;
+    pwVar14 = (wchar_t *)(ulonglong)uVar5;
     local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
-    pwVar12 = L"Received overlapID %d";
-    FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f640,(size_t *)pwVar15,p_Var18);
+    pwVar11 = L"Received overlapID %d";
+    FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f640,(size_t *)pwVar14,p_Var18);
     if ((DAT_0 & 0x10) != 0) {
-      pwVar15 = (wchar_t *)&local_a48;
-      pwVar12 = L"㚱က\x04";
+      pwVar14 = (wchar_t *)&local_a48;
+      pwVar11 = L"㚱က\x04";
       McTemplateU0z_EventWriteTransfer
                 (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,(PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,
-                 pwVar15);
-    }
-  }
-  iVar6 = (int)param_4;
-  if (uVar7 == 0x4567) {
+                 pwVar14);
+    }
+  }
+  iVar7 = (int)param_4;
+  if (uVar5 == 0x4567) {
     local_2a78[0] = local_2a78[0] & 0xffff0000;
     pUVar16 = (ULONG_PTR *)0x1fc;
     local_248 = L'\0';
     memset(local_246,0,0x1fc);
-    p_Var13 = (LPOVERLAPPED)param_3[7];
+    p_Var12 = (LPOVERLAPPED)param_3[7];
     p_Var19 = (_OVERLAPPED *)(param_3 + 0xc);
-    if (iVar6 == 0) {
-      p_Var1 = (LPCRITICAL_SECTION)(p_Var13 + 9);
-      EnterCriticalSection(p_Var1);
-      puVar2 = (uint *)((longlong)&p_Var13[7].hEvent + 4);
-      *puVar2 = *puVar2 | 0x202;
-      p_Var13[8].hEvent = (HANDLE)param_3[0xd];
-      p_Var13[8].u = *(_union_540 *)(param_3 + 0xe);
-      LeaveCriticalSection(p_Var1);
-      iVar6 = ProcessReceivedHttpRequest((longlong)p_Var19,(undefined2 *)local_2a78,pUVar16,p_Var18)
+    if (iVar7 == 0) {
+      p_Var2 = (LPCRITICAL_SECTION)(p_Var12 + 9);
+      EnterCriticalSection(p_Var2);
+      puVar1 = (uint *)((longlong)&p_Var12[7].hEvent + 4);
+      *puVar1 = *puVar1 | 0x202;
+      p_Var12[8].hEvent = (HANDLE)param_3[0xd];
+      p_Var12[8].u = *(_union_540 *)(param_3 + 0xe);
+      LeaveCriticalSection(p_Var2);
+      iVar7 = ProcessReceivedHttpRequest((longlong)p_Var19,(undefined2 *)local_2a78,pUVar16,p_Var18)
       ;
-      if (iVar6 == 0) {
+      if (iVar7 == 0) {
         PostNewHttpRequest();
         bVar4 = GetSstpConfigFlag(1);
         if ((int)CONCAT71(extraout_var_01,bVar4) != 0) {
           puVar8 = (ushort *)
                    GetSstpGroupIDFromQueryString
                              (param_3[0x18],*(undefined2 *)((longlong)param_3 + 0xa6));
-          iVar6 = FindSstpGatewayByGroup(puVar8,&local_248,pUVar16,p_Var18);
-          if (iVar6 != 0) {
+          iVar7 = FindSstpGatewayByGroup(puVar8,&local_248,pUVar16,p_Var18);
+          if (iVar7 != 0) {
             local_2a70 = (void *)0x0;
             local_2a78[0] = 0;
             memset(local_2a58,0,0x200c);
             local_2a78[1] = 0;
             local_2a68.Data1 = 0;
             local_2a68.Data2 = 0;
             local_2a68.Data3 = 0;
             local_2a68.Data4[0] = '\0';
             local_2a68.Data4[1] = '\0';
             local_2a68.Data4[2] = '\0';
             local_2a68.Data4[3] = '\0';
             local_2a68.Data4[4] = '\0';
             local_2a68.Data4[5] = '\0';
             local_2a68.Data4[6] = '\0';
             local_2a68.Data4[7] = '\0';
-            uVar7 = CoCreateGuid(&local_2a68);
-            if (uVar7 == 0) {
+            uVar5 = CoCreateGuid(&local_2a68);
+            if (uVar5 == 0) {
               p_Var18 = (_OVERLAPPED *)CONCAT71((int7)((ulonglong)p_Var18 >> 8),1);
-              uVar7 = GetSstpDestinationInfo(&local_248,&local_2a70,local_2a78);
-              DVar5 = local_2a78[0];
-              if (((uVar7 == 0) && (local_2a70 != (void *)0x0)) && (local_2a78[0] < 0x2000)) {
+              uVar5 = GetSstpDestinationInfo(&local_248,&local_2a70,local_2a78);
+              DVar6 = local_2a78[0];
+              if (((uVar5 == 0) && (local_2a70 != (void *)0x0)) && (local_2a78[0] < 0x2000)) {
                 memcpy(local_2a4c,local_2a70,(ulonglong)local_2a78[0]);
-                local_2a50 = DVar5;
+                local_2a50 = DVar6;
                 hHeap = GetProcessHeap();
                 pvVar17 = local_2a70;
                 HeapFree(hHeap,0,local_2a70);
                 uVar9 = ForwardMakeCallRequest
-                                  ((longlong)local_2a58,(longlong)p_Var13,pvVar17,(wchar_t *)p_Var18
+                                  ((longlong)local_2a58,(longlong)p_Var12,pvVar17,(wchar_t *)p_Var18
                                   );
                 if (((int)uVar9 != 0) && ((DAT_0 & 8) != 0)) {
                   local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
                   FormatRRASErrorString
                             ((STRSAFE_LPWSTR)&local_a48,0x18001f790,(size_t *)(uVar9 & 0xffffffff),
                              p_Var18);
                   goto LAB_3;
                 }
                 goto LAB_4;
               }
-              if ((DAT_0 & 8) == 0) goto LAB_18000c575;
-              pwVar15 = L"GetSstpDestinationInfo failed: %d";
-              p_Var14 = p_Var18;
+              if ((DAT_0 & 8) == 0) goto LAB_18000c6c7;
+              pwVar14 = L"GetSstpDestinationInfo failed: %d";
+              p_Var13 = p_Var18;
             }
             else {
-              if ((DAT_0 & 8) == 0) goto LAB_18000c575;
-              uVar7 = uVar7 & 0xffff;
-              pwVar15 = L"Failed to create Correlation GUID: %d";
-              p_Var14 = p_Var18;
+              if ((DAT_0 & 8) == 0) goto LAB_18000c6c7;
+              uVar5 = uVar5 & 0xffff;
+              pwVar14 = L"Failed to create Correlation GUID: %d";
+              p_Var13 = p_Var18;
             }
             local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
