# waasmedicsvc-2019-12.dll-waasmedicsvc-2020-01.dll Diff

# TOC

* [Visual Chart Diff](#visual-chart-diff)
* [Metadata](#metadata)
	* [Ghidra Diff Engine](#ghidra-diff-engine)
		* [Command Line](#command-line)
	* [Binary Metadata Diff](#binary-metadata-diff)
	* [Program Options](#program-options)
	* [Diff Stats](#diff-stats)
	* [Strings](#strings)
* [Deleted](#deleted)
	* [API-MS-WIN-CORE-COM-L1-1-0.DLL::StringFromCLSID](#api-ms-win-core-com-l1-1-0dllstringfromclsid)
* [Added](#added)
	* [WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS](#waasmedicmiscutilhresult_from_ntstatus)
	* [WaasMedic::GetRandomString](#waasmedicgetrandomstring)
	* [WaasMedic::ValidateOriginalFileName](#waasmedicvalidateoriginalfilename)
	* [WaasMedic::GetSha256HashOfString](#waasmedicgetsha256hashofstring)
	* [std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of](#stdbasic_stringunsigned_shortstdchar_traitsunsigned_shortstdallocatorunsigned_short_find_last_of)
	* [std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=](#stdbasic_stringunsigned_shortstdchar_traitsunsigned_shortstdallocatorunsigned_short_operator)
	* [swprintf_s](#swprintf_s)
	* [`WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor$0](#waasmediccsandboxrpcwrapperinit__l1dtor0)
	* [`WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor$0](#waasmediccsandboxrpcwrappercreatesandbox__l1dtor0)
	* [`WaasMedic::GetRandomString'::__l1::dtor$0](#waasmedicgetrandomstring__l1dtor0)
	* [`WaasMedic::ValidateOriginalFileName'::__l1::dtor$1](#waasmedicvalidateoriginalfilename__l1dtor1)
	* [`WaasMedic::GetSha256HashOfString'::__l1::dtor$0](#waasmedicgetsha256hashofstring__l1dtor0)
	* [API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o_tolower](#api-ms-win-crt-private-l1-1-0dll_o_tolower)
	* [API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o___stdio_common_vswprintf_s](#api-ms-win-crt-private-l1-1-0dll_o___stdio_common_vswprintf_s)
	* [BCRYPT.DLL::BCryptCreateHash](#bcryptdllbcryptcreatehash)
	* [API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoExW](#api-ms-win-core-version-l1-1-0dllgetfileversioninfoexw)
	* [API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoSizeExW](#api-ms-win-core-version-l1-1-0dllgetfileversioninfosizeexw)
	* [BCRYPT.DLL::BCryptGetProperty](#bcryptdllbcryptgetproperty)
	* [BCRYPT.DLL::BCryptCloseAlgorithmProvider](#bcryptdllbcryptclosealgorithmprovider)
	* [BCRYPT.DLL::BCryptOpenAlgorithmProvider](#bcryptdllbcryptopenalgorithmprovider)
	* [BCRYPT.DLL::BCryptHashData](#bcryptdllbcrypthashdata)
	* [NTDLL.DLL::NtQuerySystemInformation](#ntdlldllntquerysysteminformation)
	* [BCRYPT.DLL::BCryptDestroyHash](#bcryptdllbcryptdestroyhash)
	* [BCRYPT.DLL::BCryptGenRandom](#bcryptdllbcryptgenrandom)
	* [API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::LoadLibraryExW](#api-ms-win-core-libraryloader-l1-2-0dllloadlibraryexw)
	* [BCRYPT.DLL::BCryptFinishHash](#bcryptdllbcryptfinishhash)
* [Modified](#modified)
	* [WaasMedic::CSandboxRpcWrapper::CreateSandbox](#waasmediccsandboxrpcwrappercreatesandbox)
	* [WaasMedic::CWaasRemediation::LoadPluginLibrary](#waasmediccwaasremediationloadpluginlibrary)
	* [WaasMedic::IsTrustedLibrary](#waasmedicistrustedlibrary)
	* [WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper](#waasmediccsandboxrpcwrappercsandboxrpcwrapper)
	* [WaasMedic::MiscUtil::SetBelowNormalPriorityState](#waasmedicmiscutilsetbelownormalprioritystate)
	* [WaasMedic::CSandboxRpcWrapper::Init](#waasmediccsandboxrpcwrapperinit)
	* [WaasMedic::CWaasRemediation::RunPluginsInCapsule](#waasmediccwaasremediationrunpluginsincapsule)
* [Modified (No Code Changes)](#modified-no-code-changes)
	* [__local_stdio_printf_options](#__local_stdio_printf_options)
	* [basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>](#basic_stringunsigned_shortstdchar_traitsunsigned_shortstdallocatorunsigned_short_)
	* [API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree](#api-ms-win-core-heap-l2-1-0dlllocalfree)
	* [StringCchPrintfW](#stringcchprintfw)
	* [API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW](#api-ms-win-core-version-l1-1-0dllverqueryvaluew)
	* [API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp](#api-ms-win-crt-private-l1-1-0dll_o__wcsicmp)
	* [dtor$0](#dtor0)
	* [__security_check_cookie](#__security_check_cookie)
	* [API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree](#api-ms-win-core-com-l1-1-0dllcotaskmemfree)
	* [allocate](#allocate)
	* [dtor$2](#dtor2)
	* [API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid](#api-ms-win-core-com-l1-1-0dllcocreateguid)
	* [SafeFree](#safefree)
	* [SafeAllocString](#safeallocstring)
	* [__GSHandlerCheck_EH](#__gshandlercheck_eh)
	* [substr](#substr)
	* [API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError](#api-ms-win-core-errorhandling-l1-1-0dllgetlasterror)
	* [_Xran](#_xran)
	* [~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>](#basic_stringunsigned_shortstdchar_traitsunsigned_shortstdallocatorunsigned_short_)
	* [API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn](#api-ms-win-crt-private-l1-1-0dll_o__invalid_parameter_noinfo_noreturn)
	* [OLEAUT32.DLL::LoadRegTypeLib](#oleaut32dllloadregtypelib)
	* [API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc](#api-ms-win-core-heap-l2-1-0dlllocalalloc)

# Visual Chart Diff



```mermaid

flowchart LR

WaasMedicCSandboxRpcWrapperCreateSandbox-1-old<--Match 84%-->WaasMedicCSandboxRpcWrapperCreateSandbox-1-new
WaasMedicCWaasRemediationLoadPluginLibrary-2-old<--Match 89%-->WaasMedicCWaasRemediationLoadPluginLibrary-2-new
WaasMedicIsTrustedLibrary-1-old<--Match 90%-->WaasMedicIsTrustedLibrary-1-new
WaasMedicCSandboxRpcWrapperCSandboxRpcWrapper-1-old<--Match 98%-->WaasMedicCSandboxRpcWrapperCSandboxRpcWrapper-1-new
WaasMedicMiscUtilSetBelowNormalPriorityState-1-old<--Match 91%-->WaasMedicMiscUtilSetBelowNormalPriorityState-1-new
WaasMedicCSandboxRpcWrapperInit-2-old<--Match 67%-->WaasMedicCSandboxRpcWrapperInit-2-new
WaasMedicCWaasRemediationRunPluginsInCapsule-12-old<--Match 99%-->WaasMedicCWaasRemediationRunPluginsInCapsule-12-new

subgraph waasmedicsvc-2020-01.dll
    WaasMedicCSandboxRpcWrapperCreateSandbox-1-new
WaasMedicCWaasRemediationLoadPluginLibrary-2-new
WaasMedicIsTrustedLibrary-1-new
WaasMedicCSandboxRpcWrapperCSandboxRpcWrapper-1-new
WaasMedicMiscUtilSetBelowNormalPriorityState-1-new
WaasMedicCSandboxRpcWrapperInit-2-new
WaasMedicCWaasRemediationRunPluginsInCapsule-12-new
    subgraph Added
direction LR
WaasMedic-MiscUtil-HRESULT_FROM_NTSTATUS
    WaasMedic-GetRandomString
    WaasMedic-ValidateOriginalFileName
    WaasMedic-GetSha256HashOfString
    std-basic_stringunsigned_shortstd-char_traitsunsigned_shortstd-allocatorunsigned_short_-find_last_of
    std-basic_stringunsigned_shortstd-char_traitsunsigned_shortstd-allocatorunsigned_short_-operator
    swprintf_s
    WaasMedic-CSandboxRpcWrapper-Init-__l1-dtor0
    WaasMedic-CSandboxRpcWrapper-CreateSandbox-__l1-dtor0
    WaasMedic-GetRandomString-__l1-dtor0
    WaasMedic-ValidateOriginalFileName-__l1-dtor1
    WaasMedic-GetSha256HashOfString-__l1-dtor0
    API-MS-WIN-CRT-PRIVATE-L1-1-0DLL-_o_tolower
    API-MS-WIN-CRT-PRIVATE-L1-1-0DLL-_o___stdio_common_vswprintf_s
    BCRYPTDLL-BCryptCreateHash
    API-MS-WIN-CORE-VERSION-L1-1-0DLL-GetFileVersionInfoExW
    API-MS-WIN-CORE-VERSION-L1-1-0DLL-GetFileVersionInfoSizeExW
    BCRYPTDLL-BCryptGetProperty
    BCRYPTDLL-BCryptCloseAlgorithmProvider
    BCRYPTDLL-BCryptOpenAlgorithmProvider
    BCRYPTDLL-BCryptHashData
    NTDLLDLL-NtQuerySystemInformation
    BCRYPTDLL-BCryptDestroyHash
    BCRYPTDLL-BCryptGenRandom
    API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0DLL-LoadLibraryExW
    BCRYPTDLL-BCryptFinishHash
end
end

subgraph waasmedicsvc-2019-12.dll
    WaasMedicCSandboxRpcWrapperCreateSandbox-1-old
WaasMedicCWaasRemediationLoadPluginLibrary-2-old
WaasMedicIsTrustedLibrary-1-old
WaasMedicCSandboxRpcWrapperCSandboxRpcWrapper-1-old
WaasMedicMiscUtilSetBelowNormalPriorityState-1-old
WaasMedicCSandboxRpcWrapperInit-2-old
WaasMedicCWaasRemediationRunPluginsInCapsule-12-old
    subgraph Deleted
direction LR
API-MS-WIN-CORE-COM-L1-1-0DLL-StringFromCLSID
end
end

```


```mermaid
pie showData
    title Function Matches - 98.6765%
"unmatched_funcs_len" : 27
"matched_funcs_len" : 2013
```



```mermaid
pie showData
    title Matched Function Similarity - 98.3110%
"matched_funcs_with_code_changes_len" : 7
"matched_funcs_with_non_code_changes_len" : 27
"matched_funcs_no_changes_len" : 1979
```

# Metadata

## Ghidra Diff Engine

### Command Line

#### Captured Command Line


```
ghidriff --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --threaded --log-level INFO --file-log-level INFO --log-path ghidriff.log --min-func-len 10 --gdt [] --max-ram-percent 60.0 --max-section-funcs 200 waasmedicsvc-2019-12.dll waasmedicsvc-2020-01.dll
```


#### Verbose Args


<details>

```
--old ['waasmedicsvc-2019-12.dll'] --new [['waasmedicsvc-2020-01.dll']] --engine VersionTrackingDiff --output-path ghidriffs --summary False --project-location ghidra_projects --project-name ghidriff --symbols-path symbols --gzfs-path gzfs --base-address None --program-options None --threaded True --force-analysis False --force-diff False --no-symbols False --log-level INFO --file-log-level INFO --log-path ghidriff.log --va False --min-func-len 10 --use-calling-counts False --gdt [] --bsim False --bsim-full False --max-ram-percent 60.0 --print-flags False --jvm-args None --side-by-side False --max-section-funcs 200 --md-title None
```


</details>

#### Download Original PEs


```
wget https://msdl.microsoft.com/download/symbols/WaasMedicSvc.dll/F02B71B25B000/WaasMedicSvc.dll -O waasmedicsvc.dll.x64.10.0.18362.1034
wget https://msdl.microsoft.com/download/symbols/WaasMedicSvc.dll/21DF60025D000/WaasMedicSvc.dll -O waasmedicsvc.dll.x64.10.0.18362.628
```


## Binary Metadata Diff


```diff
--- waasmedicsvc-2019-12.dll Meta
+++ waasmedicsvc-2020-01.dll Meta
@@ -1,44 +1,44 @@
-Program Name: waasmedicsvc-2019-12.dll
+Program Name: waasmedicsvc-2020-01.dll
 Language ID: x86:LE:64:default (4.7)
 Compiler ID: windows
 Processor: x86
 Endian: Little
 Address Size: 64
 Minimum Address: 180000000
 Maximum Address: ff0000184f
-# of Bytes: 360176
+# of Bytes: 366832
 # of Memory Blocks: 9
-# of Instructions: 46957
-# of Defined Data: 4960
-# of Functions: 1007
-# of Symbols: 10177
-# of Data Types: 1158
-# of Data Type Categories: 59
+# of Instructions: 47771
+# of Defined Data: 5072
+# of Functions: 1033
+# of Symbols: 10430
+# of Data Types: 1169
+# of Data Type Categories: 60
 Analyzed: true
 Compiler: visualstudio:unknown
 Created With Ghidra Version: 12.1.2
-Date Created: Tue Sep 08 22:48:50 SGT 2026
+Date Created: Tue Sep 08 22:48:58 SGT 2026
 Executable Format: Portable Executable (PE)
-Executable Location: /C:/Users/Jacob/Downloads/pdbs/waasmedicsvc-2019-12.dll
-Executable MD5: 16e4aa01a7315cffe758d3de9b3d36d3
-Executable SHA256: 1f1c9f46caf56e938758af6a13a39150ceb8ef9b0c8c06c4327107bf84a304f9
-FSRL: file:///C:/Users/Jacob/Downloads/pdbs/waasmedicsvc-2019-12.dll?MD5=16e4aa01a7315cffe758d3de9b3d36d3
+Executable Location: /C:/Users/Jacob/Downloads/pdbs/waasmedicsvc-2020-01.dll
+Executable MD5: e9b2224a2d7a5612a4396f77b05b301c
+Executable SHA256: 4236c7c7d9827deb21b2d96073805f6b17924c1feb46a34a640f0dc6bb1b23ea
+FSRL: file:///C:/Users/Jacob/Downloads/pdbs/waasmedicsvc-2020-01.dll?MD5=e9b2224a2d7a5612a4396f77b05b301c
 PDB Age: 1
 PDB File: WaaSMedicSvc.pdb
-PDB GUID: 5a98ae80-0d2c-f1aa-d641-2857d56ff206
+PDB GUID: c0a62ab2-c763-f680-e13b-fd50acdedc34
 PDB Loaded: true
 PDB Version: RSDS
 PE Property[CompanyName]: Microsoft Corporation
 PE Property[FileDescription]: WaasMedic Service Dll
-PE Property[FileVersion]: 10.0.18362.1034 (WinBuild.160101.0800)
+PE Property[FileVersion]: 10.0.18362.628 (WinBuild.160101.0800)
 PE Property[InternalName]: WaasMedicSvc.dll
 PE Property[LegalCopyright]: © Microsoft Corporation. All rights reserved.
 PE Property[OriginalFilename]: WaasMedicSvc.dll
 PE Property[ProductName]: Microsoft® Windows® Operating System
-PE Property[ProductVersion]: 10.0.18362.1034
+PE Property[ProductVersion]: 10.0.18362.628
 PE Property[Translation]: 4b00409
 Preferred Root Namespace Category: 
 RTTI Found: true
 Relocatable: true
 SectionAlignment: 4096
 Should Ask To Analyze: false

