# ts_7309.dll-ts_7623.dll Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
* [Added](#added)
	* [wil::details::`dynamic_initializer_for_'g_enabledStateManager''](#wildetailsdynamic_initializer_for_g_enabledstatemanager)
	* [Feature_2464883000__private_IsEnabledDeviceUsageNoInline](#feature_2464883000__private_isenableddeviceusagenoinline)
	* [wil_RtlStagingConfig_QueryFeatureState](#wil_rtlstagingconfig_queryfeaturestate)
	* [wil_details_FeatureReporting_IncrementOpportunityInCache](#wil_details_featurereporting_incrementopportunityincache)
	* [wil_details_FeatureReporting_IncrementUsageInCache](#wil_details_featurereporting_incrementusageincache)
	* [wil_details_FeatureReporting_RecordUsageInCache](#wil_details_featurereporting_recordusageincache)
	* [wil_details_FeatureReporting_ReportUsageToService](#wil_details_featurereporting_reportusagetoservice)
	* [wil_details_FeatureReporting_ReportUsageToServiceDirect](#wil_details_featurereporting_reportusagetoservicedirect)
	* [wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState](#wil_details_featurestatecache_reevaluatecachedfeatureenabledstate)
	* [wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath](#wil_details_featurestatecache_tryenabledeviceusagefastpath)
	* [wil_details_GetCurrentFeatureEnabledState](#wil_details_getcurrentfeatureenabledstate)
	* [wil_details_IsEnabledFallback](#wil_details_isenabledfallback)
	* [wil_details_MapReportingKind](#wil_details_mapreportingkind)
	* [wil::details::unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>](#wildetailsunique_storagestruct_wildetailsresource_policystruct_feature_state_change_subscription_____ptr64void___cdeclstruct_feature_state_change_subscription_____ptr64void___cdecl_wildetailswilapi_unsubscribefeaturestatechangenotificationstruct_feature_state_change_subscription_____ptr64struct_wistdintegral_constantunsigned___int640struct_feature_state_change_subscription_____ptr64struct_feature_state_change_subscription_____ptr640stdnullptr_t_unique_storagestruct_wildetailsresource_policystruct_feature_state_change_subscription_____ptr64void___cdeclstruct_feature_state_change_subscription_____ptr64void___cdecl_wildetailswilapi_unsubscribefeaturestatechangenotificationstruct_feature_state_change_subscription_____ptr64struct_wistdintegral_constantunsigned___int640struct_feature_state_change_subscription_____ptr64struct_feature_state_change_subscription_____ptr640stdnullptr_t_)
	* [wil::details::EnabledStateManager::~EnabledStateManager](#wildetailsenabledstatemanagerenabledstatemanager)
	* [wil::details::EnsureSubscribedToFeatureConfigurationChanges](#wildetailsensuresubscribedtofeatureconfigurationchanges)
	* [wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl](#wildetailsenabledstatemanagerensuresubscribedtofeatureconfigurationchangesimpl)
	* [wil::details::EnabledStateManager::OnStateChange](#wildetailsenabledstatemanageronstatechange)
	* [wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges](#wildetailsenabledstatemanagersubscribefeaturestatecachetoconfigurationchanges)
	* [wil::details::SubscribeFeatureStateCacheToConfigurationChanges](#wildetailssubscribefeaturestatecachetoconfigurationchanges)
	* [wil::details::WilApi_RecordFeatureUsage](#wildetailswilapi_recordfeatureusage)
	* [wil::details::WilApi_RecordFeatureUsageReports](#wildetailswilapi_recordfeatureusagereports)
	* [wil::details::WilApi_UnsubscribeFeatureStateChangeNotification](#wildetailswilapi_unsubscribefeaturestatechangenotification)
	* [wil_details_RecordCachedUsage](#wil_details_recordcachedusage)
	* [wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''](#wildetailsdynamic_atexit_destructor_for_g_enabledstatemanager)
	* [KERNEL32.DLL::GetMailslotInfo](#kernel32dllgetmailslotinfo)
* [Modified](#modified)
	* [ClientAttach](#clientattach)
	* [wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''](#wildetailsdynamic_initializer_for_g_header_init_initializestagingheaderinternalapi)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [__GSHandlerCheck](#__gshandlercheck)
	* [KERNEL32.DLL::HeapAlloc](#kernel32dllheapalloc)
	* [atexit](#atexit)
	* [~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>](#unique_storagestruct_wildetailsresource_policystruct__tp_timer___ptr64void___cdeclstruct__tp_timer___ptr64public_static_void___cdecl_wildetailsdestroythreadpooltimerstruct_wildetailssystemthreadpoolmethods0destroystruct__tp_timer___ptr64struct_wistdintegral_constantunsigned___int640struct__tp_timer___ptr64struct__tp_timer___ptr640stdnullptr_t_)
	* [ProcessShutdownInProgress](#processshutdowninprogress)
	* [push_back](#push_back)
	* [KERNEL32.DLL::AcquireSRWLockExclusive](#kernel32dllacquiresrwlockexclusive)
	* [KERNEL32.DLL::GetModuleHandleW](#kernel32dllgetmodulehandlew)
	* [KERNEL32.DLL::GetLastError](#kernel32dllgetlasterror)
	* [__security_check_cookie](#__security_check_cookie)
	* [reset](#reset)
	* [~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>](#unique_storagestruct_wildetailsresource_policystruct__rtl_srwlock___ptr64void___cdeclstruct__rtl_srwlock___ptr64void___cdecl_releasesrwlockexclusivestruct__rtl_srwlock___ptr64struct_wistdintegral_constantunsigned___int641struct__rtl_srwlock___ptr64struct__rtl_srwlock___ptr640stdnullptr_t_)
	* [KERNEL32.DLL::CreateFileW](#kernel32dllcreatefilew)
	* [KERNEL32.DLL::CloseHandle](#kernel32dllclosehandle)
	* [KERNEL32.DLL::GetProcAddress](#kernel32dllgetprocaddress)
	* [wil_details_GetNtDllProcedureAddress](#wil_details_getntdllprocedureaddress)

# Visual Chart Diff



```mermaid

flowchart LR

ClientAttach-5-old<--Match 11%-->ClientAttach-5-new
wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-old<--Match 78%-->wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-new

subgraph ts_7623.dll
    ClientAttach-5-new
wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-new
    subgraph Added
direction LR
wil-details-dynamic_initializer_for_g_enabledStateManager
    Feature_2464883000__private_IsEnabledDeviceUsageNoInline
    wil_RtlStagingConfig_QueryFeatureState
    wil_details_FeatureReporting_IncrementOpportunityInCache
    wil_details_FeatureReporting_IncrementUsageInCache
    wil_details_FeatureReporting_RecordUsageInCache
    wil_details_FeatureReporting_ReportUsageToService
    wil_details_FeatureReporting_ReportUsageToServiceDirect
    wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
    wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
    wil_details_GetCurrentFeatureEnabledState
    wil_details_IsEnabledFallback
    wil_details_MapReportingKind
    wil-details-unique_storagestruct_wil-details-resource_policystruct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64void___cdeclstruct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64void___cdecl_wil-details-WilApi_UnsubscribeFeatureStateChangeNotificationstruct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64struct_wistd-integral_constantunsigned___int640struct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64struct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr640std-nullptr_t_-unique_storagestruct_wil-details-resource_policystruct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64void___cdeclstruct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64void___cdecl_wil-details-WilApi_UnsubscribeFeatureStateChangeNotificationstruct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64struct_wistd-integral_constantunsigned___int640struct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr64struct_FEATURE_STATE_CHANGE_SUBSCRIPTION_____ptr640std-nullptr_t_
    wil-details-EnabledStateManager-EnabledStateManager
    wil-details-EnsureSubscribedToFeatureConfigurationChanges
    wil-details-EnabledStateManager-EnsureSubscribedToFeatureConfigurationChangesImpl
    wil-details-EnabledStateManager-OnStateChange
    wil-details-EnabledStateManager-SubscribeFeatureStateCacheToConfigurationChanges
    wil-details-SubscribeFeatureStateCacheToConfigurationChanges
    wil-details-WilApi_RecordFeatureUsage
    wil-details-WilApi_RecordFeatureUsageReports
    wil-details-WilApi_UnsubscribeFeatureStateChangeNotification
    wil_details_RecordCachedUsage
    wil-details-dynamic_atexit_destructor_for_g_enabledStateManager
    KERNEL32DLL-GetMailslotInfo
end
end

subgraph ts_7309.dll
    ClientAttach-5-old
wildetailsdynamic_initializer_for_g_header_init_InitializeStagingHeaderInternalApi-0-old
    
end

```


```mermaid
pie showData
    title Function Matches - 98.6974%
"unmatched_funcs_len" : 26
"matched_funcs_len" : 1970
```



```mermaid
pie showData
    title Matched Function Similarity - 98.8832%
"matched_funcs_with_code_changes_len" : 2
"matched_funcs_with_non_code_changes_len" : 20
"matched_funcs_no_changes_len" : 1948
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --bsim --max-ram-percent 60.0 --max-section-funcs 200 ts_7309.dll ts_7623.dll
```


#### Verbose Args


<details>

```
--old ['ts_7309.dll'] --new [['ts_7623.dll']] --engine VersionTrackingDiff --output-path ts_out --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim True --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/TAPISRV.EXE/E11AD8A05C000/TAPISRV.EXE -O tapisrv.exe.x64.10.0.26100.7309
wget https://msdl.microsoft.com/download/symbols/TAPISRV.EXE/BBD1B1D35D000/TAPISRV.EXE -O tapisrv.exe.x64.10.0.26100.7623
```


## Binary Metadata Diff


```diff
--- ts_7309.dll Meta
+++ ts_7623.dll Meta
@@ -1,44 +1,44 @@
-Program Name: ts_7309.dll
+Program Name: ts_7623.dll
 Language ID: x86:LE:64:default (4.6)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 180000000
 Maximum Address: ff0000184f
-# of Bytes: 379664
+# of Bytes: 383960
 # of Memory Blocks: 10
-# of Instructions: 62528
-# of Defined Data: 3522
-# of Functions: 984
-# of Symbols: 11756
-# of Data Types: 764
+# of Instructions: 63663
+# of Defined Data: 3564
+# of Functions: 1012
+# of Symbols: 11942
+# of Data Types: 772
 # of Data Type Categories: 43
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.0.4
-Date Created: Tue Aug 18 21:40:15 SGT 2026
+Date Created: Tue Aug 18 21:40:19 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /tmp/ts2/ts_7309.dll
-Executable MD5: 5dd08d48d5cba24028a4d56008095d04
-Executable SHA256: aaffa1c72e0d4e65046bb74de7f6dee0b486841255907eb64d0abf40d8a83a1b
-FSRL: file:///tmp/ts2/ts_7309.dll?MD5=5dd08d48d5cba24028a4d56008095d04
+Executable Location: /tmp/ts2/ts_7623.dll
+Executable MD5: 1fa02996c650e49f83e8cbcfb031d75b
+Executable SHA256: 3eda9356b2b1dbc9af6b3ea719536e05ba4011f82bbc12aff0cbb0a37b0efeb2
+FSRL: file:///tmp/ts2/ts_7623.dll?MD5=1fa02996c650e49f83e8cbcfb031d75b
 PDB Age: 1
 PDB File: tapisrv.pdb
-PDB GUID: a8bcb652-9165-8e4a-8dec-a1822049c348
+PDB GUID: 885fb278-ac13-771b-c619-3c110739f78d
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: Microsoft® Windows(TM) Telephony Server
-PE Property[FileVersion]: 10.0.26100.7309 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.26100.7623 (WinBuild.160101.0800)
 PE Property[InternalName]: Telephony Service
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: TAPISRV.EXE
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.26100.7309
+PE Property[ProductVersion]: 10.0.26100.7623
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: false
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra ts_7309.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra ts_7309.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra ts_7309.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra ts_7623.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra ts_7623.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra ts_7623.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.Apply Function Calling Conventions|true|
|Demangler Microsoft.Apply Function Signatures|true|
|Demangler Microsoft.C-Style Symbol Interpretation|FUNCTION_IF_EXISTS|
|Demangler Microsoft.Demangle Only Known Mangled Symbols|false|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|26|
|deleted_funcs_len|0|
|modified_funcs_len|22|
|added_symbols_len|14|
|deleted_symbols_len|0|
|diff_time|5.289968252182007|
|deleted_strings_len|0|
|added_strings_len|2|
|match_types|Counter({'SymbolsHash': 979, 'ExternalsName': 230, 'ExactBytesFunctionHasher': 2, 'SigCallingCalledHasher': 1, 'StructuralGraphHash': 1, 'Implied Match': 1})|
|items_to_process|62|
|diff_types|Counter({'address': 22, 'refcount': 20, 'calling': 14, 'length': 3, 'sig': 3, 'code': 2, 'called': 2})|
|unmatched_funcs_len|26|
|total_funcs_len|1996|
|matched_funcs_len|1970|
|matched_funcs_with_code_changes_len|2|
|matched_funcs_with_non_code_changes_len|20|
|matched_funcs_no_changes_len|1948|
|match_func_similarity_percent|98.8832%|
|func_match_overall_percent|98.6974%|
|first_matches|Counter({'SymbolsHash': 979, 'ExactBytesFunctionHasher': 2, 'SigCallingCalledHasher': 1, 'StructuralGraphHash': 1, 'Implied Match': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 979
"ExternalsName" : 230
"ExactBytesFunctionHasher" : 2
"SigCallingCalledHasher" : 1
"StructuralGraphHash" : 1
"Implied-Match" : 1
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 979
"ExactBytesFunctionHasher" : 2
"SigCallingCalledHasher" : 1
"StructuralGraphHash" : 1
"Implied-Match" : 1
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 26
"deleted_funcs_len" : 0
"modified_funcs_len" : 22
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 14
"deleted_symbols_len" : 0
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 0
"added_strings_len" : 2
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -0,0 +1,2 @@
+s_ClientAttach:_GetMailslotInfo(%
+s_RtlQueryFeatureConfiguration

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|s_ClientAttach:_GetMailslotInfo(%|2|ClientAttach|
|s_RtlQueryFeatureConfiguration|1|wil_RtlStagingConfig_QueryFeatureState|

# Deleted

# Added

## wil::details::`dynamic_initializer_for_'g_enabledStateManager''

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|`dynamic_initializer_for_'g_enabledStateManager''|
|fullname|wil::details::`dynamic_initializer_for_'g_enabledStateManager''|
|refcount|2|
|length|12|
|called|atexit|
|calling||
|paramcount|0|
|address|180001010|
|sig|undefined __fastcall `dynamic_initializer_for_'g_enabledStateManager''(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil::details::`dynamic_initializer_for_'g_enabledStateManager''
+++ wil::details::`dynamic_initializer_for_'g_enabledStateManager''
@@ -0,0 +1,8 @@
+
+void wil::details::_dynamic_initializer_for__g_enabledStateManager__(void)
+
+{
+  atexit(_dynamic_atexit_destructor_for__g_enabledStateManager__);
+  return;
+}
+

```


## Feature_2464883000__private_IsEnabledDeviceUsageNoInline

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|Feature_2464883000__private_IsEnabledDeviceUsageNoInline|
|fullname|Feature_2464883000__private_IsEnabledDeviceUsageNoInline|
|refcount|1|
|length|44|
|called|wil_details_IsEnabledFallback|
|calling|ClientAttach|
|paramcount|0|
|address|180029f04|
|sig|uint __fastcall Feature_2464883000__private_IsEnabledDeviceUsageNoInline(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- Feature_2464883000__private_IsEnabledDeviceUsageNoInline
+++ Feature_2464883000__private_IsEnabledDeviceUsageNoInline
@@ -0,0 +1,15 @@
+
+uint Feature_2464883000__private_IsEnabledDeviceUsageNoInline(void)
+
+{
+  uint uVar1;
+  undefined8 local_res8;
+  
+  local_res8 = (undefined4 *)(ulonglong)Feature_2464883000__private_featureState;
+  if ((Feature_2464883000__private_featureState & 0x10) != 0) {
+    return Feature_2464883000__private_featureState & 1;
+  }
+  uVar1 = wil_details_IsEnabledFallback(local_res8,3);
+  return uVar1;
+}
+

```


## wil_RtlStagingConfig_QueryFeatureState

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_RtlStagingConfig_QueryFeatureState|
|fullname|wil_RtlStagingConfig_QueryFeatureState|
|refcount|2|
|length|271|
|called|__security_check_cookie<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_GetNtDllProcedureAddress|
|calling|wil_details_GetCurrentFeatureEnabledState|
|paramcount|4|
|address|180031b74|
|sig|undefined4 __fastcall wil_RtlStagingConfig_QueryFeatureState(uint * param_1, undefined4 param_2, int param_3, uint * param_4)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_RtlStagingConfig_QueryFeatureState
+++ wil_RtlStagingConfig_QueryFeatureState
@@ -0,0 +1,50 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+undefined4
+wil_RtlStagingConfig_QueryFeatureState(uint *param_1,undefined4 param_2,int param_3,uint *param_4)
+
+{
+  int iVar1;
+  undefined4 uVar2;
+  undefined1 auStack_78 [48];
+  undefined8 local_48;
+  undefined8 local_40;
+  uint local_38;
+  ulonglong local_30;
+  
+  local_30 = __security_cookie ^ (ulonglong)auStack_78;
+  local_48 = 0;
+  uVar2 = 0;
+  local_40 = 0;
+  local_38 = 0;
+  if ((g_wil_details_pfnRtlQueryFeatureConfiguration == (code *)0x0) &&
+     (g_wil_details_pfnRtlQueryFeatureConfiguration =
+           (code *)wil_details_GetNtDllProcedureAddress("RtlQueryFeatureConfiguration"),
+     g_wil_details_pfnRtlQueryFeatureConfiguration == (code *)0x0)) {
+    iVar1 = -0x3ffffec7;
+    uVar2 = 0;
+  }
+  else {
+    iVar1 = (*g_wil_details_pfnRtlQueryFeatureConfiguration)
+                      (param_2,param_3 == 0,&local_48,&local_40);
+    if (iVar1 == 0) {
+      *param_1 = local_40._4_4_ >> 4 & 3;
+      *(byte *)(param_1 + 1) = (byte)((ulonglong)local_40 >> 0x28) & 0x3f;
+      param_1[3] = local_38;
+      param_1[2] = local_40._4_4_ >> 0xe & 3;
+      param_1[5] = local_40._4_4_ >> 6 & 1;
+    }
+    else if (iVar1 != 0x117) goto LAB_180031c4f;
+    uVar2 = 1;
+    param_1[4] = local_40._4_4_ >> 7 & 1;
+  }
+LAB_180031c4f:
+  if (param_4 != (uint *)0x0) {
+    *param_4 = (uint)(iVar1 != -0x7fffffde);
+  }
+  return uVar2;
+}
+