             FormatRRASErrorString
-                      ((STRSAFE_LPWSTR)&local_a48,(size_t)pwVar15,(size_t *)(ulonglong)uVar7,p_Var14
+                      ((STRSAFE_LPWSTR)&local_a48,(size_t)pwVar14,(size_t *)(ulonglong)uVar5,p_Var13
                       );
             goto LAB_5;
           }
         }
         bVar4 = GetSstpConfigFlag(2);
         if ((int)CONCAT71(extraout_var_02,bVar4) == 0) {
-          EnterCriticalSection(p_Var1);
-          *(undefined4 *)((longlong)&p_Var13[8].InternalHigh + 4) = 0;
+          EnterCriticalSection(p_Var2);
+          *(undefined4 *)((longlong)&p_Var12[8].InternalHigh + 4) = 0;
           goto LAB_6;
         }
-        ProcessNewCall((size_t *)p_Var13,param_3,(longlong)p_Var19,p_Var18);
+        ProcessNewCall((size_t *)p_Var12,param_3,(longlong)p_Var19,p_Var18);
       }
       else {
         if ((DAT_0 & 8) != 0) {
-          pUVar16 = &p_Var13[0x11].InternalHigh;
+          pUVar16 = &p_Var12[0x11].InternalHigh;
           local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
           FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f670,pUVar16,p_Var18);
           if ((DAT_0 & 8) != 0) {
             pUVar16 = &local_a48;
             McTemplateU0z_EventWriteTransfer
                       (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                        (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)pUVar16);
           }
         }
-        EnterCriticalSection(p_Var1);
-        *(int *)((longlong)&p_Var13[8].InternalHigh + 4) = iVar6;
-        InitiateCallContextCleanup((longlong)p_Var13,2,pUVar16,(ulonglong)p_Var18);
+        EnterCriticalSection(p_Var2);
+        *(int *)((longlong)&p_Var12[8].InternalHigh + 4) = iVar7;
+        InitiateCallContextCleanup((longlong)p_Var12,2,pUVar16,(ulonglong)p_Var18);
         PostNewHttpRequest();
       }
     }
     else {
-      if (iVar6 == 0xea) {
+      if (iVar7 == 0xea) {
         if ((DAT_0 & 0x10) != 0) {
-          pUVar16 = &p_Var13[0x11].InternalHigh;
+          pUVar16 = &p_Var12[0x11].InternalHigh;
           local_a48._0_4_ = (uint)local_a48._2_2_ << 0x10;
           FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f7e0,pUVar16,p_Var18);
           if ((DAT_0 & 0x10) != 0) {
             pUVar16 = &local_a48;
             McTemplateU0z_EventWriteTransfer
                       (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                        (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,(wchar_t *)pUVar16);
           }
         }
-        p_Var1 = (LPCRITICAL_SECTION)(p_Var13 + 9);
-        EnterCriticalSection(p_Var1);
-        puVar2 = (uint *)((longlong)&p_Var13[7].hEvent + 4);
-        *puVar2 = *puVar2 | 2;
-        LeaveCriticalSection(p_Var1);
-        iVar6 = ProcessReceivedHttpRequest
+        p_Var2 = (LPCRITICAL_SECTION)(p_Var12 + 9);
+        EnterCriticalSection(p_Var2);
+        puVar1 = (uint *)((longlong)&p_Var12[7].hEvent + 4);
+        *puVar1 = *puVar1 | 2;
+        LeaveCriticalSection(p_Var2);
+        iVar7 = ProcessReceivedHttpRequest
                           ((longlong)p_Var19,(undefined2 *)local_2a78,pUVar16,p_Var18);
         lVar3 = SstpSvcGlobals;
-        if (iVar6 == 0) {
+        if (iVar7 == 0) {
           *param_3 = 0;
           param_3[1] = 0;
           param_3[2] = 0;
           param_3[3] = 0;
           StartThreadpoolIo(*(PTP_IO *)(lVar3 + 0xa8));
           pUVar16 = (ULONG_PTR *)0x0;
-          uVar7 = HttpReceiveHttpRequest(*(undefined8 *)(SstpSvcGlobals + 0x40),param_3[0xe]);
+          uVar5 = HttpReceiveHttpRequest(*(undefined8 *)(SstpSvcGlobals + 0x40),param_3[0xe]);
           p_Var18 = p_Var19;
-          if ((uVar7 == 0x3e5) || (uVar7 == 0)) goto LAB_1;
+          if ((uVar5 == 0x3e5) || (uVar5 == 0)) goto LAB_1;
           CancelThreadpoolIo(*(PTP_IO *)(SstpSvcGlobals + 0xa8));
           if ((DAT_0 & 8) != 0) {
-            pUVar16 = &p_Var13[0x11].InternalHigh;
+            pUVar16 = &p_Var12[0x11].InternalHigh;
             local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
-            p_Var19 = (_OVERLAPPED *)(ulonglong)uVar7;
+            p_Var19 = (_OVERLAPPED *)(ulonglong)uVar5;
             FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f830,pUVar16,p_Var19);
             if ((DAT_0 & 8) != 0) {
               pUVar16 = &local_a48;
               McTemplateU0z_EventWriteTransfer
                         (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                          (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)pUVar16);
             }
           }
-          EnterCriticalSection(p_Var1);
-          *(uint *)((longlong)&p_Var13[8].InternalHigh + 4) = uVar7;
+          EnterCriticalSection(p_Var2);
+          *(uint *)((longlong)&p_Var12[8].InternalHigh + 4) = uVar5;
         }
         else {
           p_Var19 = p_Var18;
           if ((DAT_0 & 8) != 0) {
-            pUVar16 = &p_Var13[0x11].InternalHigh;
+            pUVar16 = &p_Var12[0x11].InternalHigh;
             local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
             FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f670,pUVar16,p_Var18);
             p_Var19 = p_Var18;
             if ((DAT_0 & 8) != 0) {
               pUVar16 = &local_a48;
               McTemplateU0z_EventWriteTransfer
                         (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                          (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)pUVar16);
               p_Var19 = p_Var18;
             }
           }
-          EnterCriticalSection(p_Var1);