```


## Program Options


<details>
<summary>Ghidra waasmedicsvc-2019-12.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra waasmedicsvc-2019-12.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra waasmedicsvc-2019-12.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>


<details>
<summary>Ghidra waasmedicsvc-2020-01.dll Decompiler Options</summary>


|Decompiler Option|Value|
| :---: | :---: |
|Prototype Evaluation|__fastcall|

</details>


<details>
<summary>Ghidra waasmedicsvc-2020-01.dll Specification extensions Options</summary>


|Specification extensions Option|Value|
| :---: | :---: |
|FormatVersion|0|
|VersionCounter|0|

</details>


<details>
<summary>Ghidra waasmedicsvc-2020-01.dll Analyzers Options</summary>


|Analyzers Option|Value|
| :---: | :---: |
|ASCII Strings|true|
|ASCII Strings.Create Strings Containing Existing Strings|true|
|ASCII Strings.Create Strings Containing References|true|
|ASCII Strings.Force Model Reload|false|
|ASCII Strings.Minimum String Length|LEN_5|
|ASCII Strings.Model File|StringModel.sng|
|ASCII Strings.Require Null Termination for String|true|
|ASCII Strings.Search Only in Accessible Memory Blocks|true|
|ASCII Strings.String Start Alignment|ALIGN_1|
|ASCII Strings.String end alignment|4|
|Aggressive Instruction Finder|false|
|Aggressive Instruction Finder.Create Analysis Bookmarks|true|
|Apply Data Archives|true|
|Apply Data Archives.Archive Chooser|[Auto-Detect]|
|Apply Data Archives.Create Analysis Bookmarks|true|
|Apply Data Archives.GDT User File Archive Path|None|
|Apply Data Archives.User Project Archive Path|None|
|Call Convention ID|true|
|Call Convention ID.Analysis Decompiler Timeout (sec)|60|
|Call-Fixup Installer|true|
|Condense Filler Bytes|false|
|Condense Filler Bytes.Filler Value|Auto|
|Condense Filler Bytes.Minimum number of sequential bytes|1|
|Create Address Tables|true|
|Create Address Tables.Allow Offcut References|false|
|Create Address Tables.Auto Label Table|false|
|Create Address Tables.Create Analysis Bookmarks|true|
|Create Address Tables.Maxmimum Pointer Distance|16777215|
|Create Address Tables.Minimum Pointer Address|4132|
|Create Address Tables.Minimum Table Size|2|
|Create Address Tables.Pointer Alignment|1|
|Create Address Tables.Relocation Table Guide|true|
|Create Address Tables.Table Alignment|4|
|Data Reference|true|
|Data Reference.Address Table Alignment|1|
|Data Reference.Address Table Minimum Size|2|
|Data Reference.Align End of Strings|false|
|Data Reference.Ascii String References|true|
|Data Reference.Create Address Tables|true|
|Data Reference.Minimum String Length|5|
|Data Reference.References to Pointers|true|
|Data Reference.Relocation Table Guide|true|
|Data Reference.Respect Execute Flag|true|
|Data Reference.Subroutine References|true|
|Data Reference.Switch Table References|false|
|Data Reference.Unicode String References|true|
|Decompiler Parameter ID|true|
|Decompiler Parameter ID.Analysis Clear Level|ANALYSIS|
|Decompiler Parameter ID.Analysis Decompiler Timeout (sec)|60|
|Decompiler Parameter ID.Commit Data Types|true|
|Decompiler Parameter ID.Commit Void Return Values|false|
|Decompiler Parameter ID.Prototype Evaluation|__fastcall|
|Decompiler Switch Analysis|true|
|Decompiler Switch Analysis.Analysis Decompiler Timeout (sec)|60|
|Demangler Microsoft|true|
|Demangler Microsoft.msdApplyOptions|{
	interpretation: FUNCTION_IF_EXISTS,
	applyCallingConvention: true,
	applySignature: true,
	demangleOnlyKnownPatterns: true,
	doDisassembly: true
}|
|Demangler Microsoft.msdOutputOptions|ghidra.app.util.demangler.microsoft.options.MsdOutputOption@9e5b|
|Disassemble Entry Points|true|
|Disassemble Entry Points.Respect Execute Flag|true|
|Embedded Media|true|
|Embedded Media.Create Analysis Bookmarks|true|
|External Entry References|true|
|Function ID|true|
|Function ID.Always Apply FID Labels|false|
|Function ID.Create Analysis Bookmarks|true|
|Function ID.Instruction Count Threshold|14.6|
|Function ID.Multiple Match Threshold|30.0|
|Function Start Search|true|
|Function Start Search.Bookmark Functions|false|
|Function Start Search.Search Data Blocks|false|
|Non-Returning Functions - Discovered|true|
|Non-Returning Functions - Discovered.Create Analysis Bookmarks|true|
|Non-Returning Functions - Discovered.Function Non-return Threshold|3|
|Non-Returning Functions - Discovered.Repair Flow Damage|true|
|Non-Returning Functions - Known|true|
|Non-Returning Functions - Known.Create Analysis Bookmarks|true|
|PDB MSDIA|false|
|PDB MSDIA.Search untrusted symbol servers|false|
|PDB Universal|true|
|PDB Universal.Import Source Line Info|true|
|PDB Universal.Search untrusted symbol servers|false|
|Reference|true|
|Reference.Address Table Alignment|1|
|Reference.Address Table Minimum Size|2|
|Reference.Align End of Strings|false|
|Reference.Ascii String References|true|
|Reference.Create Address Tables|true|
|Reference.Minimum String Length|5|
|Reference.References to Pointers|true|
|Reference.Relocation Table Guide|true|
|Reference.Respect Execute Flag|true|
|Reference.Subroutine References|true|
|Reference.Switch Table References|false|
|Reference.Unicode String References|true|
|Scalar Operand References|true|
|Scalar Operand References.Relocation Table Guide|true|
|Shared Return Calls|true|
|Shared Return Calls.Allow Conditional Jumps|false|
|Shared Return Calls.Assume Contiguous Functions Only|true|
|Stack|true|
|Stack.Create Local Variables|true|
|Stack.Create Param Variables|false|
|Stack.Max Threads|2|
|Subroutine References|true|
|Subroutine References.Create Thunks Early|true|
|Variadic Function Signature Override|false|
|Variadic Function Signature Override.Create Analysis Bookmarks|false|
|Windows x86 PE Exception Handling|true|
|Windows x86 PE RTTI Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer|true|
|Windows x86 Thread Environment Block (TEB) Analyzer.Starting Address of the TEB||
|Windows x86 Thread Environment Block (TEB) Analyzer.Windows OS Version|Windows 7|
|WindowsPE x86 Propagate External Parameters|false|
|WindowsResourceReference|true|
|WindowsResourceReference.Create Analysis Bookmarks|true|
|x86 Constant Reference Analyzer|true|
|x86 Constant Reference Analyzer.Create Data from pointer|false|
|x86 Constant Reference Analyzer.Function parameter/return Pointer analysis|true|
|x86 Constant Reference Analyzer.Max Threads|2|
|x86 Constant Reference Analyzer.Min absolute reference|4|
|x86 Constant Reference Analyzer.Require pointer param data type|false|
|x86 Constant Reference Analyzer.Speculative reference max|256|
|x86 Constant Reference Analyzer.Speculative reference min|1024|
|x86 Constant Reference Analyzer.Stored Value Pointer analysis|true|
|x86 Constant Reference Analyzer.Trust values read from writable memory|true|

</details>

## Diff Stats



|Stat|Value|
| :---: | :---: |
|added_funcs_len|26|
|deleted_funcs_len|1|
|modified_funcs_len|34|
|added_symbols_len|15|
|deleted_symbols_len|1|
|diff_time|16.24411630630493|
|deleted_strings_len|2|
|added_strings_len|29|
|match_types|Counter({'SymbolsHash': 1004, 'ExternalsName': 254, 'ExactInstructionsFunctionHasher': 1})|
|items_to_process|77|
|diff_types|Counter({'address': 30, 'refcount': 27, 'calling': 24, 'code': 7, 'length': 7, 'called': 7})|
|unmatched_funcs_len|27|
|total_funcs_len|2040|
|matched_funcs_len|2013|
|matched_funcs_with_code_changes_len|7|
|matched_funcs_with_non_code_changes_len|27|
|matched_funcs_no_changes_len|1979|
|match_func_similarity_percent|98.3110%|
|func_match_overall_percent|98.6765%|
|first_matches|Counter({'SymbolsHash': 1004, 'ExactInstructionsFunctionHasher': 1})|



```mermaid
pie showData
    title All Matches
"SymbolsHash" : 1004
"ExternalsName" : 254
"ExactInstructionsFunctionHasher" : 1
```



```mermaid
pie showData
    title First Matches
"SymbolsHash" : 1004
"ExactInstructionsFunctionHasher" : 1
```



```mermaid
pie showData
    title Diff Stats
"added_funcs_len" : 26
"deleted_funcs_len" : 1
"modified_funcs_len" : 34
```



```mermaid
pie showData
    title Symbols
"added_symbols_len" : 15
"deleted_symbols_len" : 1
```

## Strings



```mermaid
pie showData
    title Strings
"deleted_strings_len" : 2
"added_strings_len" : 29
```

### Strings Diff


```diff
--- deleted strings
+++ added strings
@@ -1,2 +1,29 @@
-u_Creating_Proces
-u_RPC_Endpoint:_%
+u_%02x
+u_.dll
+u_/\
+u_Allocation_of
+u_Allocation_of_h
+u_Allocation_of_s
+u_An_error_occure
+u_BCryptCreateHas
+u_BCryptGetProper
+u_BCryptOpenAlgor
+u_Caller_passed_l
+u_Caller_passed_n
+u_Could_not_alloc
+u_Could_not_get_r
+u_Could_not_open
+u_Could_not_write
+u_Error_trying_to
+u_Expected:_%ws_F
+u_Failed_to_deter
+u_Failed_to_write
+u_HashDigestLengt
+u_ObjectLength
+u_RNG
+u_RPC_Endpoint_st
+u_SHA256
+u_The_file_name
+u_The_original_fi
+u_\StringFileInfo
+u_\VarFileInfo\Tr

```


### String References

#### Old



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|u_Creating_Proces|1|CreateSandbox|
|u_RPC_Endpoint:_%|1|Init|

#### New



|String|Ref Count|Ref Func|
| :---: | :---: | :---: |
|u_BCryptOpenAlgor|1|GetSha256HashOfString|
|u_BCryptCreateHas|1|GetSha256HashOfString|
|u_Could_not_open_|1|GetRandomString|
|u_%02x|2|GetSha256HashOfString,GetRandomString|
|u_BCryptGetProper|1|GetSha256HashOfString|
|u_RPC_Endpoint_st|1|Init|
|u_Could_not_alloc|1|GetRandomString|
|u_/\|5|find_last_of|
|u_Failed_to_deter|1|CreateSandbox|
|u_Error_trying_to|1|ValidateOriginalFileName|
|u_Allocation_of_s|1|GetSha256HashOfString|
|u_HashDigestLengt|1|GetSha256HashOfString|
|u_Could_not_write|1|GetRandomString|
|u_ObjectLength|1|GetSha256HashOfString|
|u_The_original_fi|1|ValidateOriginalFileName|
|u_Failed_to_write|1|GetSha256HashOfString|
|u_Caller_passed_l|1|ValidateOriginalFileName|
|u_Allocation_of_h|1|GetSha256HashOfString|
|u_The_file_name_d|1|IsTrustedLibrary|
|u_Allocation_of_b|1|GetSha256HashOfString|
|u_RNG|1|GetRandomString|
|u_\StringFileInfo|1|ValidateOriginalFileName|
|u_SHA256|1|GetSha256HashOfString|
|u_\VarFileInfo\Tr|1|ValidateOriginalFileName|
|u_Could_not_get_r|1|GetRandomString|
|u_An_error_occure|1|IsTrustedLibrary|
|u_Expected:_%ws_F|1|ValidateOriginalFileName|
|u_Caller_passed_n|1|ValidateOriginalFileName|
|u_.dll|1|ValidateOriginalFileName|