```


## wil_details_FeatureReporting_IncrementOpportunityInCache

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_FeatureReporting_IncrementOpportunityInCache|
|fullname|wil_details_FeatureReporting_IncrementOpportunityInCache|
|refcount|2|
|length|208|
|called||
|calling|wil_details_FeatureReporting_RecordUsageInCache|
|paramcount|4|
|address|180031cec|
|sig|undefined __fastcall wil_details_FeatureReporting_IncrementOpportunityInCache(uint * param_1, uint param_2, undefined8 param_3, uint * param_4)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureReporting_IncrementOpportunityInCache
+++ wil_details_FeatureReporting_IncrementOpportunityInCache
@@ -0,0 +1,54 @@
+
+void wil_details_FeatureReporting_IncrementOpportunityInCache
+               (uint *param_1,uint param_2,undefined8 param_3,uint *param_4)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  bool bVar5;
+  
+  uVar2 = *param_1;
+  do {
+    uVar4 = uVar2;
+    param_4[1] = 0;
+    uVar1 = uVar4 | 1;
+    if ((uVar4 & 0x400000) >> 0x16 != (uint)(param_2 == 5)) {
+      uVar2 = (uVar4 & 0x3f8000) >> 0xf;
+      if (uVar2 != 0) {
+        param_4[1] = uVar2;
+        uVar2 = 5;
+        if (param_2 != 1) {
+          uVar2 = 1;
+        }
+        uVar1 = uVar4 & 0xffc07fff | 1;
+        param_4[2] = uVar2;
+      }
+      uVar2 = 0;
+      if (param_2 == 5) {
+        uVar2 = 0x400000;
+      }
+      uVar1 = uVar2 | uVar1 & 0xffbfffff;
+    }
+    uVar2 = uVar1 >> 0xf & 0x7f;
+    uVar3 = uVar2 + 1;
+    if ((0x7f < uVar3) || (uVar3 < uVar2)) {
+      uVar3 = 1;
+      param_4[2] = param_2;
+      param_4[1] = uVar2;
+    }
+    LOCK();
+    uVar2 = *param_1;
+    bVar5 = uVar4 == uVar2;
+    if (bVar5) {
+      *param_1 = (uVar3 << 0xf ^ uVar1) & 0x3f8000 ^ uVar1;
+      uVar2 = uVar4;
+    }
+    UNLOCK();
+  } while (!bVar5);
+  param_4[4] = 0;
+  *param_4 = ~uVar4 & 1;
+  return;
+}
+

```


## wil_details_FeatureReporting_IncrementUsageInCache

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_FeatureReporting_IncrementUsageInCache|
|fullname|wil_details_FeatureReporting_IncrementUsageInCache|
|refcount|2|
|length|220|
|called||
|calling|wil_details_FeatureReporting_RecordUsageInCache|
|paramcount|4|
|address|180031dc4|
|sig|undefined __fastcall wil_details_FeatureReporting_IncrementUsageInCache(uint * param_1, uint param_2, undefined8 param_3, uint * param_4)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureReporting_IncrementUsageInCache
+++ wil_details_FeatureReporting_IncrementUsageInCache
@@ -0,0 +1,50 @@
+
+void wil_details_FeatureReporting_IncrementUsageInCache
+               (uint *param_1,uint param_2,undefined8 param_3,uint *param_4)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  bool bVar5;
+  
+  uVar4 = *param_1;
+  do {
+    uVar3 = uVar4;
+    param_4[1] = 0;
+    uVar1 = uVar3 | 1;
+    if ((uVar3 & 0x4000) >> 0xe != (uint)(param_2 == 4)) {
+      uVar4 = (uVar3 & 0x3fe0) >> 5;
+      if (uVar4 != 0) {
+        param_4[1] = uVar4;
+        param_4[2] = ~-(uint)(param_2 != 0) & 4;
+        uVar1 = uVar3 & 0xffffc01f | 1;
+      }
+      uVar4 = 0;
+      if (param_2 == 4) {
+        uVar4 = 0x4000;
+      }
+      uVar1 = uVar4 | uVar1 & 0xffffbfff;
+    }
+    uVar4 = uVar1 >> 5 & 0x1ff;
+    uVar2 = uVar4 + 1;
+    if ((0x1ff < uVar2) || (uVar2 < uVar4)) {
+      uVar2 = 1;
+      param_4[2] = param_2;
+      param_4[1] = uVar4;
+    }
+    LOCK();
+    uVar4 = *param_1;
+    bVar5 = uVar3 == uVar4;
+    if (bVar5) {
+      *param_1 = (uVar2 << 5 ^ uVar1) & 0x3fe0 ^ uVar1;
+      uVar4 = uVar3;
+    }
+    UNLOCK();
+  } while (!bVar5);
+  param_4[4] = 0;
+  *param_4 = ~uVar3 & 1;
+  return;
+}
+

```


## wil_details_FeatureReporting_RecordUsageInCache

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_FeatureReporting_RecordUsageInCache|
|fullname|wil_details_FeatureReporting_RecordUsageInCache|
|refcount|2|
|length|374|
|called|wil_details_FeatureReporting_IncrementOpportunityInCache<br>wil_details_FeatureReporting_IncrementUsageInCache|
|calling|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|paramcount|4|
|address|180031ea8|
|sig|uint * __fastcall wil_details_FeatureReporting_RecordUsageInCache(uint * param_1, uint * param_2, undefined8 param_3, uint param_4)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureReporting_RecordUsageInCache
+++ wil_details_FeatureReporting_RecordUsageInCache
@@ -0,0 +1,101 @@
+
+uint * wil_details_FeatureReporting_RecordUsageInCache
+                 (uint *param_1,uint *param_2,undefined8 param_3,uint param_4)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  uint uVar5;
+  bool bVar6;
+  
+  uVar3 = (uint)param_3;
+  param_1[0] = 0;
+  param_1[1] = 0;
+  param_1[2] = 0;
+  param_1[3] = 0;
+  param_1[4] = 0;
+  param_1[5] = 0;
+  if (uVar3 == 0) {
+LAB_180032000:
+    wil_details_FeatureReporting_IncrementUsageInCache(param_2,uVar3,param_3,param_1);
+  }
+  else {
+    if (uVar3 == 1) {
+LAB_180031ff3:
+      wil_details_FeatureReporting_IncrementOpportunityInCache(param_2,uVar3,param_3,param_1);
+      return param_1;
+    }
+    if ((uVar3 != 2) && (uVar3 != 3)) {
+      if (uVar3 == 4) goto LAB_180032000;
+      if (uVar3 == 5) goto LAB_180031ff3;
+      if ((uVar3 != 6) && (uVar3 != 7)) {
+        uVar4 = uVar3 - 0x140;
+        if ((int)uVar4 < 0x40) {
+          uVar5 = param_2[1];
+          do {
+            if (((uVar5 & 0x10) == 0) || (uVar2 = 1, (uVar5 >> 5 & 0x3f) != uVar4)) {
+              uVar2 = 0;
+            }
+            param_1[4] = uVar2;
+            LOCK();
+            uVar2 = param_2[1];
+            bVar6 = uVar5 == uVar2;
+            if (bVar6) {
+              param_2[1] = (uVar4 * 0x20 ^ uVar5) & 0x7e0 ^ uVar5 | 0x10;
+              uVar2 = uVar5;
+            }
+            uVar5 = uVar2;
+            UNLOCK();
+          } while (!bVar6);
+          if (param_1[4] != 0) {
+            return param_1;
+          }
+        }
+        param_1[2] = uVar3;
+        param_1[1] = 1;
+        param_1[3] = param_4;
+        return param_1;
+      }
+    }
+    uVar4 = 0;
+    if (uVar3 == 2) {
+      uVar4 = 2;
+    }
+    else if (uVar3 == 3) {
+      uVar4 = 8;
+    }
+    else if (uVar3 == 6) {
+      uVar4 = 4;
+    }
+    else if (uVar3 == 7) {
+      uVar4 = 0x10;
+    }
+    uVar5 = 1;
+    uVar3 = *param_2;
+    do {
+      uVar1 = uVar3;
+      uVar3 = uVar4 | uVar1;
+      param_1[4] = (uint)(uVar3 == uVar1);
+      uVar2 = uVar3 | 1;
+      if (uVar3 == uVar1) {
+        uVar2 = uVar3;
+      }
+      LOCK();
+      uVar3 = *param_2;
+      bVar6 = uVar1 == uVar3;
+      if (bVar6) {
+        *param_2 = uVar2;
+        uVar3 = uVar1;
+      }
+      UNLOCK();
+    } while (!bVar6);
+    if (((uVar2 & 1) == 0) || ((uVar1 & 1) != 0)) {
+      uVar5 = 0;
+    }
+    *param_1 = uVar5;
+  }
+  return param_1;
+}
+

```


## wil_details_FeatureReporting_ReportUsageToService

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToService|
|fullname|wil_details_FeatureReporting_ReportUsageToService|
|refcount|2|
|length|114|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_MapReportingKind|
|calling|wil_details_IsEnabledFallback|
|paramcount|3|
|address|180032028|
|sig|undefined __fastcall wil_details_FeatureReporting_ReportUsageToService(undefined8 param_1, undefined8 param_2, uint param_3)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureReporting_ReportUsageToService
+++ wil_details_FeatureReporting_ReportUsageToService
@@ -0,0 +1,28 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+void wil_details_FeatureReporting_ReportUsageToService
+               (undefined8 param_1,undefined8 param_2,uint param_3)
+
+{
+  bool bVar1;
+  uint uVar2;
+  undefined7 extraout_var;
+  ulonglong uVar3;
+  uint uVar4;
+  uint local_res18 [4];
+  
+  uVar4 = (uint)param_2 & 1;
+  uVar3 = (ulonglong)param_3;
+  local_res18[0] = param_3;
+  uVar2 = wil_details_MapReportingKind(param_3,uVar4);
+  bVar1 = wil_details_FeatureReporting_ReportUsageToServiceDirect(uVar3,param_2,(ulonglong)uVar2);
+  if (((int)CONCAT71(extraout_var,bVar1) != 0) &&
+     (g_wil_details_pfnFeatureLoggingHook != (code *)0x0)) {
+    (*g_wil_details_pfnFeatureLoggingHook)
+              (0x394e47a,&Feature_2464883000_logged_traits,0,uVar4,local_res18,0,0,1);
+  }
+  return;
+}
+

```


## wil_details_FeatureReporting_ReportUsageToServiceDirect

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|fullname|wil_details_FeatureReporting_ReportUsageToServiceDirect|
|refcount|2|
|length|137|
|called|__security_check_cookie<br>wil_RtlStagingConfig_RecordFeatureUsage<br>wil_details_FeatureReporting_RecordUsageInCache|
|calling|wil_details_FeatureReporting_ReportUsageToService|
|paramcount|3|
|address|1800320a4|
|sig|bool __fastcall wil_details_FeatureReporting_ReportUsageToServiceDirect(undefined8 param_1, undefined8 param_2, undefined8 param_3)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureReporting_ReportUsageToServiceDirect
+++ wil_details_FeatureReporting_ReportUsageToServiceDirect
@@ -0,0 +1,24 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+
+bool wil_details_FeatureReporting_ReportUsageToServiceDirect
+               (undefined8 param_1,undefined8 param_2,undefined8 param_3)
+
+{
+  uint *puVar1;
+  undefined1 auStack_78 [48];
+  uint local_48 [10];
+  undefined8 local_20;
+  ulonglong local_18;
+  
+  local_18 = __security_cookie ^ (ulonglong)auStack_78;
+  puVar1 = wil_details_FeatureReporting_RecordUsageInCache
+                     (local_48,(uint *)&Feature_2464883000__private_reporting,param_3,
+                      (uint)((ulonglong)param_2 >> 0x20));
+  local_20 = *(undefined8 *)(puVar1 + 4);
+  if ((((uint)param_2 >> 10 & 1) != 0) && ((int)param_3 != 0xfe)) {
+    wil_RtlStagingConfig_RecordFeatureUsage(0x394e47a,(short)param_3,(uint)param_2 >> 0xb & 1);
+  }
+  return (int)local_20 == 0;
+}
+

```


## wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|fullname|wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|refcount|3|
|length|263|
|called|_guard_dispatch_icall$thunk$10345483385596137414<br>wil_details_GetCurrentFeatureEnabledState|
|calling|wil_details_GetCurrentFeatureEnabledState<br>wil_details_IsEnabledFallback|
|paramcount|3|
|address|180032134|
|sig|ulonglong __fastcall wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState(uint * param_1, ulonglong param_2, longlong param_3)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+++ wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
@@ -0,0 +1,68 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+
+ulonglong wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+                    (uint *param_1,ulonglong param_2,longlong param_3)
+
+{
+  int iVar1;
+  uint uVar2;
+  ulonglong uVar3;
+  uint uVar4;
+  uint uVar5;
+  ulonglong uVar6;
+  bool bVar7;
+  uint local_res8 [2];
+  undefined8 local_res10;
+  
+  iVar1 = 0;
+  local_res8[0] = 0;
+  local_res10 = param_2;
+  if (g_wil_details_ensureSubscribedToFeatureConfigurationChanges != (code *)0x0) {
+    iVar1 = (*g_wil_details_ensureSubscribedToFeatureConfigurationChanges)();
+  }
+  uVar2 = wil_details_GetCurrentFeatureEnabledState(param_3,local_res8);
+  if (*(char *)(param_3 + 0x1c) == '\0') {
+    local_res8[0] = local_res8[0] & -(uint)(iVar1 != 0);
+  }
+  uVar3 = param_2 & 0xffffffff;
+  do {
+    uVar6 = param_2;
+    uVar5 = (uint)uVar3;
+    local_res10 = CONCAT44(local_res10._4_4_,uVar5);
+    if ((local_res8[0] != 0) && (local_res10 = CONCAT44(local_res10._4_4_,uVar5), (uVar3 & 2) == 0))
+    {
+      uVar4 = uVar5 & 0xfffff63e | uVar2 & 0x9c1;
+      uVar5 = uVar4 | 2;
+      local_res10 = CONCAT44(local_res10._4_4_,uVar4) | 2;
+    }
+    if ((uVar6 & 4) == 0) {
+      uVar4 = uVar2 & 0x400 | uVar5 & 0xfffffbff;
+      uVar5 = uVar4 | 4;
+      local_res10 = CONCAT44(local_res10._4_4_,uVar4) | 4;
+    }
+    uVar3 = uVar6 & 0xffffffff;
+    LOCK();
+    uVar4 = *param_1;
+    bVar7 = (uint)uVar6 == uVar4;
+    if (bVar7) {
+      *param_1 = uVar5;
+    }
+    else {
+      uVar3 = (ulonglong)uVar4;
+    }
+    UNLOCK();
+    param_2 = uVar3;
+  } while (!bVar7);
+  if (((uVar6 & 4) == 0) &&
+     (g_wil_details_subscribeFeatureStateCacheToConfigurationChanges != (code *)0x0)) {
+    (*g_wil_details_subscribeFeatureStateCacheToConfigurationChanges)
+              (param_1,*(undefined1 *)(param_3 + 0x1c),iVar1);
+  }
+  if (local_res8[0] == 0) {
+    local_res10 = CONCAT44(local_res10._4_4_,uVar2 & 0x9c1 | uVar5 & 0xfffff63e);
+  }
+  return local_res10;
+}
+

```


## wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|fullname|wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|refcount|1|
|length|76|
|called||
|calling|wil_details_IsEnabledFallback|
|paramcount|2|
|address|180032244|
|sig|undefined __fastcall wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
+++ wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath
@@ -0,0 +1,41 @@
+
+void wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath(uint param_1,int param_2)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  bool bVar4;
+  
+  if (param_2 == 3) {
+    uVar3 = 0x10;
+  }
+  else {
+    if (param_2 != 4) {
+      return;
+    }
+    uVar3 = 0x20;
+  }
+  if ((Feature_2464883000__private_featureState & 2) != 0) {
+    uVar2 = Feature_2464883000__private_featureState;
+    while ((uVar2 & 1) == (param_1 & 1)) {
+      LOCK();
+      bVar4 = uVar2 == Feature_2464883000__private_featureState;
+      uVar1 = uVar3 | uVar2;
+      if (!bVar4) {
+        uVar2 = Feature_2464883000__private_featureState;
+        uVar1 = Feature_2464883000__private_featureState;
+      }
+      Feature_2464883000__private_featureState = uVar1;
+      UNLOCK();
+      if (bVar4) {
+        return;
+      }
+      if ((uVar2 & 2) == 0) {
+        return;
+      }
+    }
+  }
+  return;
+}
+

```


## wil_details_GetCurrentFeatureEnabledState

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_GetCurrentFeatureEnabledState|
|fullname|wil_details_GetCurrentFeatureEnabledState|
|refcount|2|
|length|343|
|called|wil_RtlStagingConfig_QueryFeatureState<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|calling|wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState|
|paramcount|2|
|address|180032298|
|sig|uint __fastcall wil_details_GetCurrentFeatureEnabledState(longlong param_1, undefined4 * param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_GetCurrentFeatureEnabledState
+++ wil_details_GetCurrentFeatureEnabledState
@@ -0,0 +1,73 @@
+
+uint wil_details_GetCurrentFeatureEnabledState(longlong param_1,undefined4 *param_2)
+
+{
+  char cVar1;
+  undefined8 *puVar2;
+  int iVar3;
+  uint uVar4;
+  ulonglong uVar5;
+  uint uVar6;
+  longlong *plVar7;
+  uint local_res8;
+  ulonglong local_res10;
+  uint local_28 [8];
+  
+  cVar1 = *(char *)(param_1 + 0x1c);
+  *param_2 = 1;
+  local_28[4] = 0;
+  local_28[5] = 0;
+  local_28[0] = 0;
+  local_28[1] = 0;
+  local_28[2] = 0;
+  local_28[3] = 0;
+  iVar3 = wil_RtlStagingConfig_QueryFeatureState
+                    (local_28,*(undefined4 *)(param_1 + 0x18),(uint)((byte)(cVar1 - 2U) < 2),
+                     (uint *)0x0);
+  uVar4 = -(uint)(iVar3 != 0) & local_28[0] & 3;
+  if (uVar4 == 0) {
+    uVar6 = -(uint)(*(char *)(param_1 + 0x1f) != '\0') & 0x40;
+  }
+  else {
+    uVar6 = 0;
+    if (local_28[0] == 2) {
+      uVar6 = 0x40;
+    }
+  }
+  local_res8 = uVar6 >> 6 ^
+               (uVar4 << 7 | -(uint)(local_28[5] != 0) & 0x800 | -(uint)(local_28[4] != 0) & 0x400 |
+               uVar6);
+  if ((uVar6 != 0) && (plVar7 = *(longlong **)(param_1 + 0x20), plVar7 != (longlong *)0x0)) {
+    do {
+      puVar2 = (undefined8 *)*plVar7;
+      if (puVar2 == (undefined8 *)0x0) {
+        return local_res8;
+      }
+      if ((*(char *)((longlong)puVar2 + 0x1e) == '\0') &&
+         (*(char *)((longlong)puVar2 + 0x1d) == '\0')) {
+        uVar6 = *(uint *)*puVar2;
+        local_res10 = (ulonglong)uVar6;
+        if ((uVar6 & 2) == 0) {
+          uVar5 = wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+                            ((uint *)*puVar2,local_res10,(longlong)puVar2);
+          uVar6 = (uint)uVar5;
+        }
+        uVar4 = local_res8 & 0xfffffffe;
+        local_res8 = (uint)((uVar6 & local_res8 & 1) != 0);
+      }
+      else {
+        if (((local_res8 & 1) == 0) || (*(char *)((longlong)puVar2 + 0x1f) == '\0')) {
+          uVar4 = 0;
+        }
+        else {
+          uVar4 = 1;
+        }
+        local_res8 = local_res8 & 0xfffffffe;
+      }
+      local_res8 = local_res8 | uVar4;
+      plVar7 = plVar7 + 1;
+    } while ((local_res8 & 1) != 0);
+  }
+  return local_res8;
+}
+