-          *(int *)((longlong)&p_Var13[8].InternalHigh + 4) = iVar6;
-        }
-        InitiateCallContextCleanup((longlong)p_Var13,2,pUVar16,(ulonglong)p_Var19);
-        DereferenceRefCount((int *)&p_Var13[6].u);
+          EnterCriticalSection(p_Var2);
+          *(int *)((longlong)&p_Var12[8].InternalHigh + 4) = iVar7;
+        }
+        InitiateCallContextCleanup((longlong)p_Var12,2,pUVar16,(ulonglong)p_Var19);
+        DereferenceRefCount((int *)&p_Var12[6].u);
         PostNewHttpRequest();
         p_Var18 = p_Var19;
         goto LAB_1;
       }
-      if (iVar6 != 0x3e3) {
-        if ((DAT_0 & 8) == 0) goto LAB_18000c575;
+      if (iVar7 != 0x3e3) {
+        if ((DAT_0 & 8) == 0) goto LAB_18000c6c7;
         local_a48._0_4_ = (uint)local_a48._2_2_ << 0x10;
         FormatRRASErrorString
-                  ((STRSAFE_LPWSTR)&local_a48,0x18001f8b0,&p_Var13[0x11].InternalHigh,p_Var14);
+                  ((STRSAFE_LPWSTR)&local_a48,0x18001f8b0,&p_Var12[0x11].InternalHigh,p_Var13);
 LAB_5:
-        p_Var18 = p_Var14;
-        if ((DAT_0 & 8) == 0) goto LAB_18000c575;
-        pwVar15 = (wchar_t *)&local_a48;
+        p_Var18 = p_Var13;
+        if ((DAT_0 & 8) == 0) goto LAB_18000c6c7;
+        pwVar14 = (wchar_t *)&local_a48;
         goto LAB_2;
       }
-      EnterCriticalSection((LPCRITICAL_SECTION)(p_Var13 + 9));
-      *(undefined4 *)((longlong)&p_Var13[8].InternalHigh + 4) = 0x3e3;
+      EnterCriticalSection((LPCRITICAL_SECTION)(p_Var12 + 9));
+      *(undefined4 *)((longlong)&p_Var12[8].InternalHigh + 4) = 0x3e3;
 LAB_6:
-      InitiateCallContextCleanup((longlong)p_Var13,2,pUVar16,(ulonglong)p_Var18);
+      InitiateCallContextCleanup((longlong)p_Var12,2,pUVar16,(ulonglong)p_Var18);
     }
 LAB_4:
-    p_Var11 = &p_Var13[6].u;
+    p_Var10 = &p_Var12[6].u;
   }
   else {
-    if (uVar7 == 0x4568) {
+    if (uVar5 == 0x4568) {
       if ((DAT_0 & 0x10) != 0) {
-        pwVar15 = L"TerminatePartialConnection returns";
+        pwVar14 = L"TerminatePartialConnection returns";
         McTemplateU0z_EventWriteTransfer
                   (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,(PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo
                    ,L"TerminatePartialConnection returns");
       }
-      pwVar15 = (wchar_t *)CONCAT71((int7)((ulonglong)pwVar15 >> 8),1);
-      puVar10 = (undefined8 *)param_3[7];
+      uVar15 = CONCAT71((int7)((ulonglong)pwVar14 >> 8),1);
+      p_Var12 = (LPOVERLAPPED)param_3[7];
       FreeBufferToPool((uint *)(SstpSvcGlobals + 0x1a8),(longlong)param_3,'\x01');
-      EnterCriticalSection((LPCRITICAL_SECTION)(puVar10 + 0x24));
-      *(uint *)((longlong)puVar10 + 0xfc) = *(uint *)((longlong)puVar10 + 0xfc) & 0xffffdfff;
-LAB_7:
-      InitiateCallContextCleanup((longlong)puVar10,2,pwVar15,(ulonglong)p_Var18);
-      goto LAB_1;
-    }
-    if (uVar7 != 0x456b) {
-      if (uVar7 == 0x456d) {
-        p_Var13 = (LPOVERLAPPED)param_3[7];
-        if (iVar6 == 0) {
+      EnterCriticalSection((LPCRITICAL_SECTION)(p_Var12 + 9));
+      puVar1 = (uint *)((longlong)&p_Var12[7].hEvent + 4);
+      *puVar1 = *puVar1 & 0xffffdfff;
+      InitiateCallContextCleanup((longlong)p_Var12,2,uVar15,(ulonglong)p_Var18);
+      uVar5 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+      if (uVar5 == 0) goto LAB_1;
+      goto LAB_4;
+    }
+    if (uVar5 != 0x456b) {
+      if (uVar5 == 0x456d) {
+        p_Var12 = (LPOVERLAPPED)param_3[7];
+        if (iVar7 == 0) {
           if ((DAT_0 & 0x10) != 0) {
-            pwVar15 = (wchar_t *)&p_Var13[0x11].InternalHigh;
+            pwVar14 = (wchar_t *)&p_Var12[0x11].InternalHigh;
             local_a48._0_4_ = (uint)local_a48._2_2_ << 0x10;
-            pwVar12 = L"CoId=%hs:Successfully established the Layer-2";
-            FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f950,(size_t *)pwVar15,p_Var18);
+            pwVar11 = L"CoId=%hs:Successfully established the Layer-2";
+            FormatRRASErrorString((STRSAFE_LPWSTR)&local_a48,0x18001f950,(size_t *)pwVar14,p_Var18);
             if ((DAT_0 & 0x10) != 0) {
-              pwVar15 = (wchar_t *)&local_a48;
-              pwVar12 = L"㚱က\x04";
+              pwVar14 = (wchar_t *)&local_a48;
+              pwVar11 = L"㚱က\x04";
               McTemplateU0z_EventWriteTransfer
                         (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
-                         (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,pwVar15);
-            }
-          }
-          IndicateCallConnectedToTPI(p_Var13,pwVar12,pwVar15,(uint *)p_Var18);
+                         (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,pwVar14);
+            }
+          }
+          IndicateCallConnectedToTPI(p_Var12,pwVar11,pwVar14,(uint *)p_Var18);
         }
         else {
-          bVar4 = IsProxyCall((longlong)p_Var13);
+          bVar4 = IsProxyCall((longlong)p_Var12);
           if ((int)CONCAT71(extraout_var_00,bVar4) == 0) {
             p_Var18 = (_OVERLAPPED *)0x4;
             local_2a78[0] = 0;
-            DVar5 = SyncDeviceControl(*(HANDLE *)(SstpSvcGlobals + 0x118),0x128040,&p_Var13[7].u,4,
+            DVar6 = SyncDeviceControl(*(HANDLE *)(SstpSvcGlobals + 0x118),0x128040,&p_Var12[7].u,4,
                                       (LPVOID)0x0,0,local_2a78);
-            if ((DVar5 != 0) && ((DAT_0 & 8) != 0)) {
+            if ((DVar6 != 0) && ((DAT_0 & 8) != 0)) {
               local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
-              p_Var18 = (_OVERLAPPED *)(ulonglong)DVar5;
+              p_Var18 = (_OVERLAPPED *)(ulonglong)DVar6;
               FormatRRASErrorString