# Deleted

## API-MS-WIN-CORE-COM-L1-1-0.DLL::StringFromCLSID

### Function Meta



|Key|waasmedicsvc-2019-12.dll|
| :---: | :---: |
|name|StringFromCLSID|
|fullname|API-MS-WIN-CORE-COM-L1-1-0.DLL::StringFromCLSID|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::CSandboxRpcWrapper::Init|
|paramcount|2|
|address|EXTERNAL:0000009c|
|sig|HRESULT __stdcall StringFromCLSID(IID * rclsid, LPOLESTR * lplpsz)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CORE-COM-L1-1-0.DLL::StringFromCLSID*
# Added

## WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|HRESULT_FROM_NTSTATUS|
|fullname|WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS|
|refcount|8|
|length|49|
|called|NTDLL.DLL::RtlNtStatusToDosError|
|calling|WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString<br>WaasMedic::MiscUtil::SetBelowNormalPriorityState|
|paramcount|1|
|address|18000e560|
|sig|long __cdecl HRESULT_FROM_NTSTATUS(long param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS
+++ WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS
@@ -0,0 +1,22 @@
+
+/* public: static long __cdecl WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS(long) */
+
+long __cdecl WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS(long param_1)
+
+{
+  uint uVar1;
+  uint uVar2;
+  
+  uVar2 = RtlNtStatusToDosError();
+  if (uVar2 == 0x13d) {
+    uVar1 = param_1 | 0x10000000;
+  }
+  else {
+    uVar1 = uVar2 & 0xffff | 0x80070000;
+    if ((int)uVar2 < 1) {
+      uVar1 = uVar2;
+    }
+  }
+  return uVar1;
+}
+

```


## WaasMedic::GetRandomString

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|GetRandomString|
|fullname|WaasMedic::GetRandomString|
|refcount|2|
|length|407|
|called|<details><summary>Expand for full list:<br>BCRYPT.DLL::BCryptCloseAlgorithmProvider<br>BCRYPT.DLL::BCryptGenRandom<br>BCRYPT.DLL::BCryptOpenAlgorithmProvider<br>LogLevelW<br>StringCchPrintfW<br>WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS<br>WaasMedic::SafeAlloc<br>WaasMedic::SafeFree<br>__security_check_cookie<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=</summary>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_></details>|
|calling|WaasMedic::CSandboxRpcWrapper::Init|
|paramcount|2|
|address|180010bdc|
|sig|long __cdecl GetRandomString(__uint64 param_1, basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- WaasMedic::GetRandomString
+++ WaasMedic::GetRandomString
@@ -0,0 +1,105 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* long __cdecl WaasMedic::GetRandomString(unsigned __int64,class std::basic_string<unsigned
+   short,struct std::char_traits<unsigned short>,class std::allocator<unsigned short> > & __ptr64)
+    */
+
+long __cdecl
+WaasMedic::GetRandomString
+          (__uint64 param_1,
+          basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+          *param_2)
+
+{
+  NTSTATUS NVar1;
+  uint uVar2;
+  PUCHAR pbBuffer;
+  ushort *puVar3;
+  basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+  *pbVar4;
+  undefined1 uVar5;
+  wchar_t *pwVar6;
+  PUCHAR pUVar7;
+  PUCHAR pUVar8;
+  ulonglong uVar9;
+  ushort *puVar10;
+  undefined1 auStack_a8 [32];
+  BCRYPT_ALG_HANDLE local_88;
+  undefined8 local_80;
+  undefined2 local_78 [8];
+  undefined8 local_68;
+  undefined8 uStack_60;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  local_58 [32];
+  ulonglong local_38;
+  
+  local_80 = 0xfffffffffffffffe;
+  local_38 = __security_cookie ^ (ulonglong)auStack_a8;
+  pUVar8 = (PUCHAR)0x0;
+  local_68 = 0;
+  uStack_60 = 7;
+  local_78[0] = 0;
+  uVar5 = 0xa8;
+  NVar1 = BCryptOpenAlgorithmProvider(&local_88,L"RNG",(LPCWSTR)0x0,0);
+  if (NVar1 == 0) {
+    pbBuffer = SafeAlloc(0x10,(bool)uVar5);
+    if (pbBuffer != (PUCHAR)0x0) {
+      pUVar7 = pbBuffer;
+      NVar1 = BCryptGenRandom(local_88,pbBuffer,0x10,0);
+      if (NVar1 != 0) {
+        uVar2 = MiscUtil::HRESULT_FROM_NTSTATUS(NVar1);
+        pwVar6 = L"Could not get random number from the provider. Error: 0x%08x.";
+        goto LAB_180010d1b;
+      }
+      puVar3 = SafeAlloc(0x42,SUB81(pUVar7,0));
+      puVar10 = puVar3;
+      if (puVar3 != (ushort *)0x0) {
+        do {
+          uVar2 = StringCchPrintfW(puVar10,3,(ushort *)L"%02x",(ulonglong)pUVar8[(longlong)pbBuffer]
+                                  );
+          if ((int)uVar2 < 0) {
+            pwVar6 = L"Could not write characters to the generated string. Error: 0x%08x.";
+            goto LAB_180010d1b;
+          }
+          pUVar8 = pUVar8 + 1;
+          puVar10 = puVar10 + 2;
+        } while (pUVar8 < (PUCHAR)0x10);
+        pbVar4 = (basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+                  *)std::
+                    basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                    ::
+                    basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                              (local_58,puVar3);
+        std::
+        basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+        ::operator=(param_2,pbVar4);
+        std::
+        basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+        ::
+        ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                  (local_58);
+        goto LAB_180010d28;
+      }
+    }
+    uVar9 = 0x8007000e;
+    uVar2 = 0x8007000e;
+    pwVar6 = L"Could not allocate memory for the requested buffer. Error: 0x%08x.";
+  }
+  else {
+    uVar2 = MiscUtil::HRESULT_FROM_NTSTATUS(NVar1);
+    pwVar6 = L"Could not open provider. Error: 0x%08x.";
+    pbBuffer = pUVar8;
+LAB_180010d1b:
+    uVar9 = (ulonglong)uVar2;
+  }
+  LogLevelW('\x02',(ushort *)pwVar6,uVar9);
+LAB_180010d28:
+  SafeFree(pbBuffer);
+  BCryptCloseAlgorithmProvider(local_88,0);
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)local_78);
+  return uVar2;
+}
+