```


## wil_details_IsEnabledFallback

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_IsEnabledFallback|
|fullname|wil_details_IsEnabledFallback|
|refcount|2|
|length|135|
|called|wil_details_FeatureReporting_ReportUsageToService<br>wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState<br>wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath|
|calling|Feature_2464883000__private_IsEnabledDeviceUsageNoInline|
|paramcount|2|
|address|180032444|
|sig|uint __fastcall wil_details_IsEnabledFallback(undefined4 * param_1, uint param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_IsEnabledFallback
+++ wil_details_IsEnabledFallback
@@ -0,0 +1,26 @@
+
+uint wil_details_IsEnabledFallback(undefined4 *param_1,uint param_2)
+
+{
+  uint uVar1;
+  undefined4 *puVar2;
+  ulonglong local_res18;
+  
+  uVar1 = (uint)param_1;
+  local_res18 = (ulonglong)param_1 & 0xffffffff;
+  if (((ulonglong)param_1 & 2) == 0) {
+    puVar2 = &Feature_2464883000__private_featureState;
+    local_res18 = wil_details_FeatureStateCache_ReevaluateCachedFeatureEnabledState
+                            (&Feature_2464883000__private_featureState,(ulonglong)param_1,
+                             0x180053398);
+    param_1 = puVar2;
+    uVar1 = (uint)local_res18;
+  }
+  if ((param_2 != 0) &&
+     (wil_details_FeatureReporting_ReportUsageToService(param_1,local_res18,param_2),
+     param_2 - 3 < 2)) {
+    wil_details_FeatureStateCache_TryEnableDeviceUsageFastPath((uint)local_res18,param_2);
+  }
+  return uVar1 & 1;
+}
+

```


## wil_details_MapReportingKind

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_MapReportingKind|
|fullname|wil_details_MapReportingKind|
|refcount|1|
|length|144|
|called||
|calling|wil_details_FeatureReporting_ReportUsageToService|
|paramcount|2|
|address|1800324d4|
|sig|uint __fastcall wil_details_MapReportingKind(int param_1, int param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_MapReportingKind
+++ wil_details_MapReportingKind
@@ -0,0 +1,33 @@
+
+uint wil_details_MapReportingKind(int param_1,int param_2)
+
+{
+  byte bVar1;
+  
+  if (param_1 != 0) {
+    if (param_1 == 1) {
+      return ~-(uint)(param_2 != 0) & 4;
+    }
+    if (param_1 == 2) {
+      return (-(uint)(param_2 != 0) & 0xfffffffc) + 5;
+    }
+    if (param_1 == 3) {
+      return (-(uint)(param_2 != 0) & 0xfffffffc) + 6;
+    }
+    if (param_1 == 4) {
+      return (-(uint)(param_2 != 0) & 0xfffffffc) + 7;
+    }
+    if (param_1 == 5) {
+      return (-(uint)(param_2 != 0) & 0xfffffffe) + 10;
+    }
+    if (param_1 == 6) {
+      return (-(uint)(param_2 != 0) & 0xfffffffe) + 0xb;
+    }
+    bVar1 = (char)param_1 + 0x9c;
+    if (bVar1 < 0x32) {
+      return (-(uint)(param_2 != 0) & 0xffffffce) + 0x96 + (uint)bVar1;
+    }
+  }
+  return 0xff;
+}
+

```


## wil::details::unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>|
|fullname|wil::details::unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>|
|refcount|3|
|length|22|
|called|wil::details::WilApi_UnsubscribeFeatureStateChangeNotification|
|calling|wil::details::EnabledStateManager::~EnabledStateManager|
|paramcount|1|
|address|18003931c|
|sig|void __thiscall ~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>(unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_> * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+++ wil::details::unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
@@ -0,0 +1,30 @@
+
+/* public: __cdecl wil::details::unique_storage<struct wil::details::resource_policy<struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64,void (__cdecl*)(struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64),&void __cdecl
+   wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64),struct wistd::integral_constant<unsigned
+   __int64,0>,struct FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64,struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64,0,std::nullptr_t> >::~unique_storage<struct
+   wil::details::resource_policy<struct FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64,void
+   (__cdecl*)(struct FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64),&void __cdecl
+   wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64),struct wistd::integral_constant<unsigned
+   __int64,0>,struct FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64,struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64,0,std::nullptr_t> >(void) __ptr64 */
+
+void __thiscall
+wil::details::
+unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+::
+~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+          (unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+           *this)
+
+{
+  if (*(FEATURE_STATE_CHANGE_SUBSCRIPTION__ **)this != (FEATURE_STATE_CHANGE_SUBSCRIPTION__ *)0x0) {
+    WilApi_UnsubscribeFeatureStateChangeNotification(*(FEATURE_STATE_CHANGE_SUBSCRIPTION__ **)this);
+  }
+  return;
+}
+

```


## wil::details::EnabledStateManager::~EnabledStateManager

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|~EnabledStateManager|
|fullname|wil::details::EnabledStateManager::~EnabledStateManager|
|refcount|2|
|length|190|
|called|wil::details::FreeProcessHeap<br>wil::details::WilApi_RecordFeatureUsage<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_><br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::reset<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_><br>wil_details_RecordCachedUsage|
|calling|wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|paramcount|1|
|address|180039450|
|sig|void __thiscall ~EnabledStateManager(EnabledStateManager * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::~EnabledStateManager
+++ wil::details::EnabledStateManager::~EnabledStateManager
@@ -0,0 +1,53 @@
+
+/* public: __cdecl wil::details::EnabledStateManager::~EnabledStateManager(void) __ptr64 */
+
+void __thiscall wil::details::EnabledStateManager::~EnabledStateManager(EnabledStateManager *this)
+
+{
+  undefined4 *puVar1;
+  void *pvVar2;
+  undefined4 *puVar3;
+  char *in_R9;
+  
+  *this = (EnabledStateManager)0x0;
+  unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>
+  ::reset((unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>
+           *)(this + 0x10),(_TP_TIMER *)0x0);
+  *this = (EnabledStateManager)0x0;
+  puVar1 = *(undefined4 **)(this + 0x38);
+  puVar3 = *(undefined4 **)(this + 0x30);
+  if (0xf < (ulonglong)((longlong)puVar1 - (longlong)puVar3)) {
+    for (; puVar3 != puVar1; puVar3 = puVar3 + 4) {
+      wil_details_RecordCachedUsage(*puVar3,*(uint **)(puVar3 + 2));
+    }
+    *(undefined8 *)(this + 0x38) = *(undefined8 *)(this + 0x30);
+    WilApi_RecordFeatureUsage(0,0xfe,0,in_R9);
+  }
+  pvVar2 = *(void **)(this + 0x68);
+  *(undefined8 *)(this + 0x68) = 0;
+  if (pvVar2 != (void *)0x0) {
+    FreeProcessHeap(pvVar2);
+  }
+  pvVar2 = *(void **)(this + 0x48);
+  *(undefined8 *)(this + 0x48) = 0;
+  if (pvVar2 != (void *)0x0) {
+    FreeProcessHeap(pvVar2);
+  }
+  unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+  ::
+  ~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+            ((unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+              *)(this + 0x28));
+  unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+  ::
+  ~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+            ((unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>
+              *)(this + 0x20));
+  unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>
+  ::
+  ~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>
+            ((unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>
+              *)(this + 0x10));
+  return;
+}
+

```


## wil::details::EnsureSubscribedToFeatureConfigurationChanges

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|EnsureSubscribedToFeatureConfigurationChanges|
|fullname|wil::details::EnsureSubscribedToFeatureConfigurationChanges|
|refcount|3|
|length|32|
|called|wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl|
|calling||
|paramcount|0|
|address|18003af00|
|sig|uint __cdecl EnsureSubscribedToFeatureConfigurationChanges(void)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnsureSubscribedToFeatureConfigurationChanges
+++ wil::details::EnsureSubscribedToFeatureConfigurationChanges
@@ -0,0 +1,16 @@
+
+/* unsigned int __cdecl wil::details::EnsureSubscribedToFeatureConfigurationChanges(void) */
+
+uint __cdecl wil::details::EnsureSubscribedToFeatureConfigurationChanges(void)
+
+{
+  uint uVar1;
+  
+  uVar1 = DAT_180056394;
+  if (DAT_180056394 == 0) {
+    uVar1 = EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl
+                      ((EnabledStateManager *)&g_enabledStateManager);
+  }
+  return uVar1;
+}
+

```


## wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|EnsureSubscribedToFeatureConfigurationChangesImpl|
|fullname|wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl|
|refcount|2|
|length|150|
|called|KERNEL32.DLL::AcquireSRWLockExclusive<br>_guard_dispatch_icall$thunk$10345483385596137414<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|
|calling|wil::details::EnsureSubscribedToFeatureConfigurationChanges|
|paramcount|1|
|address|18003af28|
|sig|uint __thiscall EnsureSubscribedToFeatureConfigurationChangesImpl(EnabledStateManager * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl
+++ wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl
@@ -0,0 +1,54 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+/* private: unsigned int __cdecl
+   wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl(void)
+   __ptr64 */
+
+uint __thiscall
+wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl
+          (EnabledStateManager *this)
+
+{
+  EnabledStateManager *SRWLock;
+  EnabledStateManager *pEVar1;
+  code *pcVar2;
+  uint uVar3;
+  EnabledStateManager *local_res8;
+  
+  if (*this == (EnabledStateManager)0x0) {
+    uVar3 = 0;
+  }
+  else {
+    SRWLock = this + 8;
+    AcquireSRWLockExclusive((PSRWLOCK)SRWLock);
+    pEVar1 = this + 0x20;
+    local_res8 = SRWLock;
+    if (*(longlong *)pEVar1 == 0) {
+      *(longlong *)pEVar1 = 0;
+      pcVar2 = g_wil_details_internalSubscribeFeatureStateChangeNotification;
+      if ((g_wil_details_internalSubscribeFeatureStateChangeNotification != (code *)0x0) ||
+         (pcVar2 = g_wil_details_apiSubscribeFeatureStateChangeNotification,
+         g_wil_details_apiSubscribeFeatureStateChangeNotification != (code *)0x0)) {
+        (*pcVar2)(pEVar1,<lambda_fee8cea507d2413a58be13acfb66740a>::<lambda_invoker_cdecl>,this);
+      }
+      if (*(longlong *)pEVar1 == 0) {
+        uVar3 = 0;
+      }
+      else {
+        uVar3 = 1;
+        *(undefined4 *)(this + 0x1c) = 1;
+      }
+    }
+    else {
+      uVar3 = *(uint *)(this + 0x1c);
+    }
+    unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+    ::
+    ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+              ((unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+                *)&local_res8);
+  }
+  return uVar3;
+}
+

```


## wil::details::EnabledStateManager::OnStateChange

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|OnStateChange|
|fullname|wil::details::EnabledStateManager::OnStateChange|
|refcount|2|
|length|132|
|called|KERNEL32.DLL::AcquireSRWLockExclusive<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|
|calling||
|paramcount|1|
|address|18003cf7c|
|sig|void __thiscall OnStateChange(EnabledStateManager * this)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::OnStateChange
+++ wil::details::EnabledStateManager::OnStateChange
@@ -0,0 +1,35 @@
+
+/* public: void __cdecl wil::details::EnabledStateManager::OnStateChange(void) __ptr64 */
+
+void __thiscall wil::details::EnabledStateManager::OnStateChange(EnabledStateManager *this)
+
+{
+  int *piVar1;
+  int iVar2;
+  int *piVar3;
+  EnabledStateManager *local_res8;
+  
+  if (*this != (EnabledStateManager)0x0) {
+    AcquireSRWLockExclusive((PSRWLOCK)(this + 8));
+    piVar1 = *(int **)(this + 0x58);
+    for (piVar3 = *(int **)(this + 0x50); piVar3 != piVar1; piVar3 = piVar3 + 4) {
+      LOCK();
+      **(uint **)(piVar3 + 2) = **(uint **)(piVar3 + 2) & (-(uint)(*piVar3 != 0) & 0x83a) - 0x83f;
+      UNLOCK();
+    }
+    *(undefined8 *)(this + 0x58) = *(undefined8 *)(this + 0x50);
+    iVar2 = 1;
+    if (*(int *)(this + 0x1c) + 1 != 0) {
+      iVar2 = *(int *)(this + 0x1c) + 1;
+    }
+    *(int *)(this + 0x1c) = iVar2;
+    local_res8 = this + 8;
+    unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+    ::
+    ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+              ((unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+                *)&local_res8);
+  }
+  return;
+}
+

```


## wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|SubscribeFeatureStateCacheToConfigurationChanges|
|fullname|wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges|
|refcount|2|
|length|156|
|called|KERNEL32.DLL::AcquireSRWLockExclusive<br>wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_><br>wil::details_abi::heap_buffer::push_back|
|calling|wil::details::SubscribeFeatureStateCacheToConfigurationChanges|
|paramcount|4|
|address|18003eca4|
|sig|void __thiscall SubscribeFeatureStateCacheToConfigurationChanges(EnabledStateManager * this, wil_details_FeatureStateCache * param_1, wil_FeatureChangeTime param_2, uint param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges
+++ wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges
@@ -0,0 +1,42 @@
+
+/* public: void __cdecl
+   wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges(union
+   wil_details_FeatureStateCache * __ptr64,enum wil_FeatureChangeTime,unsigned int) __ptr64 */
+
+void __thiscall
+wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges
+          (EnabledStateManager *this,wil_details_FeatureStateCache *param_1,
+          wil_FeatureChangeTime param_2,uint param_3)
+
+{
+  EnabledStateManager *SRWLock;
+  bool bVar1;
+  EnabledStateManager *local_res8;
+  wil_FeatureChangeTime local_28 [2];
+  wil_details_FeatureStateCache *local_20;
+  
+  if (*this == (EnabledStateManager)0x0) {
+    return;
+  }
+  SRWLock = this + 8;
+  AcquireSRWLockExclusive((PSRWLOCK)SRWLock);
+  local_res8 = SRWLock;
+  if ((param_3 != 0) && (param_3 == *(uint *)(this + 0x1c))) {
+    local_28[1] = 0;
+    local_28[0] = param_2;
+    local_20 = param_1;
+    bVar1 = details_abi::heap_buffer::push_back((heap_buffer *)(this + 0x50),local_28,0x10);
+    if (bVar1) goto LAB_18003ed23;
+  }
+  LOCK();
+  *(uint *)param_1 = *(uint *)param_1 & (-(uint)(param_2 != 0) & 0x83a) - 0x83f;
+  UNLOCK();
+LAB_18003ed23:
+  unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+  ::
+  ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+            ((unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>
+              *)&local_res8);
+  return;
+}
+

```


## wil::details::SubscribeFeatureStateCacheToConfigurationChanges

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|SubscribeFeatureStateCacheToConfigurationChanges|
|fullname|wil::details::SubscribeFeatureStateCacheToConfigurationChanges|
|refcount|2|
|length|21|
|called|wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges|
|calling||
|paramcount|3|
|address|18003ed50|
|sig|void __cdecl SubscribeFeatureStateCacheToConfigurationChanges(wil_details_FeatureStateCache * param_1, wil_FeatureChangeTime param_2, uint param_3)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::SubscribeFeatureStateCacheToConfigurationChanges
+++ wil::details::SubscribeFeatureStateCacheToConfigurationChanges
@@ -0,0 +1,14 @@
+
+/* void __cdecl wil::details::SubscribeFeatureStateCacheToConfigurationChanges(union
+   wil_details_FeatureStateCache * __ptr64,enum wil_FeatureChangeTime,unsigned int) */
+
+void __cdecl
+wil::details::SubscribeFeatureStateCacheToConfigurationChanges
+          (wil_details_FeatureStateCache *param_1,wil_FeatureChangeTime param_2,uint param_3)
+
+{
+  EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges
+            ((EnabledStateManager *)&g_enabledStateManager,param_1,param_2,param_3);
+  return;
+}
+

```


## wil::details::WilApi_RecordFeatureUsage

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|WilApi_RecordFeatureUsage|
|fullname|wil::details::WilApi_RecordFeatureUsage|
|refcount|4|
|length|41|
|called|_guard_dispatch_icall$thunk$10345483385596137414|
|calling|wil::details::EnabledStateManager::~EnabledStateManager<br>wil::details::WilApi_RecordFeatureUsageReports<br>wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|paramcount|4|
|address|18003f7f8|
|sig|void __cdecl WilApi_RecordFeatureUsage(uint param_1, uint param_2, uint param_3, char * param_4)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::WilApi_RecordFeatureUsage
+++ wil::details::WilApi_RecordFeatureUsage
@@ -0,0 +1,21 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+/* void __cdecl wil::details::WilApi_RecordFeatureUsage(unsigned int,unsigned int,unsigned int,char
+   const * __ptr64) */
+
+void __cdecl
+wil::details::WilApi_RecordFeatureUsage(uint param_1,uint param_2,uint param_3,char *param_4)
+
+{
+  code *pcVar1;
+  
+  pcVar1 = g_wil_details_internalRecordFeatureUsage;
+  if ((g_wil_details_internalRecordFeatureUsage != (code *)0x0) ||
+     (pcVar1 = g_wil_details_apiRecordFeatureUsage,
+     g_wil_details_apiRecordFeatureUsage != (code *)0x0)) {
+    (*pcVar1)();
+  }
+  return;
+}
+

```


## wil::details::WilApi_RecordFeatureUsageReports

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|WilApi_RecordFeatureUsageReports|
|fullname|wil::details::WilApi_RecordFeatureUsageReports|
|refcount|2|
|length|59|
|called|wil::details::WilApi_RecordFeatureUsage|
|calling|wil_details_RecordCachedUsage|
|paramcount|2|
|address|18003f828|
|sig|void __cdecl WilApi_RecordFeatureUsageReports(__WIL_RTL_FEATURE_USAGE_DATA * param_1, __uint64 param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::WilApi_RecordFeatureUsageReports
+++ wil::details::WilApi_RecordFeatureUsageReports
@@ -0,0 +1,25 @@
+
+/* void __cdecl wil::details::WilApi_RecordFeatureUsageReports(struct __WIL_RTL_FEATURE_USAGE_DATA *
+   __ptr64,unsigned __int64) */
+
+void __cdecl
+wil::details::WilApi_RecordFeatureUsageReports
+          (__WIL_RTL_FEATURE_USAGE_DATA *param_1,__uint64 param_2)
+
+{
+  __WIL_RTL_FEATURE_USAGE_DATA *p_Var1;
+  char *in_R9;
+  
+  if (param_2 != 0) {
+    p_Var1 = param_1 + 4;
+    do {
+      WilApi_RecordFeatureUsage
+                (*(uint *)(p_Var1 + -4),(uint)*(ushort *)p_Var1,(uint)*(ushort *)(p_Var1 + 2),in_R9)
+      ;
+      p_Var1 = p_Var1 + 8;
+      param_2 = param_2 - 1;
+    } while (param_2 != 0);
+  }
+  return;
+}
+

```


## wil::details::WilApi_UnsubscribeFeatureStateChangeNotification

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|WilApi_UnsubscribeFeatureStateChangeNotification|
|fullname|wil::details::WilApi_UnsubscribeFeatureStateChangeNotification|
|refcount|2|
|length|38|
|called|_guard_dispatch_icall$thunk$10345483385596137414|
|calling|wil::details::unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,void_(__cdecl*)(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),&void___cdecl_wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,struct_FEATURE_STATE_CHANGE_SUBSCRIPTION__*___ptr64,0,std::nullptr_t>_>|
|paramcount|1|
|address|18003f86c|
|sig|void __cdecl WilApi_UnsubscribeFeatureStateChangeNotification(FEATURE_STATE_CHANGE_SUBSCRIPTION__ * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- wil::details::WilApi_UnsubscribeFeatureStateChangeNotification
+++ wil::details::WilApi_UnsubscribeFeatureStateChangeNotification
@@ -0,0 +1,22 @@
+
+/* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
+   guard_dispatch_icall */
+/* void __cdecl wil::details::WilApi_UnsubscribeFeatureStateChangeNotification(struct
+   FEATURE_STATE_CHANGE_SUBSCRIPTION__ * __ptr64) */
+
+void __cdecl
+wil::details::WilApi_UnsubscribeFeatureStateChangeNotification
+          (FEATURE_STATE_CHANGE_SUBSCRIPTION__ *param_1)
+
+{
+  code *pcVar1;
+  
+  pcVar1 = g_wil_details_internalUnsubscribeFeatureStateChangeNotification;
+  if ((g_wil_details_internalUnsubscribeFeatureStateChangeNotification != (code *)0x0) ||
+     (pcVar1 = g_wil_details_apiUnsubscribeFeatureStateChangeNotification,
+     g_wil_details_apiUnsubscribeFeatureStateChangeNotification != (code *)0x0)) {
+    (*pcVar1)();
+  }
+  return;
+}
+