-                        ((STRSAFE_LPWSTR)&local_a48,0x18001d2d0,&p_Var13[0x11].InternalHigh,p_Var18)
+                        ((STRSAFE_LPWSTR)&local_a48,0x18001d2d0,&p_Var12[0x11].InternalHigh,p_Var18)
               ;
 LAB_3:
               if ((DAT_0 & 8) != 0) {
                 McTemplateU0z_EventWriteTransfer
                           (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                            (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)&local_a48);
               }
             }
           }
         }
       }
       else {
-        if (uVar7 == 0x456f) {
+        if (uVar5 == 0x456f) {
           EnterCriticalSection((LPCRITICAL_SECTION)(param_3 + 0xf));
           *(uint *)((longlong)param_3 + 0x54) = *(uint *)((longlong)param_3 + 0x54) & 0xffffdfff;
-          puVar10 = param_3 + -0x15;
+          InitiateCallContextCleanup((longlong)(param_3 + -0x15),2,pwVar14,(ulonglong)p_Var18);
+          uVar5 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+          if (uVar5 == 0) goto LAB_1;
+          p_Var10 = (_union_540 *)(param_3 + 5);
           goto LAB_7;
         }
-        if (uVar7 != 0x4570) {
-          if (uVar7 == 0x4572) {
-            if ((iVar6 != 0) && ((DAT_0 & 8) != 0)) {
+        if (uVar5 != 0x4570) {
+          if (uVar5 == 0x4572) {
+            if ((iVar7 != 0) && ((DAT_0 & 8) != 0)) {
               local_a48._0_4_ = (uint)local_a48._2_2_ << 0x10;
               FormatRRASErrorString
-                        ((STRSAFE_LPWSTR)&local_a48,0x18001f9b0,(size_t *)p_Var14,p_Var18);
+                        ((STRSAFE_LPWSTR)&local_a48,0x18001f9b0,(size_t *)p_Var13,p_Var18);
               if ((DAT_0 & 8) != 0) {
                 McTemplateU0z_EventWriteTransfer
                           (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                            (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,(wchar_t *)&local_a48);
               }
             }
             FreeBufferToPool((uint *)(SstpSvcGlobals + 0x1a8),(longlong)param_3,'\x01');
           }
           goto LAB_1;
         }
-        p_Var13 = (LPOVERLAPPED)param_3[7];
-        if (iVar6 == 0) {
+        p_Var12 = (LPOVERLAPPED)param_3[7];
+        if (iVar7 == 0) {
           *(undefined4 *)((longlong)param_3 + 0x5c) = param_5;
-          *(DWORD *)(param_3 + 0xb) = p_Var13[7].u.s.Offset;
-          bVar4 = IsProxyCall((longlong)p_Var13);
+          *(DWORD *)(param_3 + 0xb) = p_Var12[7].u.s.Offset;
+          bVar4 = IsProxyCall((longlong)p_Var12);
           if ((int)CONCAT71(extraout_var,bVar4) == 0) {
-            ProcessReceivedBytes((longlong)param_3,pwVar12,pwVar15,p_Var18);
+            ProcessReceivedBytes((longlong)param_3,pwVar11,pwVar14,p_Var18);
           }
           else {
-            ProxySendToRelatedCtx(param_3,pwVar12,pwVar15,(ulonglong)p_Var18);
-          }
-          PostReceiveOnCall((longlong)p_Var13,pwVar12,pwVar15,(uint *)p_Var18);
+            ProxySendToRelatedCtx(param_3,pwVar11,pwVar14,(ulonglong)p_Var18);
+          }
+          PostReceiveOnCall((longlong)p_Var12,pwVar11,pwVar14,(uint *)p_Var18);
         }
         else {
           FreeBufferToPool((uint *)(SstpSvcGlobals + 0x1a8),(longlong)param_3,'\x01');
         }
       }
       goto LAB_4;
     }
     EnterCriticalSection((LPCRITICAL_SECTION)(param_3 + 0x14));
-    InitiateCallContextCleanup((longlong)(param_3 + -0x10),1,pwVar15,(ulonglong)p_Var18);
-    p_Var11 = (_union_540 *)(param_3 + 10);
-  }
-  DereferenceRefCount((int *)p_Var11);
+    InitiateCallContextCleanup((longlong)(param_3 + -0x10),1,pwVar14,(ulonglong)p_Var18);
+    p_Var10 = (_union_540 *)(param_3 + 10);
+  }
+LAB_7:
+  DereferenceRefCount((int *)p_Var10);
 LAB_1:
   if ((DAT_0 & 0x10) != 0) {
     local_a48._0_4_ = (uint)local_a48 & 0xffff0000;
     FormatRRASErrorString
               ((STRSAFE_LPWSTR)&local_a48,0x18001cb50,
                (size_t *)L"HttpThreadPoolRequestQueueCallback",p_Var18);
     if ((DAT_0 & 0x10) != 0) {
       McTemplateU0z_EventWriteTransfer
                 (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,(PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceInfo,
                  (wchar_t *)&local_a48);
     }
   }
   return;
 }
 

```


## DisconnectServerHttpCallContext

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.86|
|i_ratio|0.62|
|m_ratio|0.93|
|b_ratio|0.87|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|DisconnectServerHttpCallContext|DisconnectServerHttpCallContext|
|fullname|DisconnectServerHttpCallContext|DisconnectServerHttpCallContext|
|refcount|2|2|
|`length`|493|556|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>FormatRRASErrorString<br>HTTPAPI.DLL::HttpSendResponseEntityBody<br>InitiateCallContextCleanup<br>McTemplateU0z_EventWriteTransfer<br>TerminatePartialConnection<br>__security_check_cookie<br>memset</summary></details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>DereferenceRefCount<br>Feature_2530182457__private_IsEnabledDeviceUsageNoInline<br>FormatRRASErrorString<br>HTTPAPI.DLL::HttpSendResponseEntityBody<br>InitiateCallContextCleanup<br>McTemplateU0z_EventWriteTransfer<br>TerminatePartialConnection</summary>__security_check_cookie<br>memset</details>|
|calling|InitiateCallContextCleanup|InitiateCallContextCleanup|
|paramcount|4|4|
|`address`|18000ba28|18000bad4|
|sig|undefined __fastcall DisconnectServerHttpCallContext(longlong param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4)|undefined __fastcall DisconnectServerHttpCallContext(longlong param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### DisconnectServerHttpCallContext Called Diff