```


## WaasMedic::ValidateOriginalFileName

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|ValidateOriginalFileName|
|fullname|WaasMedic::ValidateOriginalFileName|
|refcount|2|
|length|1081|
|called|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc<br>API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree<br>API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoExW<br>API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoSizeExW<br>API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW<br>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp<br>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o_tolower<br>LogLevelW<br>__security_check_cookie<br>memcpy</summary>std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran<br>std::allocator<unsigned_short>::allocate<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::substr<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>swprintf_s</details>|
|calling|WaasMedic::IsTrustedLibrary|
|paramcount|2|
|address|180010d7c|
|sig|long __cdecl ValidateOriginalFileName(ushort * param_1, bool * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- WaasMedic::ValidateOriginalFileName
+++ WaasMedic::ValidateOriginalFileName
@@ -0,0 +1,263 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* long __cdecl WaasMedic::ValidateOriginalFileName(unsigned short const * __ptr64,bool & __ptr64)
+    */
+
+long __cdecl WaasMedic::ValidateOriginalFileName(ushort *param_1,bool *param_2)
+
+{
+  ushort uVar1;
+  code *pcVar2;
+  undefined2 uVar3;
+  DWORD DVar4;
+  BOOL BVar5;
+  int iVar6;
+  long lVar7;
+  allocator<unsigned_short> *paVar8;
+  __uint64 _Var9;
+  basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+  *pbVar10;
+  HLOCAL lpData;
+  uint uVar11;
+  ushort ****ppppuVar12;
+  ushort *puVar13;
+  wchar_t *pwVar14;
+  ulonglong uVar15;
+  allocator<unsigned_short> *paVar16;
+  ulonglong uVar17;
+  ulonglong uVar18;
+  longlong lVar19;
+  undefined1 auStackY_328 [32];
+  DWORD local_2f8;
+  ushort local_2f4 [2];
+  uint local_2f0 [2];
+  ushort *local_2e8;
+  LPVOID local_2e0;
+  bool *local_2d8;
+  undefined8 local_2d0;
+  allocator<unsigned_short> *local_2c8 [2];
+  ushort *local_2b8;
+  ulonglong local_2b0;
+  allocator<unsigned_short> *local_2a8;
+  undefined4 uStack_2a0;
+  undefined4 uStack_29c;
+  ushort *local_298;
+  ulonglong uStack_290;
+  ushort ***local_288 [2];
+  ushort *local_278;
+  ulonglong local_270;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  local_268 [32];
+  wchar_t local_248 [256];
+  ulonglong local_48;
+  
+  local_2d0 = 0xfffffffffffffffe;
+  local_48 = __security_cookie ^ (ulonglong)auStackY_328;
+  uVar17 = 0;
+  *param_2 = false;
+  local_2e0 = (LPVOID)0x0;
+  iVar6 = 0;
+  local_2f8 = 0;
+  local_2d8 = param_2;
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)local_2c8,param_1);
+  puVar13 = local_2b8;
+  local_298 = (ushort *)0x0;
+  uStack_290 = 0;
+  paVar8 = (allocator<unsigned_short> *)local_2c8;
+  if (7 < local_2b0) {
+    paVar8 = local_2c8[0];
+  }
+  if (local_2b8 < (ushort *)0x8) {
+    local_2a8 = *(allocator<unsigned_short> **)paVar8;
+    uStack_2a0 = *(undefined4 *)(paVar8 + 8);
+    uStack_29c = *(undefined4 *)(paVar8 + 0xc);
+    local_298 = local_2b8;
+    uStack_290 = 7;
+  }
+  else {
+    uVar15 = (ulonglong)local_2b8 | 7;
+    if (0x7ffffffffffffffe < uVar15) {
+      uVar15 = 0x7ffffffffffffffe;
+    }
+    local_2a8 = (allocator<unsigned_short> *)
+                std::allocator<unsigned_short>::allocate(local_2c8[0],uVar15 + 1);
+    memcpy(local_2a8,paVar8,(longlong)puVar13 * 2 + 2);
+    local_298 = puVar13;
+    uStack_290 = uVar15;
+  }
+  local_2e8 = (ushort *)0x0;
+  local_2f4[0] = 0x409;
+  local_2f4[1] = 0x4b0;
+  if (param_1 == (ushort *)0x0) {
+    LogLevelW('\x02',(ushort *)L"Caller passed null parameter to ValidateOriginalFileName.");
+    uVar11 = 0x80004003;
+    goto LAB_18001116e;
+  }
+  paVar8 = (allocator<unsigned_short> *)local_2c8;
+  if (7 < local_2b0) {
+    paVar8 = local_2c8[0];
+  }
+  paVar16 = (allocator<unsigned_short> *)local_2c8;
+  if (7 < local_2b0) {
+    paVar16 = local_2c8[0];
+  }
+  uVar15 = (ulonglong)(paVar8 + (longlong)local_2b8 * 2 + (1 - (longlong)paVar16)) >> 1;
+  if (paVar8 + (longlong)local_2b8 * 2 < paVar16) {
+    uVar15 = uVar17;
+  }
+  if (uVar15 != 0) {
+    lVar19 = (longlong)paVar8 - (longlong)paVar16;
+    uVar18 = uVar17;
+    do {
+      uVar3 = _o_tolower(*(undefined2 *)paVar16);
+      *(undefined2 *)(paVar16 + lVar19) = uVar3;
+      paVar16 = paVar16 + 2;
+      uVar18 = uVar18 + 1;
+    } while (uVar18 != uVar15);
+  }
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)local_288,(ushort *)L".dll");
+  if (local_278 < local_2b8) {
+    if (local_2b8 < (ushort *)((longlong)local_2b8 - (longlong)local_278)) {
+      std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran();
+      pcVar2 = (code *)swi(3);
+      lVar7 = (*pcVar2)();
+      return lVar7;
+    }
+    ppppuVar12 = local_288;
+    if (7 < local_270) {
+      ppppuVar12 = (ushort ****)local_288[0];
+    }
+    paVar8 = (allocator<unsigned_short> *)local_2c8;
+    if (7 < local_2b0) {
+      paVar8 = local_2c8[0];
+    }
+    if (local_278 != (ushort *)0x0) {
+      paVar16 = paVar8 + (((longlong)local_2b8 - (longlong)local_278) * 2 - (longlong)ppppuVar12);
+      do {
+        uVar1 = *(ushort *)ppppuVar12;
+        paVar8 = (allocator<unsigned_short> *)(ulonglong)uVar1;
+        if (*(ushort *)((longlong)ppppuVar12 + (longlong)paVar16) != uVar1) {
+          iVar6 = (-(uint)(*(ushort *)((longlong)ppppuVar12 + (longlong)paVar16) < uVar1) &
+                  0xfffffffe) + 1;
+          break;
+        }
+        ppppuVar12 = (ushort ****)((longlong)ppppuVar12 + 2);
+        local_278 = (ushort *)((longlong)local_278 + -1);
+      } while (local_278 != (ushort *)0x0);
+    }
+    if (iVar6 != 0) goto LAB_180011151;
+    _Var9 = std::
+            basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ::find_last_of((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                            *)local_2c8,local_278,(__uint64)paVar8);
+    if (_Var9 != 0xffffffffffffffff) {
+      pbVar10 = (basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+                 *)std::
+                   basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                   ::substr((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                             *)local_2c8,(__uint64)local_268,_Var9 + 1);
+      std::
+      basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+      ::operator=((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                   *)&local_2a8,pbVar10);
+      std::
+      basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+      ::
+      ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                (local_268);
+    }
+    DVar4 = GetFileVersionInfoSizeExW(0,(LPCWSTR)param_1,&local_2f8);
+    if (DVar4 == 0) {
+      DVar4 = GetLastError();
+      uVar11 = DVar4 & 0xffff | 0x80070000;
+      if ((int)DVar4 < 1) {
+        uVar11 = DVar4;
+      }
+      uVar17 = (ulonglong)uVar11;
+      pwVar14 = L"Error trying to get the file version info size. hr = 0x%08X";
+LAB_180010fec:
+      LogLevelW('\x02',(ushort *)pwVar14,uVar17);
+    }
+    else {
+      lpData = LocalAlloc(0,(ulonglong)DVar4);
+      if (lpData == (HLOCAL)0x0) {
+        uVar17 = 0x8007000e;
+        uVar11 = 0x8007000e;
+        pwVar14 = L"Failed to allocate memory for file version info. hr = 0x%08X";
+        goto LAB_180010fec;
+      }
+      BVar5 = GetFileVersionInfoExW(0,(LPCWSTR)param_1,local_2f8,DVar4,lpData);
+      if (BVar5 == 0) {
+        DVar4 = GetLastError();
+        uVar11 = DVar4 & 0xffff | 0x80070000;
+        if ((int)DVar4 < 1) {
+          uVar11 = DVar4;
+        }
+        LogLevelW('\x02',(ushort *)L"Error trying to get the file version info. hr = 0x%08X",
+                  (ulonglong)uVar11);
+        uVar17 = (ulonglong)uVar11;
+      }
+      else {
+        BVar5 = VerQueryValueW(lpData,L"\\VarFileInfo\\Translation",&local_2e8,local_2f0);
+        puVar13 = local_2f4;
+        if (BVar5 != 0) {
+          puVar13 = local_2e8;
+        }
+        local_2e8 = puVar13;
+        if (puVar13 != (ushort *)0x0) {
+          swprintf_s(local_248,0xfe,L"\\StringFileInfo\\%04x%04x\\OriginalFilename",
+                     (ulonglong)*puVar13);
+          BVar5 = VerQueryValueW(lpData,local_248,&local_2e0,local_2f0);
+          if (BVar5 == 0) {
+            LogLevelW('\x02',(ushort *)L"The original file name could not be retrieved.");
+            uVar17 = 0x80004005;
+          }
+          else if (local_2e0 != (LPVOID)0x0) {
+            paVar8 = (allocator<unsigned_short> *)&local_2a8;
+            if (7 < uStack_290) {
+              paVar8 = local_2a8;
+            }
+            iVar6 = _o__wcsicmp(paVar8);
+            *local_2d8 = iVar6 == 0;
+            uVar17 = 0;
+            if (iVar6 != 0) {
+              paVar8 = (allocator<unsigned_short> *)&local_2a8;
+              if (7 < uStack_290) {
+                paVar8 = local_2a8;
+              }
+              LogLevelW('\x02',(ushort *)L"Expected: %ws Found: %ws",paVar8,local_2e0);
+            }
+          }
+        }
+      }
+      uVar11 = (uint)uVar17;
+      LocalFree(lpData);
+    }
+  }
+  else {
+LAB_180011151:
+    LogLevelW('\x02',(ushort *)L"Caller passed library name that did not end in \"dll\".");
+    uVar11 = 0x80070057;
+  }
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)local_288);
+LAB_18001116e:
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)&local_2a8);
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)local_2c8);
+  return uVar11;
+}
+

```


## WaasMedic::GetSha256HashOfString

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|GetSha256HashOfString|
|fullname|WaasMedic::GetSha256HashOfString|
|refcount|2|
|length|760|
|called|<details><summary>Expand for full list:<br>BCRYPT.DLL::BCryptCloseAlgorithmProvider<br>BCRYPT.DLL::BCryptCreateHash<br>BCRYPT.DLL::BCryptDestroyHash<br>BCRYPT.DLL::BCryptFinishHash<br>BCRYPT.DLL::BCryptGetProperty<br>BCRYPT.DLL::BCryptHashData<br>BCRYPT.DLL::BCryptOpenAlgorithmProvider<br>LogLevelW<br>StringCchPrintfW<br>WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS<br>WaasMedic::SafeAlloc</summary>WaasMedic::SafeFree<br>__security_check_cookie<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_></details>|
|calling|WaasMedic::CSandboxRpcWrapper::CreateSandbox|
|paramcount|2|
|address|1800113e8|
|sig|long __cdecl GetSha256HashOfString(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> param_1, basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_> * param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- WaasMedic::GetSha256HashOfString
+++ WaasMedic::GetSha256HashOfString
@@ -0,0 +1,176 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* long __cdecl WaasMedic::GetSha256HashOfString(class std::basic_string<unsigned short,struct
+   std::char_traits<unsigned short>,class std::allocator<unsigned short> >,class
+   std::basic_string<unsigned short,struct std::char_traits<unsigned short>,class
+   std::allocator<unsigned short> > & __ptr64) */
+
+long __cdecl
+WaasMedic::GetSha256HashOfString
+          (basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+           *param_1,
+          basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+          *param_2)
+
+{
+  NTSTATUS NVar1;
+  uint uVar2;
+  PUCHAR pUVar3;
+  ushort *puVar4;
+  basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+  *pbVar5;
+  undefined1 uVar6;
+  wchar_t *pwVar7;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  *pbInput;
+  PUCHAR pUVar8;
+  PUCHAR pUVar9;
+  ulonglong uVar10;
+  PUCHAR pbOutput;
+  ushort *puVar11;
+  undefined1 auStackY_e8 [32];
+  uint local_a8;
+  uint local_a4;
+  ULONG local_a0 [2];
+  BCRYPT_ALG_HANDLE local_98;
+  BCRYPT_HASH_HANDLE local_90;
+  PUCHAR local_88;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  *local_80;
+  undefined8 local_78;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  *local_70;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  local_68 [32];
+  ulonglong local_48;
+  
+  local_78 = 0xfffffffffffffffe;
+  local_48 = __security_cookie ^ (ulonglong)auStackY_e8;
+  pUVar9 = (PUCHAR)0x0;
+  uVar2 = 0;
+  local_98 = (BCRYPT_HANDLE)0x0;
+  local_90 = (BCRYPT_HASH_HANDLE)0x0;
+  local_a4 = 0;
+  pbOutput = (PUCHAR)0x0;
+  local_a8 = 0;
+  local_a0[0] = 0;
+  local_80 = param_2;
+  local_70 = param_1;
+  NVar1 = BCryptOpenAlgorithmProvider(&local_98,L"SHA256",(LPCWSTR)0x0,0);
+  pUVar3 = pUVar9;
+  if (NVar1 == 0) {
+    uVar6 = 0xc0;
+    NVar1 = BCryptGetProperty(local_98,L"ObjectLength",(PUCHAR)&local_a4,4,local_a0,0);
+    if (NVar1 != 0) {
+LAB_1800114b4:
+      uVar2 = MiscUtil::HRESULT_FROM_NTSTATUS(NVar1);
+      pwVar7 = L"BCryptGetProperty failed. Error code: 0x%08x";
+      goto LAB_180011471;
+    }
+    pUVar3 = SafeAlloc((ulonglong)local_a4,(bool)uVar6);
+    local_88 = pUVar3;
+    if (pUVar3 == (PUCHAR)0x0) {
+      uVar10 = 0x8007000e;
+      uVar2 = 0x8007000e;
+      pwVar7 = L"Allocation of hash object failed. Error code: 0x%08x";
+      pbOutput = pUVar9;
+    }
+    else {
+      uVar6 = 0xb0;
+      NVar1 = BCryptGetProperty(local_98,L"HashDigestLength",(PUCHAR)&local_a8,4,local_a0,0);
+      if (NVar1 != 0) goto LAB_1800114b4;
+      pbOutput = SafeAlloc((ulonglong)local_a8,(bool)uVar6);
+      if (pbOutput != (PUCHAR)0x0) {
+        NVar1 = BCryptCreateHash(local_98,&local_90,pUVar3,local_a4,(PUCHAR)0x0,0,0);
+        if (NVar1 == 0) {
+          pbInput = param_1;
+          if (7 < *(ulonglong *)(param_1 + 0x18)) {
+            pbInput = *(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                        **)param_1;
+          }
+          NVar1 = BCryptHashData(local_90,(PUCHAR)pbInput,(int)*(undefined8 *)(param_1 + 0x10) * 2,0
+                                );
+          if ((NVar1 == 0) &&
+             (pUVar8 = pbOutput, NVar1 = BCryptFinishHash(local_90,pbOutput,local_a8,0), NVar1 == 0)
+             ) {
+            puVar4 = SafeAlloc((ulonglong)(local_a8 * 2 + 1) * 2,SUB81(pUVar8,0));
+            if (puVar4 != (ushort *)0x0) {
+              puVar11 = puVar4;
+              if (local_a8 != 0) {
+                do {
+                  uVar2 = StringCchPrintfW(puVar11,3,(ushort *)L"%02x",
+                                           (ulonglong)pUVar9[(longlong)pbOutput]);
+                  if ((int)uVar2 < 0) {
+                    LogLevelW('\x02',(ushort *)
+                                     L"Failed to write bytes to the allocated string. Error code: 0x%08x"
+                              ,(ulonglong)uVar2);
+                    pUVar3 = local_88;
+                    goto LAB_18001164f;
+                  }
+                  pUVar9 = pUVar9 + 1;
+                  puVar11 = puVar11 + 2;
+                } while (pUVar9 < (PUCHAR)(ulonglong)local_a8);
+              }
+              pbVar5 = (basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+                        *)std::
+                          basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                          ::
+                          basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                                    (local_68,puVar4);
+              std::
+              basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              ::operator=(local_80,pbVar5);
+              std::
+              basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              ::
+              ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                        (local_68);
+              pUVar3 = local_88;
+              goto LAB_18001164f;
+            }
+            uVar10 = 0x8007000e;
+            uVar2 = 0x8007000e;
+            pwVar7 = L"Allocation of string failed. Error code: 0x%08x";
+            goto LAB_180011476;
+          }
+        }
+        uVar2 = MiscUtil::HRESULT_FROM_NTSTATUS(NVar1);
+        pwVar7 = L"BCryptCreateHash failed. Error code: 0x%08x";
+        goto LAB_180011471;
+      }
+      uVar10 = 0x8007000e;
+      uVar2 = 0x8007000e;
+      pwVar7 = L"Allocation of byte array for hash failed. Error code: 0x%08x";
+    }
+  }
+  else {
+    uVar2 = MiscUtil::HRESULT_FROM_NTSTATUS(NVar1);
+    pwVar7 = L"BCryptOpenAlgorithmProvider failed. Error code: 0x%08x";
+    pbOutput = pUVar9;
+LAB_180011471:
+    uVar10 = (ulonglong)uVar2;
+  }
+LAB_180011476:
+  LogLevelW('\x02',(ushort *)pwVar7,uVar10);
+LAB_18001164f:
+  if (local_98 != (BCRYPT_ALG_HANDLE)0x0) {
+    BCryptCloseAlgorithmProvider(local_98,0);
+  }
+  if (local_90 != (BCRYPT_HASH_HANDLE)0x0) {
+    BCryptDestroyHash(local_90);
+  }
+  if (pUVar3 != (PUCHAR)0x0) {
+    SafeFree(pUVar3);
+  }
+  if (pbOutput != (PUCHAR)0x0) {
+    SafeFree(pbOutput);
+  }
+  if (NVar1 < 0) {
+    uVar2 = MiscUtil::HRESULT_FROM_NTSTATUS(NVar1);
+  }
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            (param_1);
+  return uVar2;
+}
+

```


## std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|find_last_of|
|fullname|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of|
|refcount|2|
|length|296|
|called|__security_check_cookie<br>memset|
|calling|WaasMedic::ValidateOriginalFileName|
|paramcount|3|
|address|180011794|
|sig|__uint64 __thiscall find_last_of(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this, ushort * param_1, __uint64 param_2)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of
+++ std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of
@@ -0,0 +1,80 @@
+
+/* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
+/* public: unsigned __int64 __cdecl std::basic_string<unsigned short,struct
+   std::char_traits<unsigned short>,class std::allocator<unsigned short> >::find_last_of(unsigned
+   short const * __ptr64 const,unsigned __int64)const __ptr64 */
+
+__uint64 __thiscall
+std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::
+find_last_of(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+             *this,ushort *param_1,__uint64 param_2)
+
+{
+  wchar_t wVar1;
+  longlong lVar2;
+  wchar_t *pwVar3;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  *pbVar4;
+  longlong lVar5;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  *pbVar6;
+  undefined1 auStack_138 [32];
+  char local_118 [256];
+  ulonglong local_18;
+  
+  local_18 = __security_cookie ^ (ulonglong)auStack_138;
+  pbVar6 = this;
+  if (7 < *(ulonglong *)(this + 0x18)) {
+    pbVar6 = *(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+               **)this;
+  }
+  lVar5 = *(longlong *)(this + 0x10);
+  if (lVar5 == 0) {
+    return 0xffffffffffffffff;
+  }
+  memset(local_118,0,0x100);
+  pwVar3 = L"/\\";
+  do {
+    if (0xff < (ushort)*pwVar3) {
+      lVar2 = -1;
+      if (lVar5 + -1 != -1) {
+        lVar2 = lVar5 + -1;
+      }
+      pbVar4 = pbVar6 + lVar2 * 2;
+      goto LAB_180011857;
+    }
+    wVar1 = *pwVar3;
+    pwVar3 = pwVar3 + 1;
+    local_118[(byte)wVar1] = '\x01';
+  } while (pwVar3 != L"");
+  lVar2 = -1;
+  if (lVar5 + -1 != -1) {
+    lVar2 = lVar5 + -1;
+  }
+  pbVar4 = pbVar6 + lVar2 * 2;
+  while ((0xff < (ushort)*(wchar_t *)pbVar4 || (local_118[(ushort)*(wchar_t *)pbVar4] == '\0'))) {
+    if (pbVar4 == pbVar6) {
+      return 0xffffffffffffffff;
+    }
+    pbVar4 = pbVar4 + -2;
+  }
+LAB_180011885:
+  return (longlong)pbVar4 - (longlong)pbVar6 >> 1;
+LAB_180011857:
+  pwVar3 = L"/\\";
+  lVar5 = 2;
+  do {
+    if (*pwVar3 == *(wchar_t *)pbVar4) goto LAB_180011876;
+    pwVar3 = pwVar3 + 1;
+    lVar5 = lVar5 + -1;
+  } while (lVar5 != 0);
+  pwVar3 = (wchar_t *)0x0;
+LAB_180011876:
+  if (pwVar3 != (wchar_t *)0x0) goto LAB_180011885;
+  if (pbVar4 == pbVar6) {
+    return 0xffffffffffffffff;
+  }
+  pbVar4 = pbVar4 + -2;
+  goto LAB_180011857;
+}
+

```


## std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|operator=|
|fullname|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=|
|refcount|4|
|length|142|
|called|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn<br>operator_delete[]|
|calling|WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString<br>WaasMedic::ValidateOriginalFileName|
|paramcount|2|
|address|1800118d4|
|sig|basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_> * __thiscall operator=(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this, basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_> * param_1)|
|sym_type|Function|
|sym_source|ANALYSIS|
|external|False|