```


## wil_details_RecordCachedUsage

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|wil_details_RecordCachedUsage|
|fullname|wil_details_RecordCachedUsage|
|refcount|3|
|length|324|
|called|__security_check_cookie<br>wil::details::WilApi_RecordFeatureUsageReports|
|calling|wil::details::EnabledStateManager::~EnabledStateManager<br>wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|paramcount|2|
|address|1800411e4|
|sig|undefined __fastcall wil_details_RecordCachedUsage(undefined4 param_1, uint * param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil_details_RecordCachedUsage
+++ wil_details_RecordCachedUsage
@@ -0,0 +1,90 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+
+void wil_details_RecordCachedUsage(undefined4 param_1,uint *param_2)
+
+{
+  uint uVar1;
+  uint uVar2;
+  uint uVar3;
+  uint uVar4;
+  undefined4 *puVar5;
+  __uint64 _Var6;
+  bool bVar7;
+  undefined1 auStack_68 [32];
+  undefined4 local_48;
+  short local_44 [2];
+  undefined4 local_40 [10];
+  ulonglong local_18;
+  
+  local_18 = __security_cookie ^ (ulonglong)auStack_68;
+  uVar2 = *param_2;
+  do {
+    LOCK();
+    uVar4 = *param_2;
+    bVar7 = uVar2 == uVar4;
+    if (bVar7) {
+      *param_2 = uVar2 & 0xffc0401e;
+      uVar4 = uVar2;
+    }
+    uVar2 = uVar4;
+    UNLOCK();
+  } while (!bVar7);
+  uVar3 = uVar2 >> 1 & 0xf;
+  uVar4 = 0;
+  if (uVar3 != 0) {
+    uVar4 = param_2[1];
+    do {
+      LOCK();
+      uVar1 = param_2[1];
+      bVar7 = uVar4 == uVar1;
+      if (bVar7) {
+        param_2[1] = uVar4 | uVar3;
+        uVar1 = uVar4;
+      }
+      uVar4 = uVar1;
+      UNLOCK();
+    } while (!bVar7);
+    uVar4 = uVar3 & ~uVar4;
+  }
+  puVar5 = &local_48;
+  if ((uVar4 & 1) != 0) {
+    puVar5 = local_40;
+    local_44[0] = 2;
+    local_44[1] = 1;
+    local_48 = param_1;
+  }
+  if ((uVar4 & 2) != 0) {
+    *puVar5 = param_1;
+    puVar5[1] = 0x10006;
+    puVar5 = puVar5 + 2;
+  }
+  if ((uVar4 & 4) != 0) {
+    *puVar5 = param_1;
+    puVar5[1] = 0x10003;
+    puVar5 = puVar5 + 2;
+  }
+  if (7 < uVar4) {
+    *puVar5 = param_1;
+    puVar5[1] = 0x10007;
+    puVar5 = puVar5 + 2;
+  }
+  if ((uVar2 >> 5 & 0x1ff) != 0) {
+    *puVar5 = param_1;
+    *(ushort *)((longlong)puVar5 + 6) = (ushort)(uVar2 >> 5) & 0x1ff;
+    *(ushort *)(puVar5 + 1) = ((ushort)(uVar2 >> 0xe) & 1) << 2;
+    puVar5 = puVar5 + 2;
+  }
+  if ((uVar2 >> 0xf & 0x7f) != 0) {
+    *puVar5 = param_1;
+    *(ushort *)((longlong)puVar5 + 6) = (ushort)(uVar2 >> 0xf) & 0x7f;
+    *(ushort *)(puVar5 + 1) = ((ushort)(uVar2 >> 0x16) & 1) * 4 + 1;
+    puVar5 = puVar5 + 2;
+  }
+  _Var6 = (longlong)puVar5 - (longlong)&local_48 >> 3;
+  if (0 < (longlong)_Var6) {
+    wil::details::WilApi_RecordFeatureUsageReports((__WIL_RTL_FEATURE_USAGE_DATA *)&local_48,_Var6);
+  }
+  return;
+}
+

```


## wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|fullname|wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''|
|refcount|3|
|length|128|
|called|wil::ProcessShutdownInProgress<br>wil::details::EnabledStateManager::~EnabledStateManager<br>wil::details::WilApi_RecordFeatureUsage<br>wil_details_RecordCachedUsage|
|calling||
|paramcount|0|
|address|180043960|
|sig|undefined __fastcall `dynamic_atexit_destructor_for_'g_enabledStateManager''(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''
+++ wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''
@@ -0,0 +1,28 @@
+
+void wil::details::_dynamic_atexit_destructor_for__g_enabledStateManager__(void)
+
+{
+  undefined4 *puVar1;
+  bool bVar2;
+  undefined4 *puVar3;
+  char *in_R9;
+  
+  bVar2 = ProcessShutdownInProgress();
+  puVar1 = DAT_1800563b0;
+  if (bVar2) {
+    g_enabledStateManager = (shutdown_aware_object<class_wil::details::EnabledStateManager>)0x0;
+    puVar3 = DAT_1800563a8;
+    if (0xf < (ulonglong)((longlong)DAT_1800563b0 - (longlong)DAT_1800563a8)) {
+      for (; puVar3 != puVar1; puVar3 = puVar3 + 4) {
+        wil_details_RecordCachedUsage(*puVar3,*(uint **)(puVar3 + 2));
+      }
+      DAT_1800563b0 = DAT_1800563a8;
+      WilApi_RecordFeatureUsage(0,0xfe,0,in_R9);
+    }
+  }
+  else {
+    EnabledStateManager::~EnabledStateManager((EnabledStateManager *)&g_enabledStateManager);
+  }
+  return;
+}
+

```


## KERNEL32.DLL::GetMailslotInfo

### Function Meta



|Key|ts_7623.dll|
| :---: | :---: |
|name|GetMailslotInfo|
|fullname|KERNEL32.DLL::GetMailslotInfo|
|refcount|2|
|length|0|
|called||
|calling|ClientAttach|
|paramcount|5|
|address|EXTERNAL:00000089|
|sig|BOOL __stdcall GetMailslotInfo(HANDLE hMailslot, LPDWORD lpMaxMessageSize, LPDWORD lpNextSize, LPDWORD lpMessageCount, LPDWORD lpReadTimeout)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for KERNEL32.DLL::GetMailslotInfo*
# Modified


*Modified functions contain code changes*
## ClientAttach

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|code,length,sig,address,called|
|ratio|0.49|
|i_ratio|0.33|
|m_ratio|0.98|
|b_ratio|0.11|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|ClientAttach|ClientAttach|
|fullname|ClientAttach|ClientAttach|
|refcount|3|3|
|`length`|4554|4715|
|`called`|<details><summary>Expand for full list:<br>ADVAPI32.DLL::AllocateAndInitializeSid<br>ADVAPI32.DLL::CheckTokenMembership<br>ADVAPI32.DLL::FreeSid<br>ADVAPI32.DLL::GetTokenInformation<br>ADVAPI32.DLL::LookupAccountSidW<br>ADVAPI32.DLL::OpenThreadToken<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCloseKey<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCreateKeyExW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenCurrentUser<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenKeyExW<br>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp</summary>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::wcschr<br>DSPARSE.DLL::DsMakeSpnW<br>DereferenceObject<br>GetMediaModesPriorityLists<br>GetPriorityList<br>IsLocalSystem<br>IsLocalSystemOnly<br>KERNEL32.DLL::CloseHandle<br>KERNEL32.DLL::CreateEventW<br>KERNEL32.DLL::CreateFileW<br>KERNEL32.DLL::DuplicateHandle<br>KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::GetComputerNameW<br>KERNEL32.DLL::GetCurrentThread<br>KERNEL32.DLL::GetCurrentThreadId<br>KERNEL32.DLL::GetLastError<br>KERNEL32.DLL::GetPrivateProfileIntW<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>KERNEL32.DLL::OpenProcess<br>KERNEL32.DLL::lstrlenW<br>NewObject<br>RPCRT4.DLL::NdrClientCall3<br>RPCRT4.DLL::RpcBindingFree<br>RPCRT4.DLL::RpcBindingFromStringBindingW<br>RPCRT4.DLL::RpcBindingSetAuthInfoW<br>RPCRT4.DLL::RpcImpersonateClient<br>RPCRT4.DLL::RpcRevertToSelf<br>RPCRT4.DLL::RpcServerInqCallAttributesW<br>RPCRT4.DLL::RpcStringBindingComposeW<br>RPCRT4.DLL::RpcStringFreeW<br>ServerFree<br>StringCbCatW<br>StringCbCopyA<br>StringCbCopyW<br>TRACELogPrint<br>ValidClientAttachParams<br>__security_check_cookie<br>_guard_dispatch_icall$thunk$10345483385596137414<br>memset</details>|<details><summary>Expand for full list:<br>ADVAPI32.DLL::AllocateAndInitializeSid<br>ADVAPI32.DLL::CheckTokenMembership<br>ADVAPI32.DLL::FreeSid<br>ADVAPI32.DLL::GetTokenInformation<br>ADVAPI32.DLL::LookupAccountSidW<br>ADVAPI32.DLL::OpenThreadToken<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCloseKey<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegCreateKeyExW<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenCurrentUser<br>API-MS-WIN-CORE-REGISTRY-L1-1-0.DLL::RegOpenKeyExW<br>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp</summary>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::wcschr<br>DSPARSE.DLL::DsMakeSpnW<br>DereferenceObject<br>Feature_2464883000__private_IsEnabledDeviceUsageNoInline<br>GetMediaModesPriorityLists<br>GetPriorityList<br>IsLocalSystem<br>IsLocalSystemOnly<br>KERNEL32.DLL::CloseHandle<br>KERNEL32.DLL::CreateEventW<br>KERNEL32.DLL::CreateFileW<br>KERNEL32.DLL::DuplicateHandle<br>KERNEL32.DLL::EnterCriticalSection<br>KERNEL32.DLL::GetComputerNameW<br>KERNEL32.DLL::GetCurrentThread<br>KERNEL32.DLL::GetCurrentThreadId<br>KERNEL32.DLL::GetLastError<br>KERNEL32.DLL::GetMailslotInfo<br>KERNEL32.DLL::GetPrivateProfileIntW<br>KERNEL32.DLL::HeapAlloc<br>KERNEL32.DLL::LeaveCriticalSection<br>KERNEL32.DLL::OpenProcess<br>KERNEL32.DLL::lstrlenW<br>NewObject<br>RPCRT4.DLL::NdrClientCall3<br>RPCRT4.DLL::RpcBindingFree<br>RPCRT4.DLL::RpcBindingFromStringBindingW<br>RPCRT4.DLL::RpcBindingSetAuthInfoW<br>RPCRT4.DLL::RpcImpersonateClient<br>RPCRT4.DLL::RpcRevertToSelf<br>RPCRT4.DLL::RpcServerInqCallAttributesW<br>RPCRT4.DLL::RpcStringBindingComposeW<br>RPCRT4.DLL::RpcStringFreeW<br>ServerFree<br>StringCbCatW<br>StringCbCopyA<br>StringCbCopyW<br>TRACELogPrint<br>ValidClientAttachParams<br>__security_check_cookie<br>_guard_dispatch_icall$thunk$10345483385596137414<br>memset</details>|
|calling|||
|paramcount|5|5|
|`address`|180027e10|180027e40|
|`sig`|int __fastcall ClientAttach(ulonglong * param_1, uint param_2, HKEY__ * param_3, LPCWSTR param_4, HKEY param_5)|int __fastcall ClientAttach(ulonglong * param_1, uint param_2, LPHANDLE param_3, LPCWSTR param_4, HKEY param_5)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### ClientAttach Called Diff


```diff
--- ClientAttach called
+++ ClientAttach called
@@ -14,0 +15 @@
+Feature_2464883000__private_IsEnabledDeviceUsageNoInline
@@ -27,0 +29 @@
+KERNEL32.DLL::GetMailslotInfo
```