```diff
--- DisconnectServerHttpCallContext called
+++ DisconnectServerHttpCallContext called
@@ -4,0 +5,2 @@
+DereferenceRefCount
+Feature_2530182457__private_IsEnabledDeviceUsageNoInline
```


### DisconnectServerHttpCallContext Diff


```diff
--- DisconnectServerHttpCallContext
+++ DisconnectServerHttpCallContext
@@ -1,85 +1,99 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 
 void DisconnectServerHttpCallContext
                (longlong param_1,undefined8 param_2,undefined8 param_3,ulonglong param_4)
 
 {
-  LPCRITICAL_SECTION lpCriticalSection;
   undefined8 *puVar1;
   uint uVar2;
   wchar_t *pwVar3;
   undefined1 auStack_868 [32];
   undefined8 local_848;
   undefined8 local_840;
   undefined8 local_838;
   undefined4 local_830;
   undefined8 *local_828;
   undefined8 local_820;
   uint local_818;
   undefined1 local_814 [2044];
   ulonglong local_18;
   
   local_18 = __security_cookie ^ (ulonglong)auStack_868;
   local_818 = 0;
   pwVar3 = (wchar_t *)0x7fc;
   memset(local_814,0,0x7fc);
-  lpCriticalSection = (LPCRITICAL_SECTION)(param_1 + 0x120);
   if ((*(uint *)(param_1 + 0xfc) & 2) == 0) {
     *(undefined4 *)(param_1 + 200) = 0x456f;
     *(undefined8 *)(param_1 + 0xa8) = 0;
     *(undefined8 *)(param_1 + 0xb0) = 0;
     *(undefined8 *)(param_1 + 0xb8) = 0;
     *(undefined8 *)(param_1 + 0xc0) = 0;
-    LeaveCriticalSection(lpCriticalSection);
+    uVar2 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+    if (uVar2 != 0) {
+      LOCK();
+      *(int *)(param_1 + 0xd0) = *(int *)(param_1 + 0xd0) + 1;
+      UNLOCK();
+    }
+    LeaveCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
     StartThreadpoolIo(*(PTP_IO *)(SstpSvcGlobals + 0xa8));
     param_4 = 0;
     local_820 = 0;
     pwVar3 = (wchar_t *)0x1;
     local_830 = 0;
     local_838 = 0;
     local_840 = 0;
     local_848 = 0;
     local_828 = (undefined8 *)(param_1 + 0xa8);
     uVar2 = HttpSendResponseEntityBody
                       (*(undefined8 *)(SstpSvcGlobals + 0x40),*(undefined8 *)(param_1 + 0x110));
     if (uVar2 == 0x3e5) {
       return;
     }
     if (uVar2 == 0) {
       return;
     }
     if ((DAT_0 & 8) != 0) {
       pwVar3 = (wchar_t *)(param_1 + 0x228);
       local_818 = local_818 & 0xffff0000;
       param_4 = (ulonglong)uVar2;
       FormatRRASErrorString((STRSAFE_LPWSTR)&local_818,0x18001ea60,(size_t *)pwVar3,param_4);
       if ((DAT_0 & 8) != 0) {
         pwVar3 = (wchar_t *)&local_818;
         McTemplateU0z_EventWriteTransfer
                   (&MICROSOFT_WINDOWS_RRAS_PROVIDER_Context,
                    (PCEVENT_DESCRIPTOR)&RasSSTPSvcTraceError,pwVar3);
       }
     }
     CancelThreadpoolIo(*(PTP_IO *)(SstpSvcGlobals + 0xa8));
   }
   else {
     puVar1 = *(undefined8 **)(param_1 + 0x100);
     *(uint *)(param_1 + 0xfc) = *(uint *)(param_1 + 0xfc) & 0xfffffffd;
     *(undefined8 *)(param_1 + 0x100) = 0;
     puVar1[7] = param_1;
-    LeaveCriticalSection(lpCriticalSection);
+    uVar2 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+    if (uVar2 != 0) {
+      LOCK();
+      *(int *)(param_1 + 0xd0) = *(int *)(param_1 + 0xd0) + 1;
+      UNLOCK();
+    }
+    LeaveCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
     uVar2 = TerminatePartialConnection(*(undefined8 *)(param_1 + 0x110),puVar1,pwVar3,param_4);
     if (uVar2 == 0) {
       return;
     }
     if (uVar2 == 0x3e5) {
       return;
     }
   }
-  EnterCriticalSection(lpCriticalSection);
+  uVar2 = Feature_2530182457__private_IsEnabledDeviceUsageNoInline();
+  if (uVar2 != 0) {
+    DereferenceRefCount((int *)(param_1 + 0xd0));
+  }
+  EnterCriticalSection((LPCRITICAL_SECTION)(param_1 + 0x120));
   *(uint *)(param_1 + 0xfc) = *(uint *)(param_1 + 0xfc) & 0xffffdfff;
   InitiateCallContextCleanup(param_1,2,pwVar3,param_4);
   return;
 }
 

```


## wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,length,sig,address|
|ratio|0.4|
|i_ratio|0.37|
|m_ratio|0.9|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|fullname|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|refcount|1|1|
|`length`|76|91|
|called|||
|calling|wil_details_IsEnabledFallback|wil_details_IsEnabledFallback|
|paramcount|2|3|
|`address`|18000b744|18000b7dc|
|`sig`|undefined __fastcall wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1, int param_2)|undefined __fastcall wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1, int param_2, undefined8 * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath Diff


```diff
--- wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
+++ wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
@@ -1,41 +1,52 @@
 
-void wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1,int param_2)
+void wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
+               (uint param_1,int param_2,undefined8 *param_3)
 
 {
-  uint uVar1;
+  uint *puVar1;
   uint uVar2;
   uint uVar3;
-  bool bVar4;
+  uint uVar4;
+  bool bVar5;
   
+  puVar1 = (uint *)*param_3;
   if (param_2 == 3) {
-    uVar3 = 0x10;
+    uVar4 = 0x10;
   }
   else {
     if (param_2 != 4) {
       return;
     }
-    uVar3 = 0x20;
+    uVar4 = 0x20;
   }
-  if ((Feature_1207409977__private_featureState & 2) != 0) {
-    uVar2 = Feature_1207409977__private_featureState;
-    while ((uVar2 & 1) == (param_1 & 1)) {
-      LOCK();
-      bVar4 = uVar2 == Feature_1207409977__private_featureState;
-      uVar1 = uVar3 | uVar2;
-      if (!bVar4) {
-        uVar2 = Feature_1207409977__private_featureState;
-        uVar1 = Feature_1207409977__private_featureState;
-      }
-      Feature_1207409977__private_featureState = uVar1;
-      UNLOCK();
-      if (bVar4) {
-        return;
-      }
-      if ((uVar2 & 2) == 0) {
-        return;
+  if ((*(char *)((longlong)param_3 + 0x1e) == '\0') && (*(char *)((longlong)param_3 + 0x1d) == '\0')
+     ) {
+    if ((*puVar1 & 2) != 0) {
+      uVar3 = *puVar1;
+      while ((uVar3 & 1) == (param_1 & 1)) {
+        LOCK();
+        uVar2 = *puVar1;
+        bVar5 = uVar3 == uVar2;
+        if (bVar5) {
+          *puVar1 = uVar4 | uVar3;
+          uVar2 = uVar3;
+        }
+        UNLOCK();
+        if (bVar5) {
+          return;
+        }
+        uVar3 = uVar2;
+        if ((uVar2 & 2) == 0) {
+          return;
+        }
       }
     }
+  }
+  else {
+    LOCK();
+    *puVar1 = *puVar1 | uVar4;
+    UNLOCK();
   }
   return;
 }
 

```


## IsProxyCall

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|code,name,fullname,refcount,length,sig,address,calling,called|
|ratio|0.43|
|i_ratio|0.05|
|m_ratio|0.63|
|b_ratio|0.26|
|match_types|Implied Match|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|`name`|IsProxyCall|Feature_2530182457__private_IsEnabledDeviceUsageNoInline|
|`fullname`|IsProxyCall|Feature_2530182457__private_IsEnabledDeviceUsageNoInline|
|`refcount`|10|9|
|`length`|109|51|
|`called`|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockShared<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockShared|wil_details_IsEnabledFallback|
|`calling`|HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>ProxySendToRelatedCtx<br>SstpWebReceiveResponseCompletion|DisconnectServerHttpCallContext<br>HttpThreadPoolRequestQueueCallback<br>ProxySendToRelatedCtx<br>SstpWebReceiveResponseCompletion|
|paramcount|1|0|
|`address`|1800068f0|18000bd08|
|`sig`|bool __fastcall IsProxyCall(longlong param_1)|uint __fastcall Feature_2530182457__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### IsProxyCall Called Diff