```diff
--- std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=
+++ std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=
@@ -0,0 +1,58 @@
+
+/* public: class std::basic_string<unsigned short,struct std::char_traits<unsigned short>,class
+   std::allocator<unsigned short> > & __ptr64 __cdecl std::basic_string<unsigned short,struct
+   std::char_traits<unsigned short>,class std::allocator<unsigned short> >::operator=(class
+   std::basic_string<unsigned short,struct std::char_traits<unsigned short>,class
+   std::allocator<unsigned short> > && __ptr64) __ptr64 */
+
+basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+* __thiscall
+std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::
+operator=(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+          *this,basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+                *param_1)
+
+{
+  longlong lVar1;
+  void *pvVar2;
+  code *pcVar3;
+  undefined8 uVar4;
+  basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+  *pbVar5;
+  void *pvVar6;
+  
+  if (this != (basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+               *)param_1) {
+    if (7 < *(ulonglong *)(this + 0x18)) {
+      pvVar2 = *(void **)this;
+      lVar1 = *(ulonglong *)(this + 0x18) * 2;
+      pvVar6 = pvVar2;
+      if (0xfff < lVar1 + 2U) {
+        pvVar6 = *(void **)((longlong)pvVar2 + -8);
+        if (0x1f < ((longlong)pvVar2 - (longlong)pvVar6) - 8U) {
+          _o__invalid_parameter_noinfo_noreturn((longlong)pvVar2 - (longlong)pvVar6,lVar1 + 0x29);
+          pcVar3 = (code *)swi(3);
+          pbVar5 = (basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+                    *)(*pcVar3)();
+          return pbVar5;
+        }
+      }
+      operator_delete__(pvVar6);
+    }
+    *(undefined8 *)(this + 0x10) = 0;
+    *(undefined8 *)(this + 0x18) = 7;
+    *(undefined2 *)this = 0;
+    uVar4 = *(undefined8 *)(param_1 + 8);
+    *(undefined8 *)this = *(undefined8 *)param_1;
+    *(undefined8 *)(this + 8) = uVar4;
+    uVar4 = *(undefined8 *)(param_1 + 0x18);
+    *(undefined8 *)(this + 0x10) = *(undefined8 *)(param_1 + 0x10);
+    *(undefined8 *)(this + 0x18) = uVar4;
+    *(undefined8 *)(param_1 + 0x10) = 0;
+    *(undefined8 *)(param_1 + 0x18) = 7;
+    *(undefined2 *)param_1 = 0;
+  }
+  return (basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_>
+          *)this;
+}
+

```


## swprintf_s

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|swprintf_s|
|fullname|swprintf_s|
|refcount|2|
|length|82|
|called|__local_stdio_printf_options<br>_o___stdio_common_vswprintf_s|
|calling|WaasMedic::ValidateOriginalFileName|
|paramcount|3|
|address|18002e73c|
|sig|int __cdecl swprintf_s(wchar_t * _Dst, size_t _SizeInWords, wchar_t * _Format, ...)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- swprintf_s
+++ swprintf_s
@@ -0,0 +1,18 @@
+
+int __cdecl swprintf_s(wchar_t *_Dst,size_t _SizeInWords,wchar_t *_Format,...)
+
+{
+  int iVar1;
+  __uint64 *p_Var2;
+  undefined8 in_R9;
+  undefined8 local_res20;
+  
+  local_res20 = in_R9;
+  p_Var2 = __local_stdio_printf_options();
+  iVar1 = _o___stdio_common_vswprintf_s(*p_Var2,_Dst,_SizeInWords,_Format,0,&local_res20);
+  if (iVar1 < 0) {
+    iVar1 = -1;
+  }
+  return iVar1;
+}
+

```


## `WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor$0

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|dtor$0|
|fullname|`WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor$0|
|refcount|1|
|length|12|
|called|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling||
|paramcount|2|
|address|18002f7ef|
|sig|undefined __fastcall dtor$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor$0
+++ `WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor$0
@@ -0,0 +1,11 @@
+
+void `WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor_0(undefined8 param_1,longlong param_2)
+
+{
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)(param_2 + 0x28));
+  return;
+}
+

```


## `WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor$0

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|dtor$0|
|fullname|`WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor$0|
|refcount|1|
|length|12|
|called|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling||
|paramcount|2|
|address|18002f837|
|sig|undefined __fastcall dtor$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor$0
+++ `WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor$0
@@ -0,0 +1,12 @@
+
+void `WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor_0
+               (undefined8 param_1,longlong param_2)
+
+{
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)(param_2 + 0x110));
+  return;
+}
+

```


## `WaasMedic::GetRandomString'::__l1::dtor$0

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|dtor$0|
|fullname|`WaasMedic::GetRandomString'::__l1::dtor$0|
|refcount|1|
|length|12|
|called|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling||
|paramcount|2|
|address|18002f85b|
|sig|undefined __fastcall dtor$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `WaasMedic::GetRandomString'::__l1::dtor$0
+++ `WaasMedic::GetRandomString'::__l1::dtor$0
@@ -0,0 +1,11 @@
+
+void `WaasMedic::GetRandomString'::__l1::dtor_0(undefined8 param_1,longlong param_2)
+
+{
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)(param_2 + 0x30));
+  return;
+}
+

```


## `WaasMedic::ValidateOriginalFileName'::__l1::dtor$1

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|dtor$1|
|fullname|`WaasMedic::ValidateOriginalFileName'::__l1::dtor$1|
|refcount|1|
|length|12|
|called|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling||
|paramcount|2|
|address|18002f86d|
|sig|undefined __fastcall dtor$1(undefined8 param_1, longlong param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `WaasMedic::ValidateOriginalFileName'::__l1::dtor$1
+++ `WaasMedic::ValidateOriginalFileName'::__l1::dtor$1
@@ -0,0 +1,11 @@
+
+void `WaasMedic::ValidateOriginalFileName'::__l1::dtor_1(undefined8 param_1,longlong param_2)
+
+{
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)(param_2 + 0x80));
+  return;
+}
+

```


## `WaasMedic::GetSha256HashOfString'::__l1::dtor$0

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|dtor$0|
|fullname|`WaasMedic::GetSha256HashOfString'::__l1::dtor$0|
|refcount|1|
|length|12|
|called|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling||
|paramcount|2|
|address|18002f891|
|sig|undefined __fastcall dtor$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|False|


```diff
--- `WaasMedic::GetSha256HashOfString'::__l1::dtor$0
+++ `WaasMedic::GetSha256HashOfString'::__l1::dtor$0
@@ -0,0 +1,11 @@
+
+void `WaasMedic::GetSha256HashOfString'::__l1::dtor_0(undefined8 param_1,longlong param_2)
+
+{
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            (*(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+               **)(param_2 + 0x78));
+  return;
+}
+

```


## API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o_tolower

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|_o_tolower|
|fullname|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o_tolower|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::ValidateOriginalFileName|
|paramcount|0|
|address|EXTERNAL:00000016|
|sig|undefined _o_tolower(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o_tolower*
## API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o___stdio_common_vswprintf_s

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|_o___stdio_common_vswprintf_s|
|fullname|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o___stdio_common_vswprintf_s|
|refcount|3|
|length|0|
|called||
|calling||
|paramcount|0|
|address|EXTERNAL:00000024|
|sig|undefined _o___stdio_common_vswprintf_s(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o___stdio_common_vswprintf_s*
## BCRYPT.DLL::BCryptCreateHash

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptCreateHash|
|fullname|BCRYPT.DLL::BCryptCreateHash|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::GetSha256HashOfString|
|paramcount|7|
|address|EXTERNAL:000000c2|
|sig|NTSTATUS __stdcall BCryptCreateHash(BCRYPT_ALG_HANDLE hAlgorithm, BCRYPT_HASH_HANDLE * phHash, PUCHAR pbHashObject, ULONG cbHashObject, PUCHAR pbSecret, ULONG cbSecret, ULONG dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptCreateHash*
## API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoExW

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|GetFileVersionInfoExW|
|fullname|API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoExW|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::ValidateOriginalFileName|
|paramcount|5|
|address|EXTERNAL:000000ca|
|sig|BOOL __stdcall GetFileVersionInfoExW(DWORD dwFlags, LPCWSTR lpwstrFilename, DWORD dwHandle, DWORD dwLen, LPVOID lpData)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoExW*
## API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoSizeExW

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|GetFileVersionInfoSizeExW|
|fullname|API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoSizeExW|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::ValidateOriginalFileName|
|paramcount|3|
|address|EXTERNAL:000000c9|
|sig|DWORD __stdcall GetFileVersionInfoSizeExW(DWORD dwFlags, LPCWSTR lpwstrFilename, LPDWORD lpdwHandle)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CORE-VERSION-L1-1-0.DLL::GetFileVersionInfoSizeExW*
## BCRYPT.DLL::BCryptGetProperty

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptGetProperty|
|fullname|BCRYPT.DLL::BCryptGetProperty|
|refcount|3|
|length|0|
|called||
|calling|WaasMedic::GetSha256HashOfString|
|paramcount|6|
|address|EXTERNAL:000000c8|
|sig|NTSTATUS __stdcall BCryptGetProperty(BCRYPT_HANDLE hObject, LPCWSTR pszProperty, PUCHAR pbOutput, ULONG cbOutput, ULONG * pcbResult, ULONG dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptGetProperty*
## BCRYPT.DLL::BCryptCloseAlgorithmProvider

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptCloseAlgorithmProvider|
|fullname|BCRYPT.DLL::BCryptCloseAlgorithmProvider|
|refcount|3|
|length|0|
|called||
|calling|WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString|
|paramcount|2|
|address|EXTERNAL:000000c4|
|sig|NTSTATUS __stdcall BCryptCloseAlgorithmProvider(BCRYPT_ALG_HANDLE hAlgorithm, ULONG dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptCloseAlgorithmProvider*
## BCRYPT.DLL::BCryptOpenAlgorithmProvider

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptOpenAlgorithmProvider|
|fullname|BCRYPT.DLL::BCryptOpenAlgorithmProvider|
|refcount|3|
|length|0|
|called||
|calling|WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString|
|paramcount|4|
|address|EXTERNAL:000000c6|
|sig|NTSTATUS __stdcall BCryptOpenAlgorithmProvider(BCRYPT_ALG_HANDLE * phAlgorithm, LPCWSTR pszAlgId, LPCWSTR pszImplementation, ULONG dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptOpenAlgorithmProvider*
## BCRYPT.DLL::BCryptHashData

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptHashData|
|fullname|BCRYPT.DLL::BCryptHashData|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::GetSha256HashOfString|
|paramcount|4|
|address|EXTERNAL:000000c1|
|sig|NTSTATUS __stdcall BCryptHashData(BCRYPT_HASH_HANDLE hHash, PUCHAR pbInput, ULONG cbInput, ULONG dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptHashData*
## NTDLL.DLL::NtQuerySystemInformation

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|NtQuerySystemInformation|
|fullname|NTDLL.DLL::NtQuerySystemInformation|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::CWaasRemediation::LoadPluginLibrary|
|paramcount|0|
|address|EXTERNAL:00000036|
|sig|undefined NtQuerySystemInformation(void)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for NTDLL.DLL::NtQuerySystemInformation*
## BCRYPT.DLL::BCryptDestroyHash

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptDestroyHash|
|fullname|BCRYPT.DLL::BCryptDestroyHash|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::GetSha256HashOfString|
|paramcount|1|
|address|EXTERNAL:000000c5|
|sig|NTSTATUS __stdcall BCryptDestroyHash(BCRYPT_HASH_HANDLE hHash)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptDestroyHash*
## BCRYPT.DLL::BCryptGenRandom

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptGenRandom|
|fullname|BCRYPT.DLL::BCryptGenRandom|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::GetRandomString|
|paramcount|4|
|address|EXTERNAL:000000c7|
|sig|NTSTATUS __stdcall BCryptGenRandom(BCRYPT_ALG_HANDLE hAlgorithm, PUCHAR pbBuffer, ULONG cbBuffer, ULONG dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptGenRandom*
## API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::LoadLibraryExW

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|LoadLibraryExW|
|fullname|API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::LoadLibraryExW|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::CWaasRemediation::LoadPluginLibrary|
|paramcount|3|
|address|EXTERNAL:0000003c|
|sig|HMODULE __stdcall LoadLibraryExW(LPCWSTR lpLibFileName, HANDLE hFile, DWORD dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::LoadLibraryExW*
## BCRYPT.DLL::BCryptFinishHash

### Function Meta



|Key|waasmedicsvc-2020-01.dll|
| :---: | :---: |
|name|BCryptFinishHash|
|fullname|BCRYPT.DLL::BCryptFinishHash|
|refcount|2|
|length|0|
|called||
|calling|WaasMedic::GetSha256HashOfString|
|paramcount|4|
|address|EXTERNAL:000000c3|
|sig|NTSTATUS __stdcall BCryptFinishHash(BCRYPT_HASH_HANDLE hHash, PUCHAR pbOutput, ULONG cbOutput, ULONG dwFlags)|
|sym_type|Function|
|sym_source|IMPORTED|
|external|True|