### ClientAttach Diff


```diff
--- ClientAttach
+++ ClientAttach
@@ -1,599 +1,621 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Function: _guard_dispatch_icall$thunk$10345483385596137414 replaced with injection:
    guard_dispatch_icall */
-/* WARNING: Removing unreachable block (ram,0x000180028b5b) */
-/* WARNING: Removing unreachable block (ram,0x000180028b72) */
+/* WARNING: Removing unreachable block (ram,0x000180028ca3) */
+/* WARNING: Removing unreachable block (ram,0x000180028cb5) */
 /* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
-int ClientAttach(ulonglong *param_1,uint param_2,HKEY__ *param_3,LPCWSTR param_4,HKEY param_5)
+int ClientAttach(ulonglong *param_1,uint param_2,LPHANDLE param_3,LPCWSTR param_4,HKEY param_5)
 
 {
   int iVar1;
   uint uVar2;
   BOOL BVar3;
   DWORD DVar4;
   int iVar5;
   UINT UVar6;
   RPC_STATUS RVar7;
   LSTATUS LVar8;
   undefined8 uVar9;
   wchar_t *pwVar10;
-  undefined4 *puVar11;
+  HKEY pHVar11;
   LPVOID pvVar12;
   HANDLE pvVar13;
   STRSAFE_LPWSTR pwVar14;
   longlong lVar15;
-  HKEY__ *NetworkAddr;
-  wchar_t *pwVar16;
-  HKEY pHVar17;
-  longlong lVar18;
+  longlong lVar16;
   LPWSTR pszSpn;
-  LPVOID pvVar19;
-  HKEY__ *pszDest;
-  char *pcVar20;
-  int iVar21;
-  ulonglong uVar22;
-  LPCWSTR pWVar23;
-  HKEY pHVar24;
+  LPVOID pvVar17;
+  STRSAFE_LPWSTR pszDest;
+  char *pcVar18;
+  LPCWSTR lpFileName;
+  HKEY pHVar19;
   PHANDLE TokenHandle;
   CLIENT_CALL_RETURN _Str;
-  undefined8 uVar25;
-  undefined1 auStackY_658 [32];
-  DWORD local_5f8 [2];
-  HKEY local_5f0;
-  DWORD local_5e8 [2];
+  HKEY pHVar20;
+  undefined8 uVar21;
+  size_t cbDest;
+  ulonglong uVar22;
+  undefined1 auStackY_648 [32];
+  DWORD local_5e8;
+  DWORD local_5e4;
   HKEY local_5e0;
-  HANDLE local_5d8;
-  DWORD local_5d0 [2];
+  LPHANDLE local_5d8;
+  HANDLE local_5d0;
   HKEY local_5c8;
-  wchar_t *local_5c0;
+  HKEY local_5c0;
   HKEY local_5b8;
-  LPWSTR local_5b0;
-  DWORD local_5a8;
-  uint local_5a4;
-  undefined4 local_5a0;
-  RPC_WSTR local_598;
-  CLIENT_CALL_RETURN local_590;
-  LPCWSTR local_588;
-  _SID_NAME_USE local_580;
-  DWORD local_57c;
-  HKEY__ local_578 [2];
-  PSID local_570;
-  undefined4 *local_568;
+  wchar_t *local_5b0;
+  LPWSTR local_5a8;
+  DWORD local_5a0;
+  uint local_59c;
+  uint local_598;
+  undefined4 local_594;
+  STRSAFE_LPWSTR local_590;
+  CLIENT_CALL_RETURN local_588;
+  LPCWSTR local_580;
+  _SID_NAME_USE local_578;
+  DWORD local_574;
+  HANDLE local_570;
+  PSID local_568;
   undefined4 local_560;
   ulonglong *local_558;
   _SID_IDENTIFIER_AUTHORITY local_550;
   undefined8 local_548 [5];
   uint local_520;
   WCHAR local_4c8 [192];
   WCHAR local_348 [192];
   WCHAR local_1c8 [192];
   ulonglong local_48;
   
-  local_48 = __security_cookie ^ (ulonglong)auStackY_658;
+  local_48 = __security_cookie ^ (ulonglong)auStackY_648;
   local_5c8 = param_5;
-  pwVar16 = (wchar_t *)0x0;
-  iVar21 = 0;
-  local_5c0 = (wchar_t *)0x0;
+  local_5e0 = (HKEY)0x0;
   iVar5 = 0;
-  local_5a8 = 0;
-  local_5e8[0] = 0;
-  local_578[0].unused = 0xc0;
-  local_57c = 0xc0;
-  local_5d8 = (HANDLE)0x0;
-  local_570 = (PSID)0x0;
+  local_5a0 = 0;
+  local_5e4 = 0;
+  local_570._0_4_ = 0xc0;
+  local_574 = 0xc0;
+  local_5d0 = (HANDLE)0x0;
+  local_568 = (PSID)0x0;
   local_550.Value[0] = '\0';
   local_550.Value[1] = '\0';
   local_550.Value[2] = '\0';
   local_550.Value[3] = '\0';
   local_550.Value[4] = '\0';
   local_550.Value[5] = '\x05';
-  local_580 = 0;
-  local_5e0 = param_3;
-  local_588 = param_4;
+  local_578 = 0;
+  local_5d8 = param_3;
+  local_580 = param_4;
   local_558 = param_1;
   memset(local_548,0,0x78);
   uVar9 = ValidClientAttachParams(param_2,(longlong)param_4,(wchar_t *)param_5);
   if ((int)uVar9 == 0) {
     return -0x7fffffce;
   }
   uVar22 = (ulonglong)param_2;
   TRACELogPrint(0x80002,"ClientAttach: enter, pid=x%x, user=\'%ls\', machine=\'%ls\'",uVar22,param_4
                );
   if ((param_2 == 0xffffffff) && ((DAT_0 & 2) == 0)) {
-    pcVar20 = "ClientAttach: remotesp attach request received, but this is not a telephony svr!";
+    pcVar18 = "ClientAttach: remotesp attach request received, but this is not a telephony svr!";
   }
   else {
     if ((param_2 != 0xfffffffd) || (gbNTServer != 0)) {
       local_5b8 = param_5;
       pwVar10 = wcschr((wchar_t *)param_5,L'\"');
       if (pwVar10 != (wchar_t *)0x0) {
         *pwVar10 = L'\0';
-        pwVar16 = pwVar10 + 1;
-        local_5c0 = pwVar16;
+        local_5e0 = (HKEY)(pwVar10 + 1);
       }
       pvVar13 = ghTapisrvHeap;
-      puVar11 = HeapAlloc(ghTapisrvHeap,8,0x178);
-      if (puVar11 == (undefined4 *)0x0) goto LAB_1;
-      local_568 = puVar11;
-      iVar1 = NewObject(pvVar13,(longlong)puVar11,0);
-      puVar11[0x3e] = iVar1;
-      if (iVar1 == 0) {
-        ServerFree(puVar11);
-        goto LAB_1;
-      }
-      uVar9 = 0x400;
-      pvVar19 = ghTapisrvHeap;
-      pvVar12 = HeapAlloc(ghTapisrvHeap,8,0x400);
-      *(LPVOID *)(puVar11 + 0x24) = pvVar12;
-      iVar5 = 0;
-      if (pvVar12 != (LPVOID)0x0) {
-        *(undefined8 *)(puVar11 + 0x22) = 0x400;
-        *(LPVOID *)(puVar11 + 0x28) = pvVar12;
-        *(LPVOID *)(puVar11 + 0x26) = pvVar12;
-        *(undefined8 *)(puVar11 + 0x10) = 0;
-        if (((DAT_0 & 4) == 0) || ((param_2 + 3 & 0xfffffffd) != 0)) {
-          uVar2 = RpcImpersonateClient((RPC_BINDING_HANDLE)0x0);
-          if (uVar2 == 0) {
+      pHVar11 = HeapAlloc(ghTapisrvHeap,8,0x178);
+      if (pHVar11 != (HKEY)0x0) {
+        local_5c0 = pHVar11;
+        iVar1 = NewObject(pvVar13,(longlong)pHVar11,0);
+        pHVar11[0x3e].unused = iVar1;
+        if (iVar1 == 0) {
+          ServerFree(pHVar11);
+        }
+        else {
+          uVar9 = 0x400;
+          pvVar17 = ghTapisrvHeap;
+          pvVar12 = HeapAlloc(ghTapisrvHeap,8,0x400);
+          *(LPVOID *)(pHVar11 + 0x24) = pvVar12;
+          iVar5 = 0;
+          if (pvVar12 != (LPVOID)0x0) {
+            *(undefined8 *)(pHVar11 + 0x22) = 0x400;
+            *(LPVOID *)(pHVar11 + 0x28) = pvVar12;
+            *(LPVOID *)(pHVar11 + 0x26) = pvVar12;
+            *(undefined8 *)(pHVar11 + 0x10) = 0;
+            if (((DAT_0 & 4) != 0) && ((param_2 + 3 & 0xfffffffd) == 0)) {
+              TRACELogPrint(0x10002,"A client tried to attach, but TAPISRV is PAUSED",uVar9,param_4)
+              ;
+LAB_1:
+              pvVar17 = *(LPVOID *)(pHVar11 + 0x24);
+              ServerFree(pvVar17);
+              DereferenceObject(pvVar17,pHVar11[0x3e].unused,1);
+              return -0x7fffffb8;
+            }
+            uVar2 = RpcImpersonateClient((RPC_BINDING_HANDLE)0x0);
+            if (uVar2 != 0) {
+              TRACELogPrint(0x10002,"ClientAttach: RpcImpersonateClient failed, err=%d",
+                            (ulonglong)uVar2,param_4);
+              goto LAB_1;
+            }
             pvVar13 = GetCurrentThread();
-            TokenHandle = &local_5d8;
+            TokenHandle = &local_5d0;
             BVar3 = OpenThreadToken(pvVar13,0x20008,0,TokenHandle);
-            if (BVar3 != 0) {
-              local_5f0 = (HKEY)0x800;
+            if (BVar3 == 0) {
+              DVar4 = GetLastError();
+              TRACELogPrint(0x10002,"ClientAttach: OpenThreadToken failed, err=%u",(ulonglong)DVar4,
+                            TokenHandle);
+LAB_2:
+              RpcRevertToSelf();
+              goto LAB_1;
+            }
+            cbDest = 0x800;
+            local_5e4 = 0x800;
+            pwVar14 = HeapAlloc(ghTapisrvHeap,8,0x800);
+            if (pwVar14 != (STRSAFE_LPWSTR)0x0) {
               while( true ) {
-                local_5e8[0] = (DWORD)local_5f0;
-                local_5a8 = 0;
-                pwVar14 = HeapAlloc(ghTapisrvHeap,8,(SIZE_T)local_5f0);
-                if (pwVar14 == (STRSAFE_LPWSTR)0x0) goto LAB_2;
-                uVar22 = (ulonglong)local_5e8[0];
-                BVar3 = GetTokenInformation(local_5d8,TokenUser,pwVar14,local_5e8[0],&local_5a8);
+                uVar22 = (ulonglong)local_5e4;
+                BVar3 = GetTokenInformation(local_5d0,TokenUser,pwVar14,local_5e4,&local_5a0);
                 if (BVar3 != 0) break;
                 DVar4 = GetLastError();
                 TRACELogPrint(0x10002,"ClientAttach: GetTokenInformation failed, err=%u",
                               (ulonglong)DVar4,uVar22);
                 ServerFree(pwVar14);
                 DVar4 = GetLastError();
-                if (DVar4 != 0x7a) {
-LAB_3:
-                  CloseHandle(local_5d8);
-                  goto LAB_4;
-                }
-                local_5f0 = (HKEY)(ulonglong)(local_5e8[0] * 2);
-              }
-              pwVar10 = (wchar_t *)local_578;
+                if (DVar4 != 0x7a) goto LAB_3;
+                local_5e4 = local_5e4 * 2;
+                cbDest = (size_t)local_5e4;
+                local_5a0 = 0;
+                pwVar14 = HeapAlloc(ghTapisrvHeap,8,(ulonglong)local_5e4);
+                if (pwVar14 == (STRSAFE_LPWSTR)0x0) goto LAB_4;
+              }
+              pwVar10 = (wchar_t *)&local_570;
               BVar3 = LookupAccountSidW((LPCWSTR)0x0,*(PSID *)pwVar14,local_348,(LPDWORD)pwVar10,
-                                        local_4c8,&local_57c,&local_580);
+                                        local_4c8,&local_574,&local_578);
               if (BVar3 == 0) {
                 uVar2 = GetLastError();
-                pcVar20 = "ClientAttach: LookupAccountSidW failed, err=%u";
+                pcVar18 = "ClientAttach: LookupAccountSidW failed, err=%u";
 LAB_5:
-                TRACELogPrint(0x10002,pcVar20,(ulonglong)uVar2,pwVar10);
+                TRACELogPrint(0x10002,pcVar18,(ulonglong)uVar2,pwVar10);
                 ServerFree(pwVar14);
-                goto LAB_3;
+LAB_3:
+                CloseHandle(local_5d0);
+                goto LAB_2;
               }
               TRACELogPrint(0x40002,"ClientAttach: LookupAccountSidW: User name %ls Domain name %ls"
                             ,local_348,local_4c8);
               pwVar10 = (wchar_t *)0x220;
-              BVar3 = AllocateAndInitializeSid(&local_550,'\x02',0x20,0x220,0,0,0,0,0,0,&local_570);
+              BVar3 = AllocateAndInitializeSid(&local_550,'\x02',0x20,0x220,0,0,0,0,0,0,&local_568);
               if (BVar3 == 0) {
                 uVar2 = GetLastError();
-                pcVar20 = "ClientAttach: AllocateAndInitializeSid failed, err=%u";
+                pcVar18 = "ClientAttach: AllocateAndInitializeSid failed, err=%u";
                 goto LAB_5;
               }
-              local_5f8[0] = 0;
-              puVar11[0x36] = puVar11[0x36] & 0xfffffff6;
-              BVar3 = CheckTokenMembership(local_5d8,local_570,(PBOOL)local_5f8);
+              local_5e8 = 0;
+              pHVar11[0x36].unused = pHVar11[0x36].unused & 0xfffffff6;
+              BVar3 = CheckTokenMembership(local_5d0,local_568,(PBOOL)&local_5e8);
               if (BVar3 == 0) {
                 DVar4 = GetLastError();
                 TRACELogPrint(0x10002,"ClientAttach: CheckTokenMembership failed, err=%u",
                               (ulonglong)DVar4,pwVar10);
               }
               if ((DAT_0 & 2) == 0) {
 LAB_6:
-                if (local_5f8[0] == 0) goto LAB_7;
+                if (local_5e8 == 0) goto LAB_7;
 LAB_8:
-                puVar11[0x36] = puVar11[0x36] | 8;
+                pHVar11[0x36].unused = pHVar11[0x36].unused | 8;
               }
               else {
-                if (local_5f8[0] != 0) {
+                if (local_5e8 != 0) {
                   if (param_2 == 0xffffffff) {
-                    local_5e8[0] = 0xc0;
-                    BVar3 = GetComputerNameW(local_1c8,local_5e8);
+                    local_5e4 = 0xc0;
+                    BVar3 = GetComputerNameW(local_1c8,&local_5e4);
                     if ((BVar3 != 0) && (iVar5 = _o__wcsicmp(local_1c8,local_4c8), iVar5 == 0)) {
-                      local_5f8[0] = 0;
+                      local_5e8 = 0;
                       StringCbCopyW(local_4c8,0x180,(STRSAFE_LPCWSTR)local_5c8);
                     }
                   }
                   goto LAB_6;
                 }
 LAB_7:
-                DVar4 = IsLocalSystemOnly(local_5d8);
+                DVar4 = IsLocalSystemOnly(local_5d0);
                 if (DVar4 == 0) goto LAB_8;
               }
-              if ((local_5f8[0] != 0) || (DVar4 = IsLocalSystem(local_5d8), DVar4 == 0)) {
-                puVar11[0x36] = puVar11[0x36] | 1;
-              }
-              FreeSid(local_570);
-              if ((gbNTServer != 0) && ((*(byte *)(puVar11 + 0x36) & 8) == 0)) {
-                StringCbCopyW(pwVar14,(size_t)local_5f0,local_4c8);
-                StringCbCatW(pwVar14,(size_t)local_5f0,L"\\");
-                StringCbCatW(pwVar14,(size_t)local_5f0,local_348);
+              if ((local_5e8 != 0) || (DVar4 = IsLocalSystem(local_5d0), DVar4 == 0)) {
+                pHVar11[0x36].unused = pHVar11[0x36].unused | 1;
+              }
+              FreeSid(local_568);
+              if ((gbNTServer != 0) && ((pHVar11[0x36].unused & 8) == 0)) {
+                StringCbCopyW(pwVar14,cbDest,local_4c8);
+                StringCbCatW(pwVar14,cbDest,L"\\");
+                StringCbCatW(pwVar14,cbDest,local_348);
                 pwVar10 = gszFileName;
                 UVar6 = GetPrivateProfileIntW(gszTapiAdministrators,pwVar14,0,gszFileName);
                 if (UVar6 == 1) {
-                  puVar11[0x36] = puVar11[0x36] | 9;
+                  pHVar11[0x36].unused = pHVar11[0x36].unused | 9;
                 }
               }
               ServerFree(pwVar14);
-              CloseHandle(local_5d8);
+              CloseHandle(local_5d0);
               RpcRevertToSelf();
               iVar5 = lstrlenW(local_348);
               uVar2 = iVar5 * 2 + 2;
-              puVar11[4] = uVar2;
+              pHVar11[4].unused = uVar2;
               pwVar14 = HeapAlloc(ghTapisrvHeap,8,(ulonglong)uVar2);
-              *(STRSAFE_LPWSTR *)(puVar11 + 6) = pwVar14;
+              *(STRSAFE_LPWSTR *)(pHVar11 + 6) = pwVar14;
               iVar5 = 0;
               if (pwVar14 == (STRSAFE_LPWSTR)0x0) goto LAB_9;
-              StringCbCopyW(pwVar14,(ulonglong)(uint)puVar11[4],local_348);
+              StringCbCopyW(pwVar14,(ulonglong)(uint)pHVar11[4].unused,local_348);
               iVar5 = lstrlenW(local_4c8);
               uVar22 = (longlong)(iVar5 + 1) * 2;
               pwVar14 = HeapAlloc(ghTapisrvHeap,8,uVar22 & 0xffffffff);
-              *(STRSAFE_LPWSTR *)(puVar11 + 0xc) = pwVar14;
+              *(STRSAFE_LPWSTR *)(pHVar11 + 0xc) = pwVar14;
+              iVar5 = 0;
               if (pwVar14 == (STRSAFE_LPWSTR)0x0) goto LAB_10;
               StringCbCopyW(pwVar14,uVar22,local_4c8);
-              pHVar17 = local_5c8;
+              pHVar19 = local_5c8;
               if ((param_2 + 3 & 0xfffffffd) == 0) {
                 iVar5 = lstrlenW((LPCWSTR)local_5c8);
                 uVar2 = iVar5 * 2 + 2;
-                puVar11[8] = uVar2;
+                pHVar11[8].unused = uVar2;
                 pwVar14 = HeapAlloc(ghTapisrvHeap,8,(ulonglong)uVar2);
-                *(STRSAFE_LPWSTR *)(puVar11 + 10) = pwVar14;
-                iVar21 = 0;
+                *(STRSAFE_LPWSTR *)(pHVar11 + 10) = pwVar14;
+                iVar5 = 0;
                 if (pwVar14 == (STRSAFE_LPWSTR)0x0) goto LAB_11;
-                StringCbCopyW(pwVar14,(ulonglong)(uint)puVar11[8],(STRSAFE_LPCWSTR)pHVar17);
+                StringCbCopyW(pwVar14,(ulonglong)(uint)pHVar11[8].unused,(STRSAFE_LPCWSTR)pHVar19);
               }
               local_548[0] = 3;
               uVar2 = RpcServerInqCallAttributesW(0,local_548);
               if (uVar2 == 0) {
                 pwVar10 = (wchar_t *)(ulonglong)local_520;
-                pcVar20 = "ClientAttach(%S): Auth level = 0x%x";
+                pcVar18 = "ClientAttach(%S): Auth level = 0x%x";
                 TRACELogPrint(0x40002,"ClientAttach(%S): Auth level = 0x%x",
-                              *(undefined8 *)(puVar11 + 6),pwVar10);
-                pWVar23 = local_588;
+                              *(undefined8 *)(pHVar11 + 6),pwVar10);
+                lpFileName = local_580;
                 if (param_2 == 0xffffffff) {
-                  local_5d0[0] = 6;
+                  local_598 = 6;
                   if (local_520 != 6) {
                     if (gbHighSecurity != 0) goto LAB_12;
-                    local_5d0[0] = 0;
+                    local_598 = 0;
                   }
-                  local_5e0->unused = -0x5a3c965b;
+                  *(undefined4 *)local_5d8 = 0xa5c369a5;
                   lVar15 = -1;
                   do {
                     lVar15 = lVar15 + 1;
-                  } while (local_588[lVar15] != L'\0');
+                  } while (local_580[lVar15] != L'\0');
                   if (lVar15 != 0) {
-                    *(undefined8 *)(puVar11 + 2) = 0xfffffffffffffffe;
-                    pcVar20 = (char *)0x40000000;
-                    pvVar13 = CreateFileW(local_588,0x40000000,1,(LPSECURITY_ATTRIBUTES)0x0,3,0x80,
-                                          (HANDLE)0x0);
-                    *(HANDLE *)(puVar11 + 0x20) = pvVar13;
-                    if (pvVar13 != (HANDLE)0xffffffffffffffff) goto LAB_13;
-                    DVar4 = GetLastError();
-                    uVar22 = (ulonglong)DVar4;
-                    TRACELogPrint(0x10002,"ClientAttach: CreateFile(%ws) failed, err=%u",pWVar23,
-                                  uVar22);
+                    uVar2 = Feature_2464883000__private_IsEnabledDeviceUsageNoInline();
+                    *(undefined8 *)(pHVar11 + 2) = 0xfffffffffffffffe;
+                    pcVar18 = (char *)0x40000000;
+                    if (uVar2 == 0) {
+                      pvVar13 = CreateFileW(lpFileName,0x40000000,1,(LPSECURITY_ATTRIBUTES)0x0,3,
+                                            0x80,(HANDLE)0x0);
+                      *(HANDLE *)(pHVar11 + 0x20) = pvVar13;
+                      if (pvVar13 != (HANDLE)0xffffffffffffffff) goto LAB_13;
+                      uVar2 = GetLastError();
+                      pcVar18 = "ClientAttach: CreateFile(%ws) failed, err=%u";
+                    }
+                    else {
+                      local_5d8 = (LPHANDLE)((ulonglong)local_5d8 & 0xffffffff00000000);
+                      local_5b0 = (wchar_t *)((ulonglong)local_5b0 & 0xffffffff00000000);
+                      local_590 = (STRSAFE_LPWSTR)((ulonglong)local_590 & 0xffffffff00000000);
+                      local_5e8 = 0;
+                      pvVar13 = CreateFileW(lpFileName,0x40000000,1,(LPSECURITY_ATTRIBUTES)0x0,3,
+                                            0x80,(HANDLE)0x0);
+                      *(HANDLE *)(pHVar11 + 0x20) = pvVar13;
+                      if (pvVar13 != (HANDLE)0xffffffffffffffff) {
+                        pcVar18 = (char *)&local_5d8;
+                        BVar3 = GetMailslotInfo(pvVar13,(LPDWORD)pcVar18,(LPDWORD)&local_5b0,
+                                                (LPDWORD)&local_590,&local_5e8);
+                        if (BVar3 == 1) goto LAB_13;
+                      }
+                      if (*(HANDLE *)(pHVar11 + 0x20) == (HANDLE)0xffffffffffffffff) {
+                        pcVar18 = "ClientAttach: CreateFile(%ws) failed, err=%u";
+                      }
+                      else {
+                        CloseHandle(*(HANDLE *)(pHVar11 + 0x20));
+                        *(undefined8 *)(pHVar11 + 0x20) = 0xffffffffffffffff;
+                        pcVar18 = "ClientAttach: GetMailslotInfo(%ws) failed, err=%u";
+                      }
+                      uVar2 = GetLastError();
+                    }
+                    uVar22 = (ulonglong)uVar2;
+                    TRACELogPrint(0x10002,pcVar18,lpFileName,uVar22);
                     TRACELogPrint(0x10002,"ClientAttach: trying connection-oriented approach...",
-                                  pWVar23,uVar22);
+                                  lpFileName,uVar22);
                   }
-                  *(undefined8 *)(puVar11 + 2) = 0xffffffffffffffff;
-                  local_588 = (LPCWSTR)0x0;
-                  local_598 = (RPC_WSTR)0x0;
-                  local_5f8[0] = 0;
-                  local_5b0 = (LPWSTR)0x0;
-                  iVar5 = lstrlenW((LPCWSTR)local_5c8);
-                  local_5f0 = (HKEY)((longlong)iVar5 * 2 + 6);
-                  NetworkAddr = HeapAlloc(ghTapisrvHeap,8,(ulonglong)local_5f0 & 0xffffffff);
-                  iVar21 = 0;
-                  local_5e0 = NetworkAddr;
-                  if (NetworkAddr != (HKEY__ *)0x0) {
-                    iVar5 = _o__wcsicmp(L"ncacn_np",pwVar16);
-                    pszDest = NetworkAddr;
-                    pHVar17 = local_5f0;
+                  *(undefined8 *)(pHVar11 + 2) = 0xffffffffffffffff;
+                  local_580 = (LPCWSTR)0x0;
+                  local_5d8 = (LPHANDLE)0x0;
+                  local_5e8 = 0;
+                  local_5a8 = (LPWSTR)0x0;
+                  iVar1 = lstrlenW((LPCWSTR)pHVar19);
+                  uVar22 = (longlong)iVar1 * 2 + 6;
+                  pwVar14 = HeapAlloc(ghTapisrvHeap,8,uVar22 & 0xffffffff);
+                  iVar5 = 0;
+                  local_590 = pwVar14;
+                  if (pwVar14 != (STRSAFE_LPWSTR)0x0) {
+                    iVar5 = _o__wcsicmp(L"ncacn_np",local_5e0);
+                    pszDest = pwVar14;
                     if (iVar5 == 0) {
-                      NetworkAddr->unused = 0x5c005c;
-                      pszDest = NetworkAddr + 1;