```diff
--- IsProxyCall called
+++ Feature_2530182457__private_IsEnabledDeviceUsageNoInline called
@@ -1,2 +1 @@
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockShared
-API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockShared
+wil_details_IsEnabledFallback
```


### IsProxyCall Calling Diff


```diff
--- IsProxyCall calling
+++ Feature_2530182457__private_IsEnabledDeviceUsageNoInline calling
@@ -0,0 +1 @@
+DisconnectServerHttpCallContext
@@ -2 +2,0 @@
-IndicateCallConnectedToTPI
```


### IsProxyCall Diff


```diff
--- IsProxyCall
+++ Feature_2530182457__private_IsEnabledDeviceUsageNoInline
@@ -1,19 +1,15 @@
 
-bool IsProxyCall(longlong param_1)
+uint Feature_2530182457__private_IsEnabledDeviceUsageNoInline(void)
 
 {
   uint uVar1;
-  bool bVar2;
+  ulonglong local_res8;
   
-  AcquireSRWLockShared((PSRWLOCK)(SstpSvcGlobals + 0x300));
-  uVar1 = *(uint *)(SstpSvcGlobals + 0x308);
-  ReleaseSRWLockShared((PSRWLOCK)(SstpSvcGlobals + 0x300));
-  if (((uVar1 & 1) == 0) || (param_1 == 0)) {
-    bVar2 = false;
+  local_res8 = (ulonglong)Feature_2530182457__private_featureState;
+  if ((Feature_2530182457__private_featureState & 0x10) != 0) {
+    return Feature_2530182457__private_featureState & 1;
   }
-  else {
-    bVar2 = *(longlong *)(param_1 + 0x270) != 0;
-  }
-  return bVar2;
+  uVar1 = wil_details_IsEnabledFallback(local_res8,3,&Feature_2530182457__private_descriptor);
+  return uVar1;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|EnterCriticalSection|EnterCriticalSection|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection|
|`refcount`|94|99|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>AcquireHostRouteInfoContext<br>AddBufferBlockToPool<br>AllocateAndInitializeCallContext<br>CleanupCallCtx<br>CleanupHostRouteEntry<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>ForwardMakeCallRequest<br>FreeBufferPool</summary>FreeBufferToPool<br>GetBufferFromPool<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProxySendToRelatedCtx<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>SstpMakeCall<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>SstpWebSendRequestEntityCompletion</details>|<details><summary>Expand for full list:<br>AcquireHostRouteInfoContext<br>AddBufferBlockToPool<br>AllocateAndInitializeCallContext<br>CleanupCallCtx<br>CleanupHostRouteEntry<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>ForwardMakeCallRequest<br>FreeBufferPool</summary>FreeBufferToPool<br>GetBufferFromPool<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProxySendToRelatedCtx<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>SstpMakeCall<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>SstpWebSendRequestEntityCompletion</details>|
|paramcount|1|1|
|address|EXTERNAL:00000026|EXTERNAL:00000026|
|sig|void __stdcall EnterCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall EnterCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## McTemplateU0z_EventWriteTransfer

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|McTemplateU0z_EventWriteTransfer|McTemplateU0z_EventWriteTransfer|
|fullname|McTemplateU0z_EventWriteTransfer|McTemplateU0z_EventWriteTransfer|
|`refcount`|239|240|
|length|122|122|
|called|McGenEventWrite_EventWriteTransfer<br>__security_check_cookie|McGenEventWrite_EventWriteTransfer<br>__security_check_cookie|
|calling|<details><summary>Expand for full list:<br>AddExistingEntryToXmlWriter<br>AddNewEntryToXmlWriter<br>AddNewTenantEntry<br>AllocateAndInitializeCallContext<br>AsyncSstpDeviceControl<br>CheckClientAccessToXmlFile<br>CleanupCallCtx<br>CreateTenantGatewayEntryStruct<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext</summary>DisconnectSstpCallFromTpi<br>FileStream::OpenFile<br>FindSstpGatewayByGroup<br>FlushXmlWriter<br>ForwardMakeCallRequest<br>GetXmlFilePath<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitializeService<br>InitializeSstpServer<br>InitializeTransport<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>LoadSstpProxyConfigFromXmlFile<br>LogEventWithErrorParameter<br>NotifyMakeCallComplete<br>OpenXmlWriter<br>PostNewHttpRequest<br>PostNotificationBufferToDevice<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProcessReceivedHttpRequest<br>ProxySendToRelatedCtx<br>ReplaceGatewayList<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>ServiceHandlerEx<br>ServiceMain<br>SetHostRoutLibParams<br>ShutdownSstpServer<br>SstpMakeCall<br>SstpSvcCreateUpdateTenantGatewayMapping<br>SstpSvcGetConfig<br>SstpSvcGetTenantGatewayMapping<br>SstpSvcRemoveTenantGatewayMapping<br>SstpSvcSetConfig<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>StartServiceCleanup<br>TenantGatewayMap::DeleteSstpProxyRules<br>TenantGatewayMap::GetFileStream<br>TenantGatewayMap::TenantGatewayMap<br>TerminatePartialConnection</details>|<details><summary>Expand for full list:<br>AddExistingEntryToXmlWriter<br>AddNewEntryToXmlWriter<br>AddNewTenantEntry<br>AllocateAndInitializeCallContext<br>AsyncSstpDeviceControl<br>CheckClientAccessToXmlFile<br>CleanupCallCtx<br>CreateTenantGatewayEntryStruct<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext</summary>DisconnectSstpCallFromTpi<br>FileStream::OpenFile<br>FindSstpGatewayByGroup<br>FlushXmlWriter<br>ForwardMakeCallRequest<br>GetXmlFilePath<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitializeService<br>InitializeSstpServer<br>InitializeTransport<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>LoadSstpProxyConfigFromXmlFile<br>LogEventWithErrorParameter<br>NotifyMakeCallComplete<br>OpenXmlWriter<br>PostNewHttpRequest<br>PostNotificationBufferToDevice<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProcessReceivedHttpRequest<br>ProxySendToRelatedCtx<br>ReplaceGatewayList<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>ServiceHandlerEx<br>ServiceMain<br>SetHostRoutLibParams<br>ShutdownSstpServer<br>SstpMakeCall<br>SstpSvcCreateUpdateTenantGatewayMapping<br>SstpSvcGetConfig<br>SstpSvcGetTenantGatewayMapping<br>SstpSvcRemoveTenantGatewayMapping<br>SstpSvcSetConfig<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>StartServiceCleanup<br>TenantGatewayMap::DeleteSstpProxyRules<br>TenantGatewayMap::GetFileStream<br>TenantGatewayMap::TenantGatewayMap<br>TerminatePartialConnection</details>|
|paramcount|3|3|
|`address`|180009110|1800091a0|
|sig|undefined __fastcall McTemplateU0z_EventWriteTransfer(REGHANDLE * param_1, PCEVENT_DESCRIPTOR param_2, wchar_t * param_3)|undefined __fastcall McTemplateU0z_EventWriteTransfer(REGHANDLE * param_1, PCEVENT_DESCRIPTOR param_2, wchar_t * param_3)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## FormatRRASErrorString