*No code available for BCRYPT.DLL::BCryptFinishHash*
# Modified


*Modified functions contain code changes*
## WaasMedic::CSandboxRpcWrapper::CreateSandbox

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.28|
|i_ratio|0.29|
|m_ratio|0.96|
|b_ratio|0.84|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|CreateSandbox|CreateSandbox|
|fullname|WaasMedic::CSandboxRpcWrapper::CreateSandbox|WaasMedic::CSandboxRpcWrapper::CreateSandbox|
|refcount|2|2|
|`length`|581|638|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0.DLL::ExpandEnvironmentStringsW<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::CreateProcessW<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetExitCodeProcess<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObject<br>LogLevelW<br>WaasMedic::CSandboxRpcWrapper::SandBoxShutdown<br>__security_check_cookie<br>memset</summary></details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0.DLL::ExpandEnvironmentStringsW<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::CreateProcessW<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetExitCodeProcess<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexW<br>API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::WaitForSingleObject<br>LogLevelW<br>WaasMedic::CSandboxRpcWrapper::SandBoxShutdown<br>WaasMedic::GetSha256HashOfString<br>__security_check_cookie</summary>memset<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_></details>|
|calling|WaasMedic::CWaasRemediation::RunPluginsInCapsule|WaasMedic::CWaasRemediation::RunPluginsInCapsule|
|paramcount|1|1|
|`address`|18000c218|18000c2b0|
|sig|long __thiscall CreateSandbox(CSandboxRpcWrapper * this)|long __thiscall CreateSandbox(CSandboxRpcWrapper * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WaasMedic::CSandboxRpcWrapper::CreateSandbox Called Diff


```diff
--- WaasMedic::CSandboxRpcWrapper::CreateSandbox called
+++ WaasMedic::CSandboxRpcWrapper::CreateSandbox called
@@ -9,0 +10 @@
+WaasMedic::GetSha256HashOfString
@@ -11,0 +13,2 @@
+std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
```


### WaasMedic::CSandboxRpcWrapper::CreateSandbox Diff


```diff
--- WaasMedic::CSandboxRpcWrapper::CreateSandbox
+++ WaasMedic::CSandboxRpcWrapper::CreateSandbox
@@ -1,96 +1,124 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* public: long __cdecl WaasMedic::CSandboxRpcWrapper::CreateSandbox(void) __ptr64 */
 
 long __thiscall WaasMedic::CSandboxRpcWrapper::CreateSandbox(CSandboxRpcWrapper *this)
 
 {
   uint uVar1;
   DWORD DVar2;
   uint uVar3;
   BOOL BVar4;
-  HANDLE pvVar5;
-  wchar_t *pwVar6;
-  ulonglong uVar7;
-  undefined1 auStackY_308 [32];
-  DWORD local_2b8 [2];
-  _PROCESS_INFORMATION local_2b0;
-  _STARTUPINFOW local_298;
-  WCHAR local_228 [264];
-  ulonglong local_18;
+  undefined8 uVar5;
+  HANDLE pvVar6;
+  wchar_t *pwVar7;
+  WCHAR *lpName;
+  undefined1 auStackY_368 [32];
+  DWORD local_318 [2];
+  _PROCESS_INFORMATION local_310;
+  undefined8 local_2f8;
+  basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  local_2f0 [40];
+  _STARTUPINFOW local_2c8;
+  WCHAR local_258;
+  undefined6 uStack_256;
+  undefined8 local_248;
+  ulonglong uStack_240;
+  WCHAR local_238 [264];
+  ulonglong local_28;
   
-  local_18 = __security_cookie ^ (ulonglong)auStackY_308;
-  local_2b0.hProcess = (HANDLE)0x0;
-  uVar3 = 0;
-  local_2b0.hThread = (HANDLE)0x0;
-  local_2b0.dwProcessId = 0;
-  local_2b0.dwThreadId = 0;
+  local_2f8 = 0xfffffffffffffffe;
+  local_28 = __security_cookie ^ (ulonglong)auStackY_368;
+  local_310.hProcess = (HANDLE)0x0;
+  local_310.hThread = (HANDLE)0x0;
+  local_310.dwProcessId = 0;
+  local_310.dwThreadId = 0;
+  local_248 = 0;
+  uStack_240 = 7;
+  local_258 = L'\0';
   SandBoxShutdown(this);
   if (*(LPCWSTR *)(this + 8) == (LPCWSTR)0x0) {
-    uVar7 = 0x80004003;
-    pwVar6 = L"Sandbox is not initialized! hr = 0x%08x";
+    uVar3 = 0x80004003;
+    pwVar7 = L"Sandbox is not initialized! hr = 0x%08x";
   }
   else {
-    DVar2 = ExpandEnvironmentStringsW(*(LPCWSTR *)(this + 8),local_228,0x104);
+    DVar2 = ExpandEnvironmentStringsW(*(LPCWSTR *)(this + 8),local_238,0x104);
     if (DVar2 == 0) {
       DVar2 = GetLastError();
-      pwVar6 = L"Failed to expand WaaSMedicAgent command line.  Nothing copied! hr = 0x%08x";
       uVar3 = DVar2 & 0xffff | 0x80070000;
       if ((int)DVar2 < 1) {
         uVar3 = DVar2;
       }
-      uVar7 = (ulonglong)uVar3;
+      pwVar7 = L"Failed to expand WaaSMedicAgent command line.  Nothing copied! hr = 0x%08x";
     }
     else if (DVar2 < 0x105) {
-      memset(&local_298,0,0x68);
-      pvVar5 = CreateMutexW((LPSECURITY_ATTRIBUTES)0x0,1,*(LPCWSTR *)this);
-      if ((longlong)*(HANDLE *)(this + 0x18) - 1U < 0xfffffffffffffffe) {
-        CloseHandle(*(HANDLE *)(this + 0x18));
+      memset(&local_2c8,0,0x68);
+      uVar5 = std::
+              basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              ::
+              basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                        (local_2f0,*(ushort **)this);
+      uVar3 = GetSha256HashOfString(uVar5,&local_258);
+      if ((int)uVar3 < 0) {
+        pwVar7 = L"Failed to determine mutex name. hr = 0x%08x.";
       }
-      *(HANDLE *)(this + 0x18) = pvVar5;
-      if (pvVar5 == (HANDLE)0x0) {
+      else {
+        lpName = &local_258;
+        if (7 < uStack_240) {
+          lpName = (LPCWSTR)CONCAT62(uStack_256,local_258);
+        }
+        pvVar6 = CreateMutexW((LPSECURITY_ATTRIBUTES)0x0,1,lpName);
+        if ((longlong)*(HANDLE *)(this + 0x18) - 1U < 0xfffffffffffffffe) {
+          CloseHandle(*(HANDLE *)(this + 0x18));
+        }
+        *(HANDLE *)(this + 0x18) = pvVar6;
+        if (pvVar6 == (HANDLE)0x0) {
+          DVar2 = GetLastError();
+          uVar1 = DVar2 & 0xffff | 0x80070000;
+          if ((int)DVar2 < 1) {
+            uVar1 = DVar2;
+          }
+          LogLevelW('\x03',(ushort *)L"CreateMutex failed.  name:%s, hr = 0x%08x",(ulonglong)uVar1);
+        }
+        BVar4 = CreateProcessW((LPCWSTR)0x0,local_238,(LPSECURITY_ATTRIBUTES)0x0,
+                               (LPSECURITY_ATTRIBUTES)0x0,0,0x8000000,(LPVOID)0x0,(LPCWSTR)0x0,
+                               &local_2c8,&local_310);
+        if (BVar4 != 0) {
+          WaitForSingleObject(local_310.hProcess,5000);
+          local_318[0] = 0;
+          BVar4 = GetExitCodeProcess(local_310.hProcess,local_318);
+          if ((BVar4 != 0) &&
+             (LogLevelW('\x04',(ushort *)L"Exit code of sandbox: %d!",(ulonglong)local_318[0]),
+             local_318[0] != 0x103)) {
+            uVar3 = local_318[0] & 0xffff | 0x80010000;
+            if ((int)local_318[0] < 1) {
+              uVar3 = local_318[0];
+            }
+            LogLevelW('\x02',(ushort *)L"Sandbox process died.");
+          }
+          CloseHandle(local_310.hProcess);
+          CloseHandle(local_310.hThread);
+          goto LAB_0;
+        }
         DVar2 = GetLastError();
-        uVar1 = DVar2 & 0xffff | 0x80070000;
+        uVar3 = DVar2 & 0xffff | 0x80070000;
         if ((int)DVar2 < 1) {
-          uVar1 = DVar2;
+          uVar3 = DVar2;
         }
-        LogLevelW('\x03',(ushort *)L"CreateMutex failed.  name:%s, hr = 0x%08x",(ulonglong)uVar1);
+        pwVar7 = L"CreateProcessW failed. hr = 0x%08x";
       }
-      LogLevelW('\x04',(ushort *)L"Creating Process: %s",local_228);
-      BVar4 = CreateProcessW((LPCWSTR)0x0,local_228,(LPSECURITY_ATTRIBUTES)0x0,
-                             (LPSECURITY_ATTRIBUTES)0x0,0,0x8000000,(LPVOID)0x0,(LPCWSTR)0x0,
-                             &local_298,&local_2b0);
-      if (BVar4 != 0) {
-        WaitForSingleObject(local_2b0.hProcess,5000);
-        local_2b8[0] = 0;
-        BVar4 = GetExitCodeProcess(local_2b0.hProcess,local_2b8);
-        if ((BVar4 != 0) &&
-           (LogLevelW('\x04',(ushort *)L"Exit code of sandbox: %d!",(ulonglong)local_2b8[0]),
-           local_2b8[0] != 0x103)) {
-          uVar3 = local_2b8[0] & 0xffff | 0x80010000;
-          if ((int)local_2b8[0] < 1) {
-            uVar3 = local_2b8[0];
-          }
-          LogLevelW('\x02',(ushort *)L"Sandbox process died.");
-        }
-        CloseHandle(local_2b0.hProcess);
-        CloseHandle(local_2b0.hThread);
-        return uVar3;
-      }
-      DVar2 = GetLastError();
-      pwVar6 = L"CreateProcessW failed. hr = 0x%08x";
-      uVar3 = DVar2 & 0xffff | 0x80070000;
-      if ((int)DVar2 < 1) {
-        uVar3 = DVar2;
-      }
-      uVar7 = (ulonglong)uVar3;
     }
     else {
-      uVar7 = 0x8007007a;
-      pwVar6 = L"Failed to expand WaaSMedicAgent command line! hr = 0x%08x";
+      uVar3 = 0x8007007a;
+      pwVar7 = L"Failed to expand WaaSMedicAgent command line! hr = 0x%08x";
     }
   }
-  LogLevelW('\x02',(ushort *)pwVar6,uVar7);
-  return (long)uVar7;
+  LogLevelW('\x02',(ushort *)pwVar7,(ulonglong)uVar3);
+LAB_0:
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)&local_258);
+  return uVar3;
 }
 

```


## WaasMedic::CWaasRemediation::LoadPluginLibrary

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|code,length,called|
|ratio|0.69|
|i_ratio|0.61|
|m_ratio|0.92|
|b_ratio|0.89|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|LoadPluginLibrary|LoadPluginLibrary|
|fullname|WaasMedic::CWaasRemediation::LoadPluginLibrary|WaasMedic::CWaasRemediation::LoadPluginLibrary|
|refcount|3|3|
|`length`|429|505|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-FILE-L1-1-0.DLL::CreateFileW<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-1.DLL::LoadLibraryW<br>API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0.DLL::ExpandEnvironmentStringsW<br>LogLevelW<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::IsTrustedLibrary<br>__security_check_cookie|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-FILE-L1-1-0.DLL::CreateFileW<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::LoadLibraryExW<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-1.DLL::LoadLibraryW<br>API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0.DLL::ExpandEnvironmentStringsW<br>LogLevelW<br>NTDLL.DLL::NtQuerySystemInformation<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::IsTrustedLibrary<br>__security_check_cookie</summary></details>|
|calling|WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx|WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx|
|paramcount|2|2|
|address|1800089f8|1800089f8|
|sig|long __thiscall LoadPluginLibrary(CWaasRemediation * this, ushort * param_1)|long __thiscall LoadPluginLibrary(CWaasRemediation * this, ushort * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WaasMedic::CWaasRemediation::LoadPluginLibrary Called Diff


```diff
--- WaasMedic::CWaasRemediation::LoadPluginLibrary called
+++ WaasMedic::CWaasRemediation::LoadPluginLibrary called
@@ -3,0 +4 @@
+API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::LoadLibraryExW
@@ -6,0 +8 @@
+NTDLL.DLL::NtQuerySystemInformation
```