-                      pHVar17 = local_5f0 + -1;
-                    }
-                    StringCbCopyW((STRSAFE_LPWSTR)pszDest,(size_t)pHVar17,(STRSAFE_LPCWSTR)local_5c8
-                                 );
+                      pwVar14[0] = L'\\';
+                      pwVar14[1] = L'\\';
+                      uVar22 = (longlong)iVar1 * 2 + 2;
+                      pszDest = pwVar14 + 2;
+                    }
+                    StringCbCopyW(pszDest,uVar22,(STRSAFE_LPCWSTR)local_5c8);
                     pszSpn = (LPWSTR)0x0;
                     EnterCriticalSection((LPCRITICAL_SECTION)&DAT_14);
                     do {
-                      pwVar16 = wcschr(pwVar16,L'\"');
-                      *pwVar16 = L'\0';
-                      _Str.Pointer = pwVar16 + 1;
-                      local_590.Pointer = _Str.Pointer;
-                      pHVar17 = (HKEY)wcschr(_Str.Pointer,L'\"');
-                      if (pHVar17 == (HKEY)0x0) {
+                      pwVar10 = wcschr((wchar_t *)local_5e0,L'\"');
+                      *pwVar10 = L'\0';
+                      _Str.Pointer = pwVar10 + 1;
+                      local_588.Pointer = _Str.Pointer;
+                      pwVar10 = wcschr(_Str.Pointer,L'\"');
+                      if (pwVar10 == (wchar_t *)0x0) {
                         lVar15 = -1;
                         do {
-                          lVar18 = lVar15;
-                          lVar15 = lVar18 + 1;
+                          lVar16 = lVar15;
+                          lVar15 = lVar16 + 1;
                         } while (*(wchar_t *)((longlong)_Str.Pointer + lVar15 * 2) != L'\0');
-                        pHVar17 = (HKEY)((longlong)_Str.Pointer + lVar18 * 2);
+                        pwVar10 = (wchar_t *)((longlong)_Str.Pointer + lVar16 * 2);
                       }
                       else {
-                        *(wchar_t *)&pHVar17->unused = L'\0';
-                      }
-                      local_5f0 = pHVar17;
-                      local_5a4 = RpcStringBindingComposeW
-                                            ((RPC_WSTR)0x0,(RPC_WSTR)local_5c0,(RPC_WSTR)NetworkAddr
-                                             ,_Str.Pointer,(RPC_WSTR)0x0,&local_598);
-                      if (local_5a4 != 0) {
+                        *pwVar10 = L'\0';
+                      }
+                      local_5b0 = pwVar10;
+                      local_59c = RpcStringBindingComposeW
+                                            ((RPC_WSTR)0x0,(RPC_WSTR)local_5e0,(RPC_WSTR)pwVar14,
+                                             _Str.Pointer,(RPC_WSTR)0x0,(RPC_WSTR *)&local_5d8);
+                      if (local_59c != 0) {
                         TRACELogPrint(0x10002,
                                       "ClientAttach: RpcStringBindingComposeW failed, err=%d",
-                                      (ulonglong)local_5a4,_Str);
-                      }
-                      uVar2 = RpcBindingFromStringBindingW(local_598,&hRemoteSP);
-                      local_5a4 = uVar2;
+                                      (ulonglong)local_59c,_Str);
+                      }
+                      uVar2 = RpcBindingFromStringBindingW((RPC_WSTR)local_5d8,&hRemoteSP);
+                      local_59c = uVar2;
                       if (uVar2 == 0) goto LAB_15;
                       TRACELogPrint(0x10002,
                                     "ClientAttach: RpcBindingFromStringBinding failed, err=%d",
                                     (ulonglong)uVar2,_Str);
-                      pHVar24 = local_5c8;
-                      pwVar10 = local_5c0;
+                      pHVar19 = local_5c8;
+                      pHVar20 = local_5e0;
                       TRACELogPrint(0x40002,"\t szMachine=%ws, protseq=%ws endpoint=%ws",local_5c8,
-                                    local_5c0);
-                      RpcStringFreeW(&local_598);
-                      pwVar16 = (wchar_t *)((longlong)&pHVar17->unused + 2);
-                      local_5c0 = pwVar16;
-                    } while (*pwVar16 != L'\0');
+                                    local_5e0);
+                      RpcStringFreeW((RPC_WSTR *)&local_5d8);
+                      local_5e0 = (HKEY)(pwVar10 + 1);
+                    } while ((wchar_t)local_5e0->unused != L'\0');
                     if (uVar2 != 0) {
                       TRACELogPrint(0x10002,"ClientAttach: error, can\'t find a usable protseq",
-                                    pHVar24,pwVar10);
+                                    pHVar19,pHVar20);
                       LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_14);
-                      ServerFree(NetworkAddr);
+                      ServerFree(pwVar14);
 LAB_16:
-                      iVar21 = -0x7fffffb8;
+                      iVar5 = -0x7fffffb8;
                       goto LAB_17;
                     }
 LAB_15:
-                    pHVar17 = local_5c8;
+                    pHVar19 = local_5c8;
                     TRACELogPrint(0x80002,
                                   "ClientAttach: szMachine=%ws trying protseq=%ws endpoint=%ws",
-                                  local_5c8,local_5c0);
-                    local_5f8[0] = 0;
-                    DVar4 = DsMakeSpnW(L"tapinego",(LPCWSTR)pHVar17,(LPCWSTR)0x0,0,(LPCWSTR)0x0,
-                                       local_5f8,(LPWSTR)0x0);
+                                  local_5c8,local_5e0);
+                    local_5e8 = 0;
+                    DVar4 = DsMakeSpnW(L"tapinego",(LPCWSTR)pHVar19,(LPCWSTR)0x0,0,(LPCWSTR)0x0,
+                                       &local_5e8,(LPWSTR)0x0);
                     if (DVar4 == 0x6f) {
-                      pszSpn = HeapAlloc(ghTapisrvHeap,8,(ulonglong)(local_5f8[0] * 2 + 2));
-                      uVar25 = 0;
+                      pszSpn = HeapAlloc(ghTapisrvHeap,8,(ulonglong)(local_5e8 * 2 + 2));
+                      uVar21 = 0;
                       uVar9 = 0;
-                      local_5b0 = pszSpn;
-                      DVar4 = DsMakeSpnW(L"tapinego",(LPCWSTR)pHVar17,(LPCWSTR)0x0,0,(LPCWSTR)0x0,
-                                         local_5f8,pszSpn);
+                      local_5a8 = pszSpn;
+                      DVar4 = DsMakeSpnW(L"tapinego",(LPCWSTR)pHVar19,(LPCWSTR)0x0,0,(LPCWSTR)0x0,
+                                         &local_5e8,pszSpn);
                       if ((DVar4 != 0) &&
-                         (TRACELogPrint(0x10002,"ClientAttach: error,can\'t make SPN",uVar9,uVar25),
+                         (TRACELogPrint(0x10002,"ClientAttach: error,can\'t make SPN",uVar9,uVar21),
                          pszSpn != (LPWSTR)0x0)) {
                         ServerFree(pszSpn);
                         pszSpn = (LPWSTR)0x0;
-                        local_5b0 = (LPWSTR)0x0;
+                        local_5a8 = (LPWSTR)0x0;
                       }
                     }
                     uVar9 = 9;
-                    uVar22 = (ulonglong)local_5d0[0];
+                    uVar22 = (ulonglong)local_598;
                     RVar7 = RpcBindingSetAuthInfoW
-                                      (hRemoteSP,(RPC_WSTR)pszSpn,local_5d0[0],9,
+                                      (hRemoteSP,(RPC_WSTR)pszSpn,local_598,9,
                                        (RPC_AUTH_IDENTITY_HANDLE)0x0,0);
                     if (pszSpn != (LPWSTR)0x0) {
                       ServerFree(pszSpn);
-                      local_5b0 = (LPWSTR)0x0;
+                      local_5a8 = (LPWSTR)0x0;
                     }
                     if (RVar7 == 0) {
-                      local_590 = (CLIENT_CALL_RETURN)0x0;
-                      pcVar20 = (char *)0x0;
-                      local_590 = NdrClientCall3((MIDL_STUBLESS_PROXY_INFO *)&PTR_PTR_180044d20,0,
+                      local_588 = (CLIENT_CALL_RETURN)0x0;
+                      pcVar18 = (char *)0x0;
+                      local_588 = NdrClientCall3((MIDL_STUBLESS_PROXY_INFO *)&PTR_PTR_180045d20,0,
                                                  (void *)0x0);
-                      local_5a0 = 0;
+                      local_594 = 0;
                       RpcBindingFree(&hRemoteSP);
-                      RpcStringFreeW(&local_598);
+                      RpcStringFreeW((RPC_WSTR *)&local_5d8);
                       LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_14);
-                      ServerFree(NetworkAddr);
-                      *(LPCWSTR *)(puVar11 + 0xe) = local_588;
+                      ServerFree(pwVar14);
+                      *(LPCWSTR *)(pHVar11 + 0xe) = local_580;
 LAB_13:
                       EnterCriticalSection((LPCRITICAL_SECTION)&DAT_18);
-                      _DAT_19 = 0x1556;
+                      _DAT_19 = 0x157f;
                       _DAT_20 = GetCurrentThreadId();
-                      StringCbCopyA(&DAT_21,(size_t)pcVar20,"server\\server.c");
+                      StringCbCopyA(&DAT_21,(size_t)pcVar18,"server\\server.c");
                       lVar15 = (longlong)DAT_22;
-                      *(undefined4 **)(puVar11 + 0x34) = DAT_22;
-                      if (DAT_22 != (undefined4 *)0x0) {
-                        *(undefined4 **)(lVar15 + 200) = puVar11;
+                      *(HKEY *)(pHVar11 + 0x34) = DAT_22;
+                      if (DAT_22 != (HKEY)0x0) {
+                        *(HKEY *)(lVar15 + 200) = pHVar11;
                       }
                       gfWeHadAtLeastOneClient = 1;
-                      DAT_22 = puVar11;
-                      *puVar11 = 0x544e4c43;
+                      DAT_22 = pHVar11;
+                      pHVar11->unused = 0x544e4c43;
                       for (lVar15 = DAT_23; lVar15 != 0;
                           lVar15 = *(longlong *)(lVar15 + 0x30)) {
                         if (*(code **)(lVar15 + 0x400) != (code *)0x0) {
                           (**(code **)(lVar15 + 0x400))(*(undefined4 *)(lVar15 + 0x20));
                         }
                       }
-                      _DAT_24 = 0x1577;
+                      _DAT_24 = 0x15a0;
                       _DAT_25 = GetCurrentThreadId();
-                      StringCbCopyA(&DAT_26,(size_t)pcVar20,"server\\server.c");
+                      StringCbCopyA(&DAT_26,(size_t)pcVar18,"server\\server.c");
                       LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_18);
-                      *local_558 = (ulonglong)(uint)puVar11[0x3e];
+                      *local_558 = (ulonglong)(uint)pHVar11[0x3e].unused;
                       _DAT_27 = _DAT_27 + 1;
                       return 0;
                     }
                     TRACELogPrint(0x10002,"ClientAttach: error in RpcBindingSetAuthInfo",uVar22,
                                   uVar9);
                     LeaveCriticalSection((LPCRITICAL_SECTION)&DAT_14);
-                    ServerFree(NetworkAddr);
+                    ServerFree(pwVar14);
                     local_560 = 0x80000048;
-                    iVar21 = -0x7fffffb8;
+                    iVar5 = -0x7fffffb8;
                   }
 LAB_17:
-                  if (*(LPVOID *)(puVar11 + 10) != DAT_28) {
-                    ServerFree(*(LPVOID *)(puVar11 + 10));
+                  if (*(LPVOID *)(pHVar11 + 10) != DAT_28) {
+                    ServerFree(*(LPVOID *)(pHVar11 + 10));
                   }
 LAB_11:
-                  ServerFree(*(LPVOID *)(puVar11 + 0xc));
+                  ServerFree(*(LPVOID *)(pHVar11 + 0xc));
 LAB_10:
-                  ServerFree(*(LPVOID *)(puVar11 + 6));
-                  iVar5 = iVar21;
+                  ServerFree(*(LPVOID *)(pHVar11 + 6));
                   goto LAB_9;
                 }
                 if (param_2 == 0xfffffffd) {
                   if ((gbHighSecurity == 0) || (local_520 == 6)) {
-                    if ((*(byte *)(puVar11 + 0x36) & 1) != 0) {
-                      *(undefined8 *)(puVar11 + 2) = 0xfffffffffffffffd;
-                      local_5e0->unused = 0x64646464;
+                    if ((pHVar11[0x36].unused & 1) != 0) {
+                      *(undefined8 *)(pHVar11 + 2) = 0xfffffffffffffffd;
+                      *(undefined4 *)local_5d8 = 0x64646464;
                       goto LAB_13;
                     }
-                    iVar21 = -0x13;
+                    iVar5 = -0x13;
                     goto LAB_17;
                   }
 LAB_12:
-                  pcVar20 = "ClientAttach: unsecure call, AuthLevel=0x%x";
+                  pcVar18 = "ClientAttach: unsecure call, AuthLevel=0x%x";
                   uVar2 = local_520;
                 }
                 else {
                   uVar2 = RpcImpersonateClient((RPC_BINDING_HANDLE)0x0);
                   if (uVar2 == 0) {
                     pvVar13 = OpenProcess(0x40,0,param_2);
-                    *(HANDLE *)(puVar11 + 2) = pvVar13;
+                    *(HANDLE *)(pHVar11 + 2) = pvVar13;
                     if (pvVar13 == (HANDLE)0x0) {
                       DVar4 = GetLastError();
                       TRACELogPrint(0x10002,"OpenProcess(pid=x%x) failed, err=%u",(ulonglong)param_2
                                     ,(ulonglong)DVar4);
                       RpcRevertToSelf();
-                      iVar21 = 0;
+                      iVar5 = 0;
                       goto LAB_17;
                     }
-                    puVar11[8] = DAT_29;
-                    *(LPVOID *)(puVar11 + 10) = DAT_28;
-                    pcVar20 = CreateEventW((LPSECURITY_ATTRIBUTES)0x0,1,0,(LPCWSTR)0x0);
-                    *(char **)(puVar11 + 0x20) = pcVar20;
-                    if ((wchar_t *)pcVar20 == (wchar_t *)0x0) {
+                    pHVar11[8].unused = DAT_29;
+                    *(LPVOID *)(pHVar11 + 10) = DAT_28;
+                    pcVar18 = CreateEventW((LPSECURITY_ATTRIBUTES)0x0,1,0,(LPCWSTR)0x0);
+                    *(char **)(pHVar11 + 0x20) = pcVar18;
+                    if ((LPHANDLE *)pcVar18 == (LPHANDLE *)0x0) {
                       RpcRevertToSelf();
                       goto LAB_16;
                     }
-                    pwVar10 = (wchar_t *)local_5e0;
-                    BVar3 = DuplicateHandle(DAT_30,pcVar20,*(HANDLE *)(puVar11 + 2),
-                                            (LPHANDLE)local_5e0,0,0,2);
+                    pwVar10 = (wchar_t *)local_5d8;
+                    BVar3 = DuplicateHandle(DAT_30,pcVar18,*(HANDLE *)(pHVar11 + 2),local_5d8
+                                            ,0,0,2);
                     if (BVar3 == 0) {
                       DVar4 = GetLastError();
-                      pcVar20 = "ClientAttach: DupHandle failed, err=%u";
+                      pcVar18 = "ClientAttach: DupHandle failed, err=%u";
                       TRACELogPrint(0x10002,"ClientAttach: DupHandle failed, err=%u",
                                     (ulonglong)DVar4,pwVar10);
                     }
                     RpcRevertToSelf();
                     if (gbPriorityListsInitialized == 0) {
                       uVar2 = RpcImpersonateClient((RPC_BINDING_HANDLE)0x0);
                       if (uVar2 != 0) {
-                        pcVar20 = "ClientAttach: RpcImpersonateClient failed, err=%d";
+                        pcVar18 = "ClientAttach: RpcImpersonateClient failed, err=%d";
                         goto LAB_31;
                       }
                       EnterCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
                       if (gbPriorityListsInitialized == 0) {
-                        local_5f0 = (HKEY)0x0;
-                        local_5b8 = (HKEY)0x0;
+                        local_5e0 = (HKEY)0x0;
+                        local_5c0 = (HKEY)0x0;
                         gbPriorityListsInitialized = 1;
-                        uVar2 = RegOpenCurrentUser(0xf003f,&local_5b8);
+                        uVar2 = RegOpenCurrentUser(0xf003f,&local_5c0);
                         if (uVar2 == 0) {
                           uVar9 = 0x20019;
-                          uVar2 = RegOpenKeyExW(local_5b8,
+                          uVar2 = RegOpenKeyExW(local_5c0,
                                                 L"Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\HandoffPriorities"
-                                                ,0,0x20019,&local_5f0);
+                                                ,0,0x20019,&local_5e0);
                           if (uVar2 == 0) {
-                            local_5e0 = (HKEY)0x0;
-                            local_5d0[0] = 0;
-                            pwVar16 = L"";
+                            local_5b8 = (HKEY)0x0;
+                            local_5d8 = (LPHANDLE)((ulonglong)local_5d8 & 0xffffffff00000000);
+                            pwVar10 = L"";
                             uVar9 = 0;
-                            LVar8 = RegCreateKeyExW(local_5f0,L"MediaModes",0,L"",0,0xf003f,
-                                                    (LPSECURITY_ATTRIBUTES)0x0,&local_5e0,local_5d0)
-                            ;
+                            LVar8 = RegCreateKeyExW(local_5e0,L"MediaModes",0,L"",0,0xf003f,
+                                                    (LPSECURITY_ATTRIBUTES)0x0,&local_5b8,
+                                                    (LPDWORD)&local_5d8);
                             if (LVar8 == 0) {
                               GetMediaModesPriorityLists
-                                        (local_5e0,&DAT_32,uVar9,(LPDWORD)pwVar16);
-                              RegCloseKey(local_5e0);
+                                        (local_5b8,&DAT_32,uVar9,(LPDWORD)pwVar10);
+                              RegCloseKey(local_5b8);
                             }
-                            pwVar16 = L"RequestMediaCall";
-                            GetPriorityList(local_5f0,L"RequestMediaCall",&DAT_33);
-                            RegCloseKey(local_5f0);
+                            pwVar10 = L"RequestMediaCall";
+                            GetPriorityList(local_5e0,L"RequestMediaCall",&DAT_33);
+                            RegCloseKey(local_5e0);
                           }
                           else {
-                            pcVar20 = "RegOpenKey(\'\\HandoffPri\') failed, err=%ld";
+                            pcVar18 = "RegOpenKey(\'\\HandoffPri\') failed, err=%ld";
                             TRACELogPrint(0x10002,"RegOpenKey(\'\\HandoffPri\') failed, err=%ld",
                                           (ulonglong)uVar2,uVar9);
-                            pwVar16 = (wchar_t *)pcVar20;
+                            pwVar10 = (wchar_t *)pcVar18;
                           }
-                          RegCloseKey(local_5b8);
-                          pcVar20 = (char *)pwVar16;
+                          RegCloseKey(local_5c0);
+                          pcVar18 = (char *)pwVar10;
                         }
                         else {
-                          pcVar20 = "RegOpenCurrentUser failed, err=%ld";
+                          pcVar18 = "RegOpenCurrentUser failed, err=%ld";
                           TRACELogPrint(0x10002,"RegOpenCurrentUser failed, err=%ld",
                                         (ulonglong)uVar2,pwVar10);
                         }
                       }
                       LeaveCriticalSection((LPCRITICAL_SECTION)&gPriorityListCritSec);
                       RpcRevertToSelf();
                     }
                     goto LAB_13;
                   }
-                  pcVar20 = "RpcImpersonateClient failed, err=%d";
+                  pcVar18 = "RpcImpersonateClient failed, err=%d";
                 }
               }
               else {
-                pcVar20 = "ClientAttach: Failed to retrieve the RPC call attributes, error 0x%x";
+                pcVar18 = "ClientAttach: Failed to retrieve the RPC call attributes, error 0x%x";
               }
 LAB_31:
-              TRACELogPrint(0x10002,pcVar20,(ulonglong)uVar2,pwVar10);
+              TRACELogPrint(0x10002,pcVar18,(ulonglong)uVar2,pwVar10);
               goto LAB_16;
             }
-            DVar4 = GetLastError();
-            TRACELogPrint(0x10002,"ClientAttach: OpenThreadToken failed, err=%u",(ulonglong)DVar4,
-                          TokenHandle);
 LAB_4:
+            CloseHandle(local_5d0);
             RpcRevertToSelf();
+            iVar5 = 0;
+LAB_9:
+            pvVar17 = *(LPVOID *)(pHVar11 + 0x24);
+            ServerFree(pvVar17);
           }
-          else {
-            TRACELogPrint(0x10002,"ClientAttach: RpcImpersonateClient failed, err=%d",
-                          (ulonglong)uVar2,param_4);
-          }
+          DereferenceObject(pvVar17,pHVar11[0x3e].unused,1);
         }
-        else {
-          TRACELogPrint(0x10002,"A client tried to attach, but TAPISRV is PAUSED",uVar9,param_4);
-        }
-        pvVar19 = *(LPVOID *)(puVar11 + 0x24);
-        ServerFree(pvVar19);
-        DereferenceObject(pvVar19,puVar11[0x3e],1);
-        return -0x7fffffb8;
       }
       goto LAB_34;
     }
-    pcVar20 = "ClientAttach: tapimgmt attach request received, but this is not a svr sku!";
+    pcVar18 = "ClientAttach: tapimgmt attach request received, but this is not a svr sku!";
   }
   iVar5 = -0x7fffffb8;
-  TRACELogPrint(0x10002,pcVar20,uVar22,param_4);
-  goto LAB_1;
-LAB_2:
-  CloseHandle(local_5d8);
-  RpcRevertToSelf();
-  iVar5 = 0;
-LAB_9:
-  pvVar19 = *(LPVOID *)(puVar11 + 0x24);
-  ServerFree(pvVar19);
+  TRACELogPrint(0x10002,pcVar18,uVar22,param_4);
 LAB_34:
-  DereferenceObject(pvVar19,puVar11[0x3e],1);
-LAB_1:
   if (iVar5 == 0) {
     iVar5 = -0x7fffffbc;
   }
   return iVar5;
 }
 