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.91|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|FormatRRASErrorString|FormatRRASErrorString|
|fullname|FormatRRASErrorString|FormatRRASErrorString|
|`refcount`|246|247|
|length|40|40|
|called|StringVPrintfWorkerW|StringVPrintfWorkerW|
|calling|<details><summary>Expand for full list:<br>AcquireHostRouteInfoContext<br>AddExistingEntryToXmlWriter<br>AddNewEntryToXmlWriter<br>AddNewTenantEntry<br>AllocateAndInitializeCallContext<br>AsyncSstpDeviceControl<br>CheckClientAccessToXmlFile<br>CleanupCallCtx<br>CleanupHostRouteEntry<br>DeinitializeTransport<br>DisconnectClientHttpCallContext</summary>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>FileStream::OpenFile<br>FindSstpGatewayByGroup<br>FlushXmlWriter<br>ForwardMakeCallRequest<br>GetXmlFilePath<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitializeHostRouteInfo<br>InitializeService<br>InitializeSstpServer<br>InitializeTransport<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>LoadSstpProxyConfigFromXmlFile<br>LogEventWithErrorParameter<br>NotifyMakeCallComplete<br>OpenXmlWriter<br>PostNewHttpRequest<br>PostNotificationBufferToDevice<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProcessReceivedHttpRequest<br>ProxySendToRelatedCtx<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>ServiceHandlerEx<br>ServiceMain<br>ShutdownSstpServer<br>SstpMakeCall<br>SstpSvcCreateUpdateTenantGatewayMapping<br>SstpSvcGetConfig<br>SstpSvcGetTenantGatewayMapping<br>SstpSvcRemoveTenantGatewayMapping<br>SstpSvcSetConfig<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>StartServiceCleanup<br>TenantGatewayMap::DeleteSstpProxyRules<br>TenantGatewayMap::GetFileStream<br>TenantGatewayMap::TenantGatewayMap<br>TerminatePartialConnection</details>|<details><summary>Expand for full list:<br>AcquireHostRouteInfoContext<br>AddExistingEntryToXmlWriter<br>AddNewEntryToXmlWriter<br>AddNewTenantEntry<br>AllocateAndInitializeCallContext<br>AsyncSstpDeviceControl<br>CheckClientAccessToXmlFile<br>CleanupCallCtx<br>CleanupHostRouteEntry<br>DeinitializeTransport<br>DisconnectClientHttpCallContext</summary>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>FileStream::OpenFile<br>FindSstpGatewayByGroup<br>FlushXmlWriter<br>ForwardMakeCallRequest<br>GetXmlFilePath<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitializeHostRouteInfo<br>InitializeService<br>InitializeSstpServer<br>InitializeTransport<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>LoadSstpProxyConfigFromXmlFile<br>LogEventWithErrorParameter<br>NotifyMakeCallComplete<br>OpenXmlWriter<br>PostNewHttpRequest<br>PostNotificationBufferToDevice<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProcessReceivedHttpRequest<br>ProxySendToRelatedCtx<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>ServiceHandlerEx<br>ServiceMain<br>ShutdownSstpServer<br>SstpMakeCall<br>SstpSvcCreateUpdateTenantGatewayMapping<br>SstpSvcGetConfig<br>SstpSvcGetTenantGatewayMapping<br>SstpSvcRemoveTenantGatewayMapping<br>SstpSvcSetConfig<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>StartServiceCleanup<br>TenantGatewayMap::DeleteSstpProxyRules<br>TenantGatewayMap::GetFileStream<br>TenantGatewayMap::TenantGatewayMap<br>TerminatePartialConnection</details>|
|paramcount|4|4|
|`address`|180009320|1800093b0|
|sig|undefined __fastcall FormatRRASErrorString(STRSAFE_LPWSTR param_1, size_t param_2, size_t * param_3, undefined8 param_4)|undefined __fastcall FormatRRASErrorString(STRSAFE_LPWSTR param_1, size_t param_2, size_t * param_3, undefined8 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## InitiateSstpResponse

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|InitiateSstpResponse|InitiateSstpResponse|
|fullname|InitiateSstpResponse|InitiateSstpResponse|
|`refcount`|3|4|
|length|685|685|
|called|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>DereferenceRefCount<br>FormatRRASErrorString<br>HTTPAPI.DLL::HttpSendHttpResponse<br>InitiateCallContextCleanup<br>McTemplateU0z_EventWriteTransfer<br>__security_check_cookie<br>memset</summary></details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CancelThreadpoolIo<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::StartThreadpoolIo<br>DereferenceRefCount<br>FormatRRASErrorString<br>HTTPAPI.DLL::HttpSendHttpResponse<br>InitiateCallContextCleanup<br>McTemplateU0z_EventWriteTransfer<br>__security_check_cookie<br>memset</summary></details>|
|calling|SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion|SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion|
|paramcount|4|4|
|`address`|18000d120|18000d274|
|sig|undefined __fastcall InitiateSstpResponse(longlong param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4)|undefined __fastcall InitiateSstpResponse(longlong param_1, undefined8 param_2, undefined8 param_3, undefined8 param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## DereferenceRefCount