### WaasMedic::CWaasRemediation::LoadPluginLibrary Diff


```diff
--- WaasMedic::CWaasRemediation::LoadPluginLibrary
+++ WaasMedic::CWaasRemediation::LoadPluginLibrary
@@ -1,77 +1,90 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* private: long __cdecl WaasMedic::CWaasRemediation::LoadPluginLibrary(unsigned short const *
    __ptr64) __ptr64 */
 
 long __thiscall
 WaasMedic::CWaasRemediation::LoadPluginLibrary(CWaasRemediation *this,ushort *param_1)
 
 {
   DWORD DVar1;
   uint uVar2;
+  int iVar3;
   HANDLE hObject;
-  HMODULE pHVar3;
-  ulonglong uVar4;
-  undefined1 auStackY_278 [32];
-  WCHAR local_228 [264];
-  ulonglong local_18;
+  HMODULE pHVar4;
+  ulonglong uVar5;
+  undefined1 auStackY_288 [32];
+  HANDLE local_248;
+  undefined8 local_240;
+  WCHAR local_238 [264];
+  ulonglong local_28;
   
-  local_18 = __security_cookie ^ (ulonglong)auStackY_278;
+  local_240 = 0xfffffffffffffffe;
+  local_28 = __security_cookie ^ (ulonglong)auStackY_288;
   uVar2 = 0;
   hObject = (HANDLE)0x0;
-  DVar1 = ExpandEnvironmentStringsW((LPCWSTR)param_1,local_228,0x104);
+  local_248 = (HANDLE)0x0;
+  DVar1 = ExpandEnvironmentStringsW((LPCWSTR)param_1,local_238,0x104);
   if (DVar1 == 0) {
     DVar1 = GetLastError();
     uVar2 = DVar1 & 0xffff | 0x80070000;
     if ((int)DVar1 < 1) {
       uVar2 = DVar1;
     }
 LAB_0:
     if ((int)uVar2 < 0) goto LAB_1;
   }
   else if (0x104 < DVar1) {
     uVar2 = 0x8007007a;
     goto LAB_0;
   }
   if (*(longlong *)(this + 0x48) != 0) {
     uVar2 = FreePluginLibrary(this);
   }
   if (-1 < (int)uVar2) {
-    hObject = CreateFileW(local_228,0x80000000,1,(LPSECURITY_ATTRIBUTES)0x0,3,0x80,(HANDLE)0x0);
+    hObject = CreateFileW(local_238,0x80000000,1,(LPSECURITY_ATTRIBUTES)0x0,3,0x80,(HANDLE)0x0);
+    local_248 = hObject;
     if (((longlong)hObject + 1U & 0xfffffffffffffffe) == 0) {
       DVar1 = GetLastError();
       uVar2 = DVar1 & 0xffff | 0x80070000;
       if ((int)DVar1 < 1) {
         uVar2 = DVar1;
       }
-      uVar4 = (ulonglong)uVar2;
+      uVar5 = (ulonglong)uVar2;
       if (-1 < (int)uVar2) {
-        uVar4 = 0x8007006e;
+        uVar5 = 0x8007006e;
       }
-      uVar2 = (uint)uVar4;
-      LogLevelW('\x02',(ushort *)L"CreateFile failed wih error: 0x%08x",uVar4);
+      uVar2 = (uint)uVar5;
+      LogLevelW('\x02',(ushort *)L"CreateFile failed wih error: 0x%08x",uVar5);
     }
-    if ((-1 < (int)uVar2) && (uVar2 = IsTrustedLibrary((ushort *)local_228), -1 < (int)uVar2)) {
-      pHVar3 = LoadLibraryW(local_228);
-      *(HMODULE *)(this + 0x48) = pHVar3;
-      if (pHVar3 == (HMODULE)0x0) {
+    if ((-1 < (int)uVar2) && (uVar2 = IsTrustedLibrary((ushort *)local_238), -1 < (int)uVar2)) {
+      local_248 = (HANDLE)0x8;
+      iVar3 = NtQuerySystemInformation(0x67,&local_248,8,0);
+      if ((iVar3 < 0) || (((ulonglong)local_248 & 0x200000000) == 0)) {
+        pHVar4 = LoadLibraryExW(local_238,(HANDLE)0x0,0x80);
+      }
+      else {
+        pHVar4 = LoadLibraryW(local_238);
+      }
+      *(HMODULE *)(this + 0x48) = pHVar4;
+      if (pHVar4 == (HMODULE)0x0) {
         DVar1 = GetLastError();
         uVar2 = DVar1 & 0xffff | 0x80070000;
         if ((int)DVar1 < 1) {
           uVar2 = DVar1;
         }
-        LogLevelW('\x02',(ushort *)L"Failed to load plugin library:%s.  hr=0x%08x",local_228,
+        LogLevelW('\x02',(ushort *)L"Failed to load plugin library:%s.  hr=0x%08x",local_238,
                   (ulonglong)uVar2);
       }
       else {
         LogLevelW('\x05',(ushort *)L"Library loaded.");
       }
     }
   }
 LAB_1:
   if ((longlong)hObject - 1U < 0xfffffffffffffffe) {
     CloseHandle(hObject);
   }
   return uVar2;
 }
 

```


## WaasMedic::IsTrustedLibrary

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.42|
|i_ratio|0.41|
|m_ratio|0.93|
|b_ratio|0.9|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|IsTrustedLibrary|IsTrustedLibrary|
|fullname|WaasMedic::IsTrustedLibrary|WaasMedic::IsTrustedLibrary|
|refcount|2|2|
|`length`|501|549|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-FILE-L1-1-0.DLL::CreateFileW<br>API-MS-WIN-CORE-FILE-L1-1-0.DLL::GetFileAttributesW<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>LogLevelW<br>WINTRUST.DLL::WTGetSignatureInfo<br>WaasMedic::TimeHelper::SyncSystemTime<br>memset|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-FILE-L1-1-0.DLL::CreateFileW<br>API-MS-WIN-CORE-FILE-L1-1-0.DLL::GetFileAttributesW<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>LogLevelW<br>WINTRUST.DLL::WTGetSignatureInfo<br>WaasMedic::TimeHelper::SyncSystemTime<br>WaasMedic::ValidateOriginalFileName<br>memset|
|calling|WaasMedic::CWaasRemediation::LoadPluginLibrary|WaasMedic::CWaasRemediation::LoadPluginLibrary|
|paramcount|1|1|
|`address`|180014abc|1800111bc|
|sig|long __cdecl IsTrustedLibrary(ushort * param_1)|long __cdecl IsTrustedLibrary(ushort * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WaasMedic::IsTrustedLibrary Called Diff


```diff
--- WaasMedic::IsTrustedLibrary called
+++ WaasMedic::IsTrustedLibrary called
@@ -7,0 +8 @@
+WaasMedic::ValidateOriginalFileName
```


### WaasMedic::IsTrustedLibrary Diff


```diff
--- WaasMedic::IsTrustedLibrary
+++ WaasMedic::IsTrustedLibrary
@@ -1,87 +1,105 @@
 
 /* long __cdecl WaasMedic::IsTrustedLibrary(unsigned short * __ptr64) */
 
 long __cdecl WaasMedic::IsTrustedLibrary(ushort *param_1)
 
 {
   DWORD DVar1;
   DWORD DVar2;
   HANDLE hObject;
   wchar_t *pwVar3;
   ulonglong uVar4;
+  bool local_res8 [8];
+  HANDLE local_res10;
   undefined4 uVar5;
-  undefined4 local_68;
-  int local_64 [20];
-  uint local_14;
+  undefined4 local_78;
+  int local_74;
+  uint local_24;
   
   hObject = (HANDLE)0x0;
+  uVar4 = 0;
   if (param_1 == (ushort *)0x0) {
-    DVar2 = 0x80004003;
+    uVar4 = 0x80004003;
+    DVar1 = 0x80004003;
 LAB_0:
-    uVar4 = (ulonglong)DVar2;
     pwVar3 = L"CheckIfFileExists failed for %s.  hr = 0x%08x";
   }
   else {
     DVar1 = GetFileAttributesW((LPCWSTR)param_1);
-    DVar2 = 0;
     if (DVar1 == 0xffffffff) {
       DVar1 = GetLastError();
-      DVar2 = DVar1 & 0xffff | 0x80070000;
+      uVar4 = (ulonglong)(DVar1 & 0xffff | 0x80070000);
       if ((int)DVar1 < 1) {
-        DVar2 = DVar1;
+        uVar4 = (ulonglong)DVar1;
       }
     }
-    if ((int)DVar2 < 0) goto LAB_0;
+    DVar1 = (DWORD)uVar4;
+    if ((int)DVar1 < 0) goto LAB_0;
     hObject = CreateFileW((LPCWSTR)param_1,0x80000000,1,(LPSECURITY_ATTRIBUTES)0x0,3,0x80,
                           (HANDLE)0x0);
+    local_res10 = hObject;
     if (hObject == (HANDLE)0xffffffffffffffff) {
-      DVar1 = GetLastError();
-      DVar2 = DVar1 & 0xffff | 0x80070000;
-      if ((int)DVar1 < 1) {
-        DVar2 = DVar1;
+      DVar2 = GetLastError();
+      DVar1 = DVar2 & 0xffff | 0x80070000;
+      if ((int)DVar2 < 1) {
+        DVar1 = DVar2;
       }
       goto LAB_1;
     }
-    memset(local_64,0,0x54);
-    local_68 = 0x58;
-    uVar5 = 0;
-    DVar2 = WTGetSignatureInfo(param_1,hObject,0x1803,&local_68,0,0);
-    if (-1 < (int)DVar2) {
-      if (local_64[0] == 2) {
-        LogLevelW('\x04',(ushort *)
-                         L"First try failed with \'SIGNATURE_STATE_UNSIGNED_POLICY\', retrying....")
-        ;
-        DVar2 = TimeHelper::SyncSystemTime();
-        if ((int)DVar2 < 0) goto LAB_1;
-        memset(local_64,0,0x54);
-        local_68 = 0x58;
-        uVar5 = 0;
-        DVar2 = WTGetSignatureInfo(param_1,hObject,0x1803,&local_68,0,0);
-        if ((int)DVar2 < 0) {
-          uVar4 = (ulonglong)DVar2;
-          pwVar3 = 
-          L"Could not establish trust with the requested library %s in retry. Error code was 0x%08x"
-          ;
-          goto LAB_2;
+    local_res8[0] = false;
+    DVar1 = ValidateOriginalFileName(param_1,local_res8);
+    if ((int)DVar1 < 0) {
+      uVar4 = (ulonglong)DVar1;
+      pwVar3 = 
+      L"An error occured while validating the original file name for %s. Error code was 0x%08x";
+    }
+    else if (local_res8[0] == false) {
+      DVar1 = 0x80070241;
+      uVar4 = 0x80070241;
+      pwVar3 = L"The file name does not match the original name.";
+    }
+    else {
+      memset(&local_78,0,0x58);
+      local_78 = 0x58;
+      uVar5 = 0;
+      DVar1 = WTGetSignatureInfo(param_1,hObject,0x1803,&local_78,0,0);
+      if (-1 < (int)DVar1) {
+        if (local_74 == 2) {
+          LogLevelW('\x04',(ushort *)
+                           L"First try failed with \'SIGNATURE_STATE_UNSIGNED_POLICY\', retrying...."
+                   );
+          DVar1 = TimeHelper::SyncSystemTime();
+          if ((int)DVar1 < 0) goto LAB_1;
+          memset(&local_78,0,0x58);
+          local_78 = 0x58;
+          uVar5 = 0;
+          DVar1 = WTGetSignatureInfo(param_1,hObject,0x1803,&local_78,0,0);
+          if ((int)DVar1 < 0) {
+            uVar4 = (ulonglong)DVar1;
+            pwVar3 = 
+            L"Could not establish trust with the requested library %s in retry. Error code was 0x%08x"
+            ;
+            goto LAB_2;
+          }
         }
+        if (1 < local_74 - 5U) {
+          LogLevelW('\x02',(ushort *)
+                           L"Unexpected sigInfo for \'%s\'.  fOSBinary=%d, SignatureState=%d.",
+                    param_1,(ulonglong)local_24,CONCAT44(uVar5,local_74));
+          DVar1 = 0x80070241;
+        }
+        goto LAB_1;
       }
-      if (1 < local_64[0] - 5U) {
-        LogLevelW('\x02',(ushort *)
-                         L"Unexpected sigInfo for \'%s\'.  fOSBinary=%d, SignatureState=%d.",param_1
-                  ,(ulonglong)local_14,CONCAT44(uVar5,local_64[0]));
-        DVar2 = 0x80070241;
-      }
-      goto LAB_1;
+      uVar4 = (ulonglong)DVar1;
+      pwVar3 = L"Could not establish trust with the requested library %s. Error code was 0x%08x";
     }
-    uVar4 = (ulonglong)DVar2;
-    pwVar3 = L"Could not establish trust with the requested library %s. Error code was 0x%08x";
   }
 LAB_2:
   LogLevelW('\x02',(ushort *)pwVar3,param_1,uVar4);
 LAB_1:
   if ((longlong)hObject - 1U < 0xfffffffffffffffe) {
     CloseHandle(hObject);
   }
-  return DVar2;
+  return DVar1;
 }
 

```


## WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.83|
|i_ratio|0.75|
|m_ratio|0.98|
|b_ratio|0.98|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|~CSandboxRpcWrapper|~CSandboxRpcWrapper|
|fullname|WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper|WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper|
|refcount|2|2|
|`length`|90|85|
|`called`|API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>WaasMedic::CSandboxRpcWrapper::SandBoxShutdown<br>WaasMedic::SafeFree|API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>WaasMedic::CSandboxRpcWrapper::SandBoxShutdown<br>WaasMedic::SafeFree|
|calling|`WaasMedic::CWaasRemediation::RunPluginsInCapsule'::__l1::dtor$0|`WaasMedic::CWaasRemediation::RunPluginsInCapsule'::__l1::dtor$0|
|paramcount|1|1|
|`address`|18000beac|18000bedc|
|sig|void __thiscall ~CSandboxRpcWrapper(CSandboxRpcWrapper * this)|void __thiscall ~CSandboxRpcWrapper(CSandboxRpcWrapper * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper Called Diff


```diff
--- WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper called
+++ WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree
```


### WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper Diff


```diff
--- WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper
+++ WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper
@@ -1,20 +1,19 @@
 
 /* public: __cdecl WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper(void) __ptr64 */
 
 void __thiscall WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper(CSandboxRpcWrapper *this)
 
 {
   SandBoxShutdown(this);
-  if (*(LPVOID *)this != (LPVOID)0x0) {
-    CoTaskMemFree(*(LPVOID *)this);
-    *(undefined8 *)this = 0;
+  if (*(void **)this != (void *)0x0) {
+    SafeFree(*(void **)this);
   }
   SafeFree(*(void **)(this + 8));
   *(undefined8 *)(this + 8) = 0;
   if ((longlong)*(HANDLE *)(this + 0x18) - 1U < 0xfffffffffffffffe) {
     CloseHandle(*(HANDLE *)(this + 0x18));
   }
   *(undefined8 *)(this + 0x18) = 0;
   return;
 }
 