```


## wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|code,length,address|
|ratio|0.55|
|i_ratio|0.11|
|m_ratio|0.78|
|b_ratio|0.78|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|
|fullname|wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''|
|refcount|2|2|
|`length`|43|71|
|called|||
|calling|||
|paramcount|0|0|
|`address`|1800010b0|1800010d0|
|sig|undefined __fastcall `dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''(void)|undefined __fastcall `dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi'' Diff


```diff
--- wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''
+++ wil::details::`dynamic_initializer_for_'g_header_init_InitializeStagingHeaderInternalApi''
@@ -1,15 +1,17 @@
-
-/* WARNING: Globals starting with '_' overlap smaller symbols at the same address */
 
 void wil::details::_dynamic_initializer_for__g_header_init_InitializeStagingHeaderInternalApi__
                (void)
 
 {
-  _g_wil_details_internalRecordFeatureUsage = WilApiImpl_RecordFeatureUsage;
-  _g_wil_details_internalSubscribeFeatureStateChangeNotification =
+  g_wil_details_ensureSubscribedToFeatureConfigurationChanges =
+       EnsureSubscribedToFeatureConfigurationChanges;
+  g_wil_details_subscribeFeatureStateCacheToConfigurationChanges =
+       SubscribeFeatureStateCacheToConfigurationChanges;
+  g_wil_details_internalRecordFeatureUsage = WilApiImpl_RecordFeatureUsage;
+  g_wil_details_internalSubscribeFeatureStateChangeNotification =
        WilApiImpl_SubscribeFeatureStateChangeNotification;
-  _g_wil_details_internalUnsubscribeFeatureStateChangeNotification =
+  g_wil_details_internalUnsubscribeFeatureStateChangeNotification =
        WilApiImpl_UnsubscribeFeatureStateChangeNotification;
   return;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## __GSHandlerCheck

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|__GSHandlerCheck|__GSHandlerCheck|
|fullname|__GSHandlerCheck|__GSHandlerCheck|
|`refcount`|66|69|
|length|29|29|
|called|__GSHandlerCheckCommon|__GSHandlerCheckCommon|
|calling|||
|paramcount|4|4|
|`address`|180042604|1800435d4|
|sig|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|undefined8 __fastcall __GSHandlerCheck(undefined8 param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## KERNEL32.DLL::HeapAlloc

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|HeapAlloc|HeapAlloc|
|fullname|KERNEL32.DLL::HeapAlloc|KERNEL32.DLL::HeapAlloc|
|`refcount`|201|202|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>AddLine<br>AddPhone<br>AddProviderToIdArrayList<br>AddSIDToKernelObjectDacl<br>AppendNewDeviceInfo<br>BuildCountryList<br>BuildCountryListCache<br>BuildDeviceInfoList<br>ChangeDeviceUserAssociation<br>ClientAttach<br>CreateHandleTable</summary>CreateProxyRequest<br>CreateSCP<br>CreatetCall<br>CreatetCallAndClient<br>CreatetCallClient<br>DeleteAllSubkeys<br>DoCallHubHashing<br>EventNotificationThread<br>FreeDialogInstance<br>GetCallClientListFromCall<br>GetCallListFromLine<br>GetClientList<br>GetConfCallListFromConf<br>GetDeviceAccess<br>GetDomainAndUserNames<br>GetLineAppListFromClient<br>GetLineClientListFromLine<br>GetList<br>GetLocalSystemToken<br>GetMediaModesPriorityLists<br>GetNewClientHandle<br>GetPermLineIDAndInsertInTable<br>GetPermPhoneIDAndInsertInTable<br>GetPhoneAppListFromClient<br>GetPhoneClientListFromPhone<br>GetPriorityList<br>GetPriorityListForMediaModes<br>GetProviderFriendlyName<br>GetTokenUser<br>GetUIDllName<br>GrowTable<br>InitSecurityDescriptor<br>InitializeClient<br>InsertDevNameAddrInfo<br>InsertInfoListString<br>InsertIntoTable<br>LAccept<br>LAnswer<br>LCompleteTransfer<br>LCreateAgent<br>LCreateAgentSession<br>LForward<br>LGatherDigits<br>LGenerateDigits<br>LGenerateTone<br>LGetAddressCaps<br>LGetCallInfo<br>LGetCallStatus<br>LGetCountry<br>LGetCountryGroups<br>LGetDevCaps<br>LGetDevConfig<br>LGetID<br>LGetIDEx<br>LGetLineDevStatus<br>LGetProviderList<br>LInitialize<br>LReceiveMSPData<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetNumRings<br>LSetupConference<br>LineEventProc<br>LineEventProcSP<br>LineProlog<br>MGetAvailableProviders<br>MGetServerConfig<br>MyGetPrivateProfileString<br>NewToOldLineforwardlist<br>OldToNewLineforwardlist<br>OnProxyLineOpen<br>PGetButtonInfo<br>PGetDevCaps<br>PGetID<br>PGetIDEx<br>PGetStatus<br>PInitialize<br>POpen<br>PhoneEventProc<br>PhoneEventProcSP<br>PhoneProlog<br>ReadAndInitManagementDlls<br>ReadAndInitMapper<br>SendBufferMsgToCallClients<br>SendBufferMsgToLineClients<br>SendNewCallHubEvent<br>ServerInit<br>ServiceMain<br>SetCallConfList<br>SetDeviceInfo<br>SetSidOnAcl<br>SetTokenDefaultDacl<br>TRequestMakeCall<br>ValidateButtonInfo<br>ValidateCallParams<br>VerifyDomainName<br>WaveDeviceIdToStringId<br>WriteEventBuffer<br>WriteServiceConfig<br>wil::details::ProcessHeapAlloc<br>xxxLOpen</details>|<details><summary>Expand for full list:<br>AddLine<br>AddPhone<br>AddProviderToIdArrayList<br>AddSIDToKernelObjectDacl<br>AppendNewDeviceInfo<br>BuildCountryList<br>BuildCountryListCache<br>BuildDeviceInfoList<br>ChangeDeviceUserAssociation<br>ClientAttach<br>CreateHandleTable</summary>CreateProxyRequest<br>CreateSCP<br>CreatetCall<br>CreatetCallAndClient<br>CreatetCallClient<br>DeleteAllSubkeys<br>DoCallHubHashing<br>EventNotificationThread<br>FreeDialogInstance<br>GetCallClientListFromCall<br>GetCallListFromLine<br>GetClientList<br>GetConfCallListFromConf<br>GetDeviceAccess<br>GetDomainAndUserNames<br>GetLineAppListFromClient<br>GetLineClientListFromLine<br>GetList<br>GetLocalSystemToken<br>GetMediaModesPriorityLists<br>GetNewClientHandle<br>GetPermLineIDAndInsertInTable<br>GetPermPhoneIDAndInsertInTable<br>GetPhoneAppListFromClient<br>GetPhoneClientListFromPhone<br>GetPriorityList<br>GetPriorityListForMediaModes<br>GetProviderFriendlyName<br>GetTokenUser<br>GetUIDllName<br>GrowTable<br>InitSecurityDescriptor<br>InitializeClient<br>InsertDevNameAddrInfo<br>InsertInfoListString<br>InsertIntoTable<br>LAccept<br>LAnswer<br>LCompleteTransfer<br>LCreateAgent<br>LCreateAgentSession<br>LForward<br>LGatherDigits<br>LGenerateDigits<br>LGenerateTone<br>LGetAddressCaps<br>LGetCallInfo<br>LGetCallStatus<br>LGetCountry<br>LGetCountryGroups<br>LGetDevCaps<br>LGetDevConfig<br>LGetID<br>LGetIDEx<br>LGetLineDevStatus<br>LGetProviderList<br>LInitialize<br>LReceiveMSPData<br>LRegisterRequestRecipient<br>LSetAppPriority<br>LSetNumRings<br>LSetupConference<br>LineEventProc<br>LineEventProcSP<br>LineProlog<br>MGetAvailableProviders<br>MGetServerConfig<br>MyGetPrivateProfileString<br>NewToOldLineforwardlist<br>OldToNewLineforwardlist<br>OnProxyLineOpen<br>PGetButtonInfo<br>PGetDevCaps<br>PGetID<br>PGetIDEx<br>PGetStatus<br>PInitialize<br>POpen<br>PhoneEventProc<br>PhoneEventProcSP<br>PhoneProlog<br>ReadAndInitManagementDlls<br>ReadAndInitMapper<br>SendBufferMsgToCallClients<br>SendBufferMsgToLineClients<br>SendNewCallHubEvent<br>ServerInit<br>ServiceMain<br>SetCallConfList<br>SetDeviceInfo<br>SetSidOnAcl<br>SetTokenDefaultDacl<br>TRequestMakeCall<br>ValidateButtonInfo<br>ValidateCallParams<br>VerifyDomainName<br>WaveDeviceIdToStringId<br>WriteEventBuffer<br>WriteServiceConfig<br>wil::details::ProcessHeapAlloc<br>xxxLOpen</details>|
|paramcount|3|3|
|`address`|EXTERNAL:00000085|EXTERNAL:00000084|
|sig|LPVOID __stdcall HeapAlloc(HANDLE hHeap, DWORD dwFlags, SIZE_T dwBytes)|LPVOID __stdcall HeapAlloc(HANDLE hHeap, DWORD dwFlags, SIZE_T dwBytes)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## atexit

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.88|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|atexit|atexit|
|fullname|atexit|atexit|
|`refcount`|4|5|
|length|23|23|
|called|_onexit|_onexit|
|`calling`|wil::details::`dynamic_atexit_destructor_for_'g_threadFailureCallbacks''<br>wil::details::`dynamic_initializer_for_'g_featureStateManager''<br>wil::details::`dynamic_initializer_for_'g_processLocalData''|wil::details::`dynamic_atexit_destructor_for_'g_threadFailureCallbacks''<br>wil::details::`dynamic_initializer_for_'g_enabledStateManager''<br>wil::details::`dynamic_initializer_for_'g_featureStateManager''<br>wil::details::`dynamic_initializer_for_'g_processLocalData''|
|paramcount|1|1|
|`address`|180001cc8|180001cf8|
|sig|int __cdecl atexit(_func_5014 * param_1)|int __cdecl atexit(_func_5014 * param_1)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### atexit Calling Diff


```diff
--- atexit calling
+++ atexit calling
@@ -1,0 +2 @@
+wil::details::`dynamic_initializer_for_'g_enabledStateManager''
```


## ~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.71|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>|~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>|
|fullname|wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>|wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>|
|`refcount`|3|4|
|length|22|22|
|called|wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy|wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy|
|`calling`|wil::details::FeatureStateManager::~FeatureStateManager|wil::details::EnabledStateManager::~EnabledStateManager<br>wil::details::FeatureStateManager::~FeatureStateManager|
|paramcount|1|1|
|`address`|180038860|1800393a8|
|sig|void __thiscall ~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>(unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_> * this)|void __thiscall ~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>(unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_> Calling Diff


```diff
--- wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_> calling
+++ wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_> calling
@@ -0,0 +1 @@
+wil::details::EnabledStateManager::~EnabledStateManager
```


## ProcessShutdownInProgress

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.62|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|ProcessShutdownInProgress|ProcessShutdownInProgress|
|fullname|wil::ProcessShutdownInProgress|wil::ProcessShutdownInProgress|
|`refcount`|8|9|
|length|47|47|
|called|_guard_dispatch_icall$thunk$10345483385596137414|_guard_dispatch_icall$thunk$10345483385596137414|
|`calling`|wil::details::FeatureStateManager::FlushUsage<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::`dynamic_atexit_destructor_for_'g_featureStateManager''<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release|wil::details::FeatureStateManager::FlushUsage<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''<br>wil::details::`dynamic_atexit_destructor_for_'g_featureStateManager''<br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Release<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Release|
|paramcount|0|0|
|`address`|18003c3a4|18003d110|
|sig|bool __cdecl ProcessShutdownInProgress(void)|bool __cdecl ProcessShutdownInProgress(void)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ProcessShutdownInProgress Calling Diff


```diff
--- wil::ProcessShutdownInProgress calling
+++ wil::ProcessShutdownInProgress calling
@@ -4,0 +5 @@
+wil::details::`dynamic_atexit_destructor_for_'g_enabledStateManager''
```


## push_back

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.89|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|push_back|push_back|
|fullname|wil::details_abi::heap_buffer::push_back|wil::details_abi::heap_buffer::push_back|
|`refcount`|3|4|
|length|90|90|
|called|memcpy_s<br>wil::details_abi::heap_buffer::ensure|memcpy_s<br>wil::details_abi::heap_buffer::ensure|
|`calling`|wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details_abi::SubscriptionList::SubscribeUnderLock|wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details_abi::SubscriptionList::SubscribeUnderLock|
|paramcount|3|3|
|`address`|18003ed8c|18003fc6c|
|sig|bool __thiscall push_back(heap_buffer * this, void * param_1, __uint64 param_2)|bool __thiscall push_back(heap_buffer * this, void * param_1, __uint64 param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### push_back Calling Diff


```diff
--- wil::details_abi::heap_buffer::push_back calling
+++ wil::details_abi::heap_buffer::push_back calling
@@ -0,0 +1 @@
+wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges
```


## KERNEL32.DLL::AcquireSRWLockExclusive

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|AcquireSRWLockExclusive|AcquireSRWLockExclusive|
|fullname|KERNEL32.DLL::AcquireSRWLockExclusive|KERNEL32.DLL::AcquireSRWLockExclusive|
|`refcount`|13|16|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::EnsureSubscribedToProcessWideUsageFlushUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled</summary>wil::details_abi::SubscriptionList::Unsubscribe</details>|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl<br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::EnsureSubscribedToProcessWideUsageFlushUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush</summary>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|
|paramcount|1|1|
|`address`|EXTERNAL:00000062|EXTERNAL:0000005f|
|sig|void __stdcall AcquireSRWLockExclusive(PSRWLOCK SRWLock)|void __stdcall AcquireSRWLockExclusive(PSRWLOCK SRWLock)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### KERNEL32.DLL::AcquireSRWLockExclusive Calling Diff


```diff
--- KERNEL32.DLL::AcquireSRWLockExclusive calling
+++ KERNEL32.DLL::AcquireSRWLockExclusive calling
@@ -2,0 +3,3 @@
+wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl
+wil::details::EnabledStateManager::OnStateChange
+wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges
```


## KERNEL32.DLL::GetModuleHandleW

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|GetModuleHandleW|GetModuleHandleW|
|fullname|KERNEL32.DLL::GetModuleHandleW|KERNEL32.DLL::GetModuleHandleW|
|`refcount`|5|6|
|length|0|0|
|called|||
|`calling`|wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetNtDllModuleHandle|wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress<br>wil_details_GetNtDllModuleHandle<br>wil_details_GetNtDllProcedureAddress|
|paramcount|1|1|
|`address`|EXTERNAL:00000057|EXTERNAL:0000007c|
|sig|HMODULE __stdcall GetModuleHandleW(LPCWSTR lpModuleName)|HMODULE __stdcall GetModuleHandleW(LPCWSTR lpModuleName)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### KERNEL32.DLL::GetModuleHandleW Calling Diff