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|DereferenceRefCount|DereferenceRefCount|
|fullname|DereferenceRefCount|DereferenceRefCount|
|`refcount`|28|32|
|length|34|34|
|called|_guard_dispatch_icall$thunk$10345483385596137414|_guard_dispatch_icall$thunk$10345483385596137414|
|`calling`|<details><summary>Expand for full list:<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>NotifyMakeCallComplete<br>PostNewHttpRequest<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessNewCall<br>ReleaseHostRouteInfoContext<br>ResponseWaitTimeout</summary>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebSendRequestCompletion</details>|<details><summary>Expand for full list:<br>DisconnectServerHttpCallContext<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>NotifyMakeCallComplete<br>PostNewHttpRequest<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessNewCall<br>ProxySendToRelatedCtx</summary>ReleaseHostRouteInfoContext<br>ResponseWaitTimeout<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebSendRequestCompletion</details>|
|paramcount|1|1|
|address|180004ab0|180004ab0|
|sig|undefined __fastcall DereferenceRefCount(int * param_1)|undefined __fastcall DereferenceRefCount(int * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### DereferenceRefCount Calling Diff


```diff
--- DereferenceRefCount calling
+++ DereferenceRefCount calling
@@ -0,0 +1 @@
+DisconnectServerHttpCallContext
@@ -9,0 +11 @@
+ProxySendToRelatedCtx
```


## InitiateCallContextCleanup

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|0.96|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|InitiateCallContextCleanup|InitiateCallContextCleanup|
|fullname|InitiateCallContextCleanup|InitiateCallContextCleanup|
|`refcount`|34|35|
|length|1256|1256|
|called|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-IO-L1-1-0.DLL::CancelIoEx<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CloseThreadpoolWork<br>DereferenceRefCount<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>Feature_1207409977__private_IsEnabledDeviceUsageNoInline<br>FormatRRASErrorString<br>FreeBufferToPool</summary>HfFreeHandle32<br>InitiateCallContextCleanup<br>McTemplateU0z_EventWriteTransfer<br>NotifyMakeCallComplete<br>__security_check_cookie<br>memset</details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-IO-L1-1-0.DLL::CancelIoEx<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::EnterCriticalSection<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection<br>API-MS-WIN-CORE-THREADPOOL-L1-2-0.DLL::CloseThreadpoolWork<br>DereferenceRefCount<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>Feature_1207409977__private_IsEnabledDeviceUsageNoInline<br>FormatRRASErrorString<br>FreeBufferToPool</summary>HfFreeHandle32<br>InitiateCallContextCleanup<br>McTemplateU0z_EventWriteTransfer<br>NotifyMakeCallComplete<br>__security_check_cookie<br>memset</details>|
|calling|<details><summary>Expand for full list:<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>ForwardMakeCallRequest<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>PostReceiveOnCall<br>ProcessMakeCallRequest</summary>ProcessNewCall<br>ProcessReceivedBytesWorker<br>ProxySendToRelatedCtx<br>SendToNetworkWorker<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>SstpWebSendRequestEntityCompletion</details>|<details><summary>Expand for full list:<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>ForwardMakeCallRequest<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>PostReceiveOnCall<br>ProcessMakeCallRequest</summary>ProcessNewCall<br>ProcessReceivedBytesWorker<br>ProxySendToRelatedCtx<br>SendToNetworkWorker<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>SstpWebSendRequestEntityCompletion</details>|
|paramcount|4|4|
|address|1800020bc|1800020bc|
|sig|undefined __fastcall InitiateCallContextCleanup(longlong param_1, uint param_2, undefined8 param_3, ulonglong param_4)|undefined __fastcall InitiateCallContextCleanup(longlong param_1, uint param_2, undefined8 param_3, ulonglong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## IsProxyCall

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|IsProxyCall|IsProxyCall|
|fullname|IsProxyCall|IsProxyCall|
|`refcount`|10|13|
|length|109|109|
|called|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockShared<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockShared|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockShared<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::ReleaseSRWLockShared|
|calling|HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>ProxySendToRelatedCtx<br>SstpWebReceiveResponseCompletion|HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>ProxySendToRelatedCtx<br>SstpWebReceiveResponseCompletion|
|paramcount|1|1|
|`address`|1800068f0|180006590|
|sig|bool __fastcall IsProxyCall(longlong param_1)|bool __fastcall IsProxyCall(longlong param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection

### Match Info



|Key|sstp_8875.dll - sstp_9168.dll|
| :---: | :---: |
|diff_type|refcount|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|sstp_8875.dll|sstp_9168.dll|
| :---: | :---: | :---: |
|name|LeaveCriticalSection|LeaveCriticalSection|
|fullname|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection|API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::LeaveCriticalSection|
|`refcount`|87|93|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>AcquireHostRouteInfoContext<br>AddBufferBlockToPool<br>AllocateAndInitializeCallContext<br>CleanupCallCtx<br>CleanupHostRouteEntry<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>ForwardMakeCallRequest<br>FreeBufferPool</summary>GetBufferFromPool<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProxySendToRelatedCtx<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>SstpMakeCall<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>SstpWebSendRequestEntityCompletion</details>|<details><summary>Expand for full list:<br>AcquireHostRouteInfoContext<br>AddBufferBlockToPool<br>AllocateAndInitializeCallContext<br>CleanupCallCtx<br>CleanupHostRouteEntry<br>DeinitializeTransport<br>DisconnectClientHttpCallContext<br>DisconnectServerHttpCallContext<br>DisconnectSstpCallFromTpi<br>ForwardMakeCallRequest<br>FreeBufferPool</summary>GetBufferFromPool<br>HttpThreadPoolRequestQueueCallback<br>IndicateCallConnectedToTPI<br>InitiateCallContextCleanup<br>InitiateSstpResponse<br>PostReceiveOnCall<br>PostSendNotificationRequest<br>ProcessMakeCallRequest<br>ProcessNewCall<br>ProcessReceivedBytes<br>ProcessReceivedBytesWorker<br>ProxySendToRelatedCtx<br>ResponseWaitTimeout<br>SendToNetworkWorker<br>SstpMakeCall<br>SstpThreadPoolRequestQueueCallback<br>SstpWebReceiveResponseCompletion<br>SstpWebReceiveResponseEntityCompletion<br>SstpWebSendRequestCompletion<br>SstpWebSendRequestEntityCompletion</details>|
|paramcount|1|1|
|address|EXTERNAL:00000027|EXTERNAL:00000027|
|sig|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|void __stdcall LeaveCriticalSection(LPCRITICAL_SECTION lpCriticalSection)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|



<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-21T23:50:51</sub>