```diff
--- KERNEL32.DLL::GetModuleHandleW calling
+++ KERNEL32.DLL::GetModuleHandleW calling
@@ -4,0 +5 @@
+wil_details_GetNtDllProcedureAddress
```


## KERNEL32.DLL::GetLastError

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|GetLastError|GetLastError|
|fullname|KERNEL32.DLL::GetLastError|KERNEL32.DLL::GetLastError|
|`refcount`|89|90|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>AddLine<br>AddPhone<br>AddSIDToKernelObjectDacl<br>AllowAccessToScpProperties<br>BuildDeviceInfoList<br>ClientAttach<br>CreateSCP<br>EventNotificationThread<br>GetDomainAndUserNames<br>GetLocalSystemToken<br>GetProviderFriendlyName</summary>GetTokenUser<br>GetUIDllName<br>ImpersonateLocalSystem<br>InitSecurityDescriptor<br>IsCurrentLocalSystem<br>IsLocalSystem<br>IsLocalSystemOnly<br>LoadCountryNameString<br>LoadNewDll<br>MGetAvailableProviders<br>MSetServerConfig<br>ReadAndInitMapper<br>RemoveSCP<br>RevertLocalSystemImp<br>ServerInit<br>ServiceMain<br>SetCurrentPrivilege<br>SetPrivilege<br>SetSidOnAcl<br>SetTokenDefaultDacl<br>StoreADialingRuleInReg<br>TReadLocations<br>TWriteLocations<br>UpdateLastWriteTime<br>UpdateSCP<br>VerifyDomainName<br>WriteEventBuffer<br>WriteServiceConfig<br>wil::details::GetLastErrorFail<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore<br>wil::details_abi::SemaphoreValue::TryGetValueInternal<br>wil::last_error_context::last_error_context<br>wil::semaphore_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>::create</details>|<details><summary>Expand for full list:<br>AddLine<br>AddPhone<br>AddSIDToKernelObjectDacl<br>AllowAccessToScpProperties<br>BuildDeviceInfoList<br>ClientAttach<br>CreateSCP<br>EventNotificationThread<br>GetDomainAndUserNames<br>GetLocalSystemToken<br>GetProviderFriendlyName</summary>GetTokenUser<br>GetUIDllName<br>ImpersonateLocalSystem<br>InitSecurityDescriptor<br>IsCurrentLocalSystem<br>IsLocalSystem<br>IsLocalSystemOnly<br>LoadCountryNameString<br>LoadNewDll<br>MGetAvailableProviders<br>MSetServerConfig<br>ReadAndInitMapper<br>RemoveSCP<br>RevertLocalSystemImp<br>ServerInit<br>ServiceMain<br>SetCurrentPrivilege<br>SetPrivilege<br>SetSidOnAcl<br>SetTokenDefaultDacl<br>StoreADialingRuleInReg<br>TReadLocations<br>TWriteLocations<br>UpdateLastWriteTime<br>UpdateSCP<br>VerifyDomainName<br>WriteEventBuffer<br>WriteServiceConfig<br>wil::details::GetLastErrorFail<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore<br>wil::details_abi::SemaphoreValue::TryGetValueInternal<br>wil::last_error_context::last_error_context<br>wil::semaphore_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>::create</details>|
|paramcount|0|0|
|`address`|EXTERNAL:000000a3|EXTERNAL:000000a4|
|sig|DWORD __stdcall GetLastError(void)|DWORD __stdcall GetLastError(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## __security_check_cookie

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|__security_check_cookie|__security_check_cookie|
|fullname|__security_check_cookie|__security_check_cookie|
|`refcount`|88|91|
|length|30|30|
|called|__report_gsfailure|__report_gsfailure|
|`calling`|<details><summary>Expand for full list:<br>AllowAccessToScpProperties<br>BuildCountryList<br>BuildCountryListCache<br>BuildCountryRegistryListFromRCW<br>BuildDeviceInfoList<br>ChangeDeviceUserAssociation<br>CleanUpClient<br>ClientAttach<br>CompletionProc<br>ConvertLocations<br>ConvertOneLocation</summary>ConvertUserLocations<br>CreateAreaCodeRule<br>CreateCallMonitors<br>CreateProxySCP<br>CreateSCP<br>CreateTapiSCP<br>DestroytCall<br>DestroytLine<br>DestroytLineApp<br>DestroytLineClient<br>DestroytPhone<br>EnablePrivilege<br>EnsureTsecIni<br>FreeDialogInstance<br>GetCallIDs<br>GetLocalSystemToken<br>GetProviderFriendlyName<br>GetUIDllName<br>InitSecurityDescriptor<br>InsertDevNameAddrInfo<br>IsLocalSystem<br>IsLocalSystemOnly<br>IsNTServer<br>LGetAppPriority<br>LGetCountry<br>LGetProviderList<br>LHandoff<br>LProxyMessage<br>LSetAppPriority<br>LSetCallHubTracking<br>LSetupConference_PostProcess<br>LineEventProc<br>MGetAvailableProviders<br>ManagementAddLineProc<br>NotifyHighestPriorityRequestRecipient<br>PhoneEventProc<br>RegDeleteKeyNT<br>RemoveProxySCP<br>RemoveSCP<br>ReportStatusToSCMgr<br>SendAMsgToAllLineApps<br>SendAMsgToAllPhoneApps<br>SendMsgToCallClients<br>SendMsgToLineClients<br>SendMsgToPhoneClients<br>ServerInit<br>ServerShutdown<br>ServiceMain<br>SetDeviceInfo<br>SetMediaModesPriorityList<br>SetPrivilege<br>SetSidOnAcl<br>SetTokenDefaultDacl<br>StoreADialingRuleInReg<br>TRACELogPrint<br>TRACELogRegister<br>TReadLocations<br>TWriteLocations<br>UpdateLastWriteTime<br>UpdateSCP<br>UpdateTapiSCP<br>ValidateButtonInfo<br>ValidateCallParams<br>__GSHandlerCheckCommon<br>wil::GetFailureLogString<br>wil::details::GetModuleInformation<br>wil::details::ReportFailure_Return<1><br>wil::details::ReportFailure_Return<2><br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::SemaphoreValue::CreateFromValueInternal<br>wil::details_abi::SemaphoreValue::TryGetValueInternal<br>wil::details_abi::UsageIndexes::Record<br>wil_details_WriteSRUMWnfUsageBuffer<br>xxxLOpen</details>|<details><summary>Expand for full list:<br>AllowAccessToScpProperties<br>BuildCountryList<br>BuildCountryListCache<br>BuildCountryRegistryListFromRCW<br>BuildDeviceInfoList<br>ChangeDeviceUserAssociation<br>CleanUpClient<br>ClientAttach<br>CompletionProc<br>ConvertLocations<br>ConvertOneLocation</summary>ConvertUserLocations<br>CreateAreaCodeRule<br>CreateCallMonitors<br>CreateProxySCP<br>CreateSCP<br>CreateTapiSCP<br>DestroytCall<br>DestroytLine<br>DestroytLineApp<br>DestroytLineClient<br>DestroytPhone<br>EnablePrivilege<br>EnsureTsecIni<br>FreeDialogInstance<br>GetCallIDs<br>GetLocalSystemToken<br>GetProviderFriendlyName<br>GetUIDllName<br>InitSecurityDescriptor<br>InsertDevNameAddrInfo<br>IsLocalSystem<br>IsLocalSystemOnly<br>IsNTServer<br>LGetAppPriority<br>LGetCountry<br>LGetProviderList<br>LHandoff<br>LProxyMessage<br>LSetAppPriority<br>LSetCallHubTracking<br>LSetupConference_PostProcess<br>LineEventProc<br>MGetAvailableProviders<br>ManagementAddLineProc<br>NotifyHighestPriorityRequestRecipient<br>PhoneEventProc<br>RegDeleteKeyNT<br>RemoveProxySCP<br>RemoveSCP<br>ReportStatusToSCMgr<br>SendAMsgToAllLineApps<br>SendAMsgToAllPhoneApps<br>SendMsgToCallClients<br>SendMsgToLineClients<br>SendMsgToPhoneClients<br>ServerInit<br>ServerShutdown<br>ServiceMain<br>SetDeviceInfo<br>SetMediaModesPriorityList<br>SetPrivilege<br>SetSidOnAcl<br>SetTokenDefaultDacl<br>StoreADialingRuleInReg<br>TRACELogPrint<br>TRACELogRegister<br>TReadLocations<br>TWriteLocations<br>UpdateLastWriteTime<br>UpdateSCP<br>UpdateTapiSCP<br>ValidateButtonInfo<br>ValidateCallParams<br>__GSHandlerCheckCommon<br>wil::GetFailureLogString<br>wil::details::GetModuleInformation<br>wil::details::ReportFailure_Return<1><br>wil::details::ReportFailure_Return<2><br>wil::details_abi::ProcessLocalStorageData<class_wil::details_abi::FeatureStateData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::RecordWnfUsageIndex<br>wil::details_abi::SemaphoreValue::CreateFromValueInternal<br>wil::details_abi::SemaphoreValue::TryGetValueInternal<br>wil::details_abi::UsageIndexes::Record<br>wil_RtlStagingConfig_QueryFeatureState<br>wil_details_FeatureReporting_ReportUsageToServiceDirect<br>wil_details_RecordCachedUsage<br>wil_details_WriteSRUMWnfUsageBuffer<br>xxxLOpen</details>|
|paramcount|1|1|
|`address`|180001610|180001640|
|sig|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### __security_check_cookie Calling Diff


```diff
--- __security_check_cookie calling
+++ __security_check_cookie calling
@@ -85,0 +86,3 @@
+wil_RtlStagingConfig_QueryFeatureState
+wil_details_FeatureReporting_ReportUsageToServiceDirect
+wil_details_RecordCachedUsage
```


## reset

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.81|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|reset|reset|
|fullname|wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::reset|wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::reset|
|`refcount`|5|6|
|length|76|76|
|called|wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::last_error_context::last_error_context<br>wil::last_error_context::~last_error_context|wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy<br>wil::last_error_context::last_error_context<br>wil::last_error_context::~last_error_context|
|`calling`|wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::~FeatureStateManager|wil::details::EnabledStateManager::~EnabledStateManager<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::~FeatureStateManager|
|paramcount|2|2|
|`address`|18003eeb0|18003fd90|
|sig|void __thiscall reset(unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_> * this, _TP_TIMER * param_1)|void __thiscall reset(unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_> * this, _TP_TIMER * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### reset Calling Diff


```diff
--- wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::reset calling
+++ wil::details::unique_storage<struct_wil::details::resource_policy<struct__TP_TIMER*___ptr64,void_(__cdecl*)(struct__TP_TIMER*___ptr64),&public:_static_void___cdecl_wil::details::DestroyThreadPoolTimer<struct_wil::details::SystemThreadPoolMethods,0>::Destroy(struct__TP_TIMER*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,struct__TP_TIMER*___ptr64,struct__TP_TIMER*___ptr64,0,std::nullptr_t>_>::reset calling
@@ -0,0 +1 @@
+wil::details::EnabledStateManager::~EnabledStateManager
```


## ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.75|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|
|fullname|wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>|
|`refcount`|13|16|
|length|29|29|
|called|KERNEL32.DLL::ReleaseSRWLockExclusive|KERNEL32.DLL::ReleaseSRWLockExclusive|
|`calling`|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::EnsureSubscribedToProcessWideUsageFlushUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush<br>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled</summary>wil::details_abi::SubscriptionList::Unsubscribe</details>|<details><summary>Expand for full list:<br><lambda_5035b992506f4af81a770c5842624510>::<lambda_invoker_cdecl><br><lambda_d51448ba32f8ef42e59400edd4566183>::<lambda_invoker_cdecl><br>wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl<br>wil::details::EnabledStateManager::OnStateChange<br>wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges<br>wil::details::FeatureStateManager::EnsureStateData<br>wil::details::FeatureStateManager::EnsureSubscribedToProcessWideUsageFlushUnderLock<br>wil::details::FeatureStateManager::QueueBackgroundSRUMUsageReporting<br>wil::details::FeatureStateManager::RecordFeatureUsage<br>wil::details::FeatureStateManager::SubscribeToEnabledStateChanges<br>wil::details::FeatureStateManager::SubscribeToUsageFlush</summary>wil::details_abi::FeatureStateData::RecordFeatureUsage<br>wil::details_abi::FeatureStateData::RecordUsage<br>wil::details_abi::SubscriptionList::OnSignaled<br>wil::details_abi::SubscriptionList::Unsubscribe</details>|
|paramcount|1|1|
|`address`|180038818|180039360|
|sig|void __thiscall ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>(unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> * this)|void __thiscall ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>(unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> Calling Diff


```diff
--- wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> calling
+++ wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> calling
@@ -2,0 +3,3 @@
+wil::details::EnabledStateManager::EnsureSubscribedToFeatureConfigurationChangesImpl
+wil::details::EnabledStateManager::OnStateChange
+wil::details::EnabledStateManager::SubscribeFeatureStateCacheToConfigurationChanges
```


## KERNEL32.DLL::CreateFileW

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|CreateFileW|CreateFileW|
|fullname|KERNEL32.DLL::CreateFileW|KERNEL32.DLL::CreateFileW|
|`refcount`|4|5|
|length|0|0|
|called|||
|calling|BuildDeviceInfoList<br>ClientAttach<br>EnsureTsecIni|BuildDeviceInfoList<br>ClientAttach<br>EnsureTsecIni|
|paramcount|7|7|
|`address`|EXTERNAL:00000091|EXTERNAL:00000092|
|sig|HANDLE __stdcall CreateFileW(LPCWSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile)|HANDLE __stdcall CreateFileW(LPCWSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## KERNEL32.DLL::CloseHandle

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|CloseHandle|CloseHandle|
|fullname|KERNEL32.DLL::CloseHandle|KERNEL32.DLL::CloseHandle|
|`refcount`|51|52|
|length|0|0|
|called|||
|calling|<details><summary>Expand for full list:<br>AddLine<br>BuildDeviceInfoList<br>CleanUpClient<br>ClientAttach<br>EnablePrivilege<br>EnsureTsecIni<br>EventNotificationThread<br>FreeDialogInstance<br>GetDomainAndUserNames<br>GetLocalSystemToken<br>ImpersonateLocalSystem</summary>IsCurrentLocalSystem<br>LineEventProc<br>MSetServerConfig<br>ManagementProc<br>MyCloseMutex<br>POpen<br>PhoneEventProc<br>ReadAndInitManagementDlls<br>ServerInit<br>ServerShutdown<br>ServiceMain<br>ServiceShutdown<br>SetCurrentPrivilege<br>TReadLocations<br>TWriteLocations<br>wil::details::CloseHandle<br>xxxLOpen</details>|<details><summary>Expand for full list:<br>AddLine<br>BuildDeviceInfoList<br>CleanUpClient<br>ClientAttach<br>EnablePrivilege<br>EnsureTsecIni<br>EventNotificationThread<br>FreeDialogInstance<br>GetDomainAndUserNames<br>GetLocalSystemToken<br>ImpersonateLocalSystem</summary>IsCurrentLocalSystem<br>LineEventProc<br>MSetServerConfig<br>ManagementProc<br>MyCloseMutex<br>POpen<br>PhoneEventProc<br>ReadAndInitManagementDlls<br>ServerInit<br>ServerShutdown<br>ServiceMain<br>ServiceShutdown<br>SetCurrentPrivilege<br>TReadLocations<br>TWriteLocations<br>wil::details::CloseHandle<br>xxxLOpen</details>|
|paramcount|1|1|
|`address`|EXTERNAL:000000a1|EXTERNAL:000000a2|
|sig|BOOL __stdcall CloseHandle(HANDLE hObject)|BOOL __stdcall CloseHandle(HANDLE hObject)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## KERNEL32.DLL::GetProcAddress

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|GetProcAddress|GetProcAddress|
|fullname|KERNEL32.DLL::GetProcAddress|KERNEL32.DLL::GetProcAddress|
|`refcount`|23|24|
|length|0|0|
|called|||
|calling|GetProviderFriendlyName<br>GetUIDllName<br>LoadNewDll<br>MGetAvailableProviders<br>ReadAndInitMapper<br>ServerInit<br>wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress|GetProviderFriendlyName<br>GetUIDllName<br>LoadNewDll<br>MGetAvailableProviders<br>ReadAndInitMapper<br>ServerInit<br>wil::details::ProcessHeapAlloc<br>wil::details::WilDynamicLoadRaiseFailFastException<br>wil_details_GetKernelBaseProcAddress|
|paramcount|2|2|
|`address`|EXTERNAL:00000082|EXTERNAL:00000081|
|sig|FARPROC __stdcall GetProcAddress(HMODULE hModule, LPCSTR lpProcName)|FARPROC __stdcall GetProcAddress(HMODULE hModule, LPCSTR lpProcName)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

## wil_details_GetNtDllProcedureAddress

### Match Info



|Key|ts_7309.dll - ts_7623.dll|
| :---: | :---: |
|diff_type|refcount,length,sig,address,calling,called|
|ratio|0.36|
|i_ratio|0.5|
|m_ratio|0.75|
|b_ratio|0.42|
|match_types|Implied Match|

### Function Meta Diff



|Key|ts_7309.dll|ts_7623.dll|
| :---: | :---: | :---: |
|name|wil_details_GetNtDllProcedureAddress|wil_details_GetNtDllProcedureAddress|
|fullname|wil_details_GetNtDllProcedureAddress|wil_details_GetNtDllProcedureAddress|
|`refcount`|8|3|
|`length`|32|65|
|`called`|wil_details_GetNtDllModuleHandle|KERNEL32.DLL::GetModuleHandleW|
|`calling`|wil::details::RtlDllShutdownInProgress<br>wil::details::RtlNtStatusToDosErrorNoTeb<br>wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_><br>wil_RtlStagingConfig_RecordFeatureUsage<br>wil_details_NtQueryWnfStateData<br>wil_details_NtUpdateWnfStateData<br>wil_details_RtlRegisterFeatureConfigurationChangeNotification|wil_RtlStagingConfig_QueryFeatureState<br>wil_RtlStagingConfig_RecordFeatureUsage|
|paramcount|1|1|
|`address`|18003f048|1800323f8|
|`sig`|_func___int64 * __cdecl wil_details_GetNtDllProcedureAddress(char * param_1)|undefined __fastcall wil_details_GetNtDllProcedureAddress(LPCSTR param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|IMPORTED|
|external|False|False|

### wil_details_GetNtDllProcedureAddress Called Diff


```diff
--- wil_details_GetNtDllProcedureAddress called
+++ wil_details_GetNtDllProcedureAddress called
@@ -1 +1 @@
-wil_details_GetNtDllModuleHandle
+KERNEL32.DLL::GetModuleHandleW
```


### wil_details_GetNtDllProcedureAddress Calling Diff


```diff
--- wil_details_GetNtDllProcedureAddress calling
+++ wil_details_GetNtDllProcedureAddress calling
@@ -1,3 +1 @@
-wil::details::RtlDllShutdownInProgress
-wil::details::RtlNtStatusToDosErrorNoTeb
-wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::UnregisterWilFeatureConfigurationChange(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>
+wil_RtlStagingConfig_QueryFeatureState
@@ -5,3 +2,0 @@
-wil_details_NtQueryWnfStateData
-wil_details_NtUpdateWnfStateData
-wil_details_RtlRegisterFeatureConfigurationChangeNotification
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-08-18T21:41:12</sub>