```


## WaasMedic::MiscUtil::SetBelowNormalPriorityState

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.45|
|i_ratio|0.63|
|m_ratio|0.94|
|b_ratio|0.91|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|SetBelowNormalPriorityState|SetBelowNormalPriorityState|
|fullname|WaasMedic::MiscUtil::SetBelowNormalPriorityState|WaasMedic::MiscUtil::SetBelowNormalPriorityState|
|refcount|3|3|
|`length`|294|264|
|`called`|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::SetThreadPriority<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-2.DLL::SetThreadInformation<br>LogLevelW<br>NTDLL.DLL::NtSetInformationThread<br>NTDLL.DLL::RtlNtStatusToDosError|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::SetThreadPriority<br>API-MS-WIN-CORE-PROCESSTHREADS-L1-1-2.DLL::SetThreadInformation<br>LogLevelW<br>NTDLL.DLL::NtSetInformationThread<br>WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS|
|calling|WaasMedic::CWaasMedic::LaunchRemediation<br>WaasMedic::CWaasRemediation::PerformActionThread|WaasMedic::CWaasMedic::LaunchRemediation<br>WaasMedic::CWaasRemediation::PerformActionThread|
|paramcount|1|1|
|`address`|18000e380|18000e450|
|sig|long __cdecl SetBelowNormalPriorityState(void * param_1)|long __cdecl SetBelowNormalPriorityState(void * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WaasMedic::MiscUtil::SetBelowNormalPriorityState Called Diff


```diff
--- WaasMedic::MiscUtil::SetBelowNormalPriorityState called
+++ WaasMedic::MiscUtil::SetBelowNormalPriorityState called
@@ -6 +6 @@
-NTDLL.DLL::RtlNtStatusToDosError
+WaasMedic::MiscUtil::HRESULT_FROM_NTSTATUS
```


### WaasMedic::MiscUtil::SetBelowNormalPriorityState Diff


```diff
--- WaasMedic::MiscUtil::SetBelowNormalPriorityState
+++ WaasMedic::MiscUtil::SetBelowNormalPriorityState
@@ -1,66 +1,55 @@
 
 /* public: static long __cdecl WaasMedic::MiscUtil::SetBelowNormalPriorityState(void * __ptr64) */
 
 long __cdecl WaasMedic::MiscUtil::SetBelowNormalPriorityState(void *param_1)
 
 {
-  uint uVar1;
-  BOOL BVar2;
-  DWORD DVar3;
-  int iVar4;
-  uint uVar5;
-  uint uVar6;
+  BOOL BVar1;
+  DWORD DVar2;
+  int iVar3;
+  uint uVar4;
   uint local_res8 [2];
   uint local_res10 [2];
   
-  uVar1 = 0;
+  uVar4 = 0;
   if (param_1 == (void *)0xffffffffffffffff) {
     LogLevelW('\x03',(ushort *)
                      L"SetBelowNormalPriorityState was passed invalid thread handle. Will not attempt to adjust priority."
              );
-    uVar1 = 0x80070057;
+    uVar4 = 0x80070057;
   }
   else {
     local_res8[0] = 4;
     local_res10[0] = 1;
-    BVar2 = SetThreadPriority(param_1,-1);
-    if (BVar2 == 0) {
-      DVar3 = GetLastError();
-      uVar1 = DVar3 & 0xffff | 0x80070000;
-      if ((int)DVar3 < 1) {
-        uVar1 = DVar3;
+    BVar1 = SetThreadPriority(param_1,-1);
+    if (BVar1 == 0) {
+      DVar2 = GetLastError();
+      uVar4 = DVar2 & 0xffff | 0x80070000;
+      if ((int)DVar2 < 1) {
+        uVar4 = DVar2;
       }
       LogLevelW('\x03',(ushort *)
                        L"Attempt to move thread to CPU priority %d failed with GetLastError=0x%08x",
-                0xffffffff,(ulonglong)uVar1);
+                0xffffffff,(ulonglong)uVar4);
     }
-    iVar4 = SetThreadInformation(param_1,0,local_res8,4);
-    if (iVar4 == 0) {
-      DVar3 = GetLastError();
-      uVar1 = DVar3 & 0xffff | 0x80070000;
-      if ((int)DVar3 < 1) {
-        uVar1 = DVar3;
+    iVar3 = SetThreadInformation(param_1,0,local_res8,4);
+    if (iVar3 == 0) {
+      DVar2 = GetLastError();
+      uVar4 = DVar2 & 0xffff | 0x80070000;
+      if ((int)DVar2 < 1) {
+        uVar4 = DVar2;
       }
       LogLevelW('\x03',(ushort *)
                        L"Attempt to move thread to memory priority %d failed with GetLastError=0x%08x"
-                ,(ulonglong)local_res8[0],(ulonglong)uVar1);
+                ,(ulonglong)local_res8[0],(ulonglong)uVar4);
     }
-    uVar5 = NtSetInformationThread(param_1,0x16,local_res10);
-    if ((int)uVar5 < 0) {
-      uVar6 = RtlNtStatusToDosError(uVar5);
-      if (uVar6 == 0x13d) {
-        uVar1 = uVar5 | 0x10000000;
-      }
-      else {
-        uVar1 = uVar6 & 0xffff | 0x80070000;
-        if ((int)uVar6 < 1) {
-          uVar1 = uVar6;
-        }
-      }
+    iVar3 = NtSetInformationThread(param_1,0x16,local_res10);
+    if (iVar3 < 0) {
+      uVar4 = HRESULT_FROM_NTSTATUS(iVar3);
       LogLevelW('\x03',(ushort *)L"Attempt to move thread to IO priority %d failed with hr=0x%08x",
-                (ulonglong)local_res10[0],(ulonglong)uVar1);
+                (ulonglong)local_res10[0],(ulonglong)uVar4);
     }
   }
-  return uVar1;
+  return uVar4;
 }
 

```


## WaasMedic::CSandboxRpcWrapper::Init

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.29|
|i_ratio|0.28|
|m_ratio|0.8|
|b_ratio|0.67|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|Init|Init|
|fullname|WaasMedic::CSandboxRpcWrapper::Init|WaasMedic::CSandboxRpcWrapper::Init|
|refcount|2|2|
|`length`|185|292|
|`called`|API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid<br>API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree<br>API-MS-WIN-CORE-COM-L1-1-0.DLL::StringFromCLSID<br>LogLevelW<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>__security_check_cookie|LogLevelW<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::GetRandomString<br>WaasMedic::SafeAllocString<br>WaasMedic::SafeFree<br>__security_check_cookie<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling|WaasMedic::CWaasRemediation::RunPluginsInCapsule|WaasMedic::CWaasRemediation::RunPluginsInCapsule|
|paramcount|2|2|
|`address`|18000bf0c|18000bf38|
|sig|long __thiscall Init(CSandboxRpcWrapper * this, TraceLoggingCorrelationVector * param_1)|long __thiscall Init(CSandboxRpcWrapper * this, TraceLoggingCorrelationVector * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WaasMedic::CSandboxRpcWrapper::Init Called Diff


```diff
--- WaasMedic::CSandboxRpcWrapper::Init called
+++ WaasMedic::CSandboxRpcWrapper::Init called
@@ -1,3 +0,0 @@
-API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid
-API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree
-API-MS-WIN-CORE-COM-L1-1-0.DLL::StringFromCLSID
@@ -5,0 +3,3 @@
+WaasMedic::GetRandomString
+WaasMedic::SafeAllocString
+WaasMedic::SafeFree
@@ -6,0 +7 @@
+std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
```


### WaasMedic::CSandboxRpcWrapper::Init Diff


```diff
--- WaasMedic::CSandboxRpcWrapper::Init
+++ WaasMedic::CSandboxRpcWrapper::Init
@@ -1,43 +1,70 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* public: long __cdecl WaasMedic::CSandboxRpcWrapper::Init(class TraceLoggingCorrelationVector *
    __ptr64) __ptr64 */
 
 long __thiscall
 WaasMedic::CSandboxRpcWrapper::Init(CSandboxRpcWrapper *this,TraceLoggingCorrelationVector *param_1)
 
 {
   uint uVar1;
-  wchar_t *pwVar2;
-  undefined1 auStack_48 [32];
-  GUID local_28;
-  ulonglong local_18;
+  ushort *puVar2;
+  wchar_t *pwVar3;
+  undefined1 auStack_58 [32];
+  undefined8 local_38;
+  ushort local_30;
+  undefined6 uStack_2e;
+  undefined8 local_20;
+  ulonglong uStack_18;
+  ulonglong local_10;
   
-  local_18 = __security_cookie ^ (ulonglong)auStack_48;
-  *(TraceLoggingCorrelationVector **)(this + 0x20) = param_1;
-  uVar1 = CoCreateGuid(&local_28);
-  if ((int)uVar1 < 0) {
-    pwVar2 = L"Failed to create a GUID for RPC endpoint. hr = 0x%08x.";
+  local_38 = 0xfffffffffffffffe;
+  local_10 = __security_cookie ^ (ulonglong)auStack_58;
+  local_20 = 0;
+  uStack_18 = 7;
+  local_30 = 0;
+  if (param_1 == (TraceLoggingCorrelationVector *)0x0) {
+    uVar1 = 0x80004003;
+    LogLevelW('\x02',(ushort *)L"null cv passed in.");
   }
   else {
-    if (*(LPVOID *)this != (LPVOID)0x0) {
-      CoTaskMemFree(*(LPVOID *)this);
-      *(undefined8 *)this = 0;
-    }
-    uVar1 = StringFromCLSID(&local_28,(LPOLESTR *)this);
+    *(TraceLoggingCorrelationVector **)(this + 0x20) = param_1;
+    uVar1 = GetRandomString((__uint64)this,
+                            (basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+                             *)&local_30);
     if ((int)uVar1 < 0) {
-      pwVar2 = L"Failed to convert GUID to string for RPC endpoint. hr = 0x%08x.";
+      pwVar3 = L"Failed to create a random string for RPC endpoint. hr = 0x%08x.";
     }
     else {
-      LogLevelW('\x04',(ushort *)L"RPC Endpoint: %s",*(undefined8 *)this);
-      uVar1 = PrepareCommandLine(this);
-      if (-1 < (int)uVar1) {
-        return uVar1;
+      if (*(void **)this != (void *)0x0) {
+        SafeFree(*(void **)this);
       }
-      pwVar2 = L"Failed to prepare command line for WaaSMedicAgent. hr = 0x%08x.";
+      puVar2 = &local_30;
+      if ((uStack_18 < 8) ||
+         (puVar2 = (ushort *)CONCAT62(uStack_2e,local_30), puVar2 != (ushort *)0x0)) {
+        uVar1 = SafeAllocString(puVar2,(ushort **)this);
+      }
+      else {
+        uVar1 = 0x80004003;
+      }
+      if ((int)uVar1 < 0) {
+        pwVar3 = L"Failed to allocate memory for RPC endpoint string. hr = 0x%08x.";
+      }
+      else {
+        LogLevelW('\x04',(ushort *)L"RPC Endpoint starting character: %c",
+                  (ulonglong)**(ushort **)this);
+        uVar1 = PrepareCommandLine(this);
+        if (-1 < (int)uVar1) goto LAB_0;
+        pwVar3 = L"Failed to prepare command line for WaaSMedicAgent. hr = 0x%08x.";
+      }
     }
+    LogLevelW('\x02',(ushort *)pwVar3,(ulonglong)uVar1);
   }
-  LogLevelW('\x02',(ushort *)pwVar2,(ulonglong)uVar1);
+LAB_0:
+  std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+  ::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+            ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
+              *)&local_30);
   return uVar1;
 }
 

```


## WaasMedic::CWaasRemediation::RunPluginsInCapsule

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|code,length,address,called|
|ratio|0.47|
|i_ratio|0.65|
|m_ratio|1.0|
|b_ratio|0.99|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|RunPluginsInCapsule|RunPluginsInCapsule|
|fullname|WaasMedic::CWaasRemediation::RunPluginsInCapsule|WaasMedic::CWaasRemediation::RunPluginsInCapsule|
|refcount|3|3|
|`length`|4164|4130|
|`called`|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress<br>API-MS-WIN-CORE-SYSINFO-L1-1-0.DLL::GetSystemTimeAsFileTime<br>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn<br>CJsonHelper::SetValue<br>LogLevelW<br>OLEAUT32.DLL::VariantClear<br>OLEAUT32.DLL::VariantInit<br>WaasMedic::CSandboxRpcWrapper::ConnectToSandbox</summary>WaasMedic::CSandboxRpcWrapper::CreateSandbox<br>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::SandBoxFreePluginLibrary<br>WaasMedic::CSandboxRpcWrapper::SandBoxShutdown<br>WaasMedic::CSandboxRpcWrapper::SandboxLoadLibrary<br>WaasMedic::CSandboxRpcWrapper::SandboxPluginAction<br>WaasMedic::CWaasRemediation::AppendPluginName<br>WaasMedic::CWaasRemediation::CheckIfPluginIsRunnable<br>WaasMedic::CWaasRemediation::ExecutePerformAction<br>WaasMedic::CWaasRemediation::IsPluginNeedToSkipBasedOnPluginList<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::ReportPluginError<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings<br>WaasMedic::SafeAlloc<br>WaasMedic::SafeFree<br>WaasMedic::TelemetryProvider::DetectionActivity::StartActivity<br>WaasMedic::TelemetryProvider::EnumeratePluginActivity::StartActivity<br>WaasMedic::TelemetryProvider::RemediationActivity::StartActivity<br>WaasMedic::TelemetryProvider::ReportDetectionCompleted<br>WaasMedic::TelemetryProvider::ReportDetectionFailed<br>WaasMedic::TelemetryProvider::ReportDetectionStarted<br>WaasMedic::TelemetryProvider::ReportRemediationCompleted<br>WaasMedic::TelemetryProvider::ReportRemediationFailed<br>WaasMedic::TelemetryProvider::ReportRemediationStarted<br>WaasMedic::TelemetryProvider::SandboxActivity::StartActivity<br>WaasMedic::TimeHelper::FileTimeToVariant<br>WaasMedic::ws2s<br>__security_check_cookie<br>_com_issue_error<br>_guard_dispatch_icall<br>memset<br>operator_delete[]<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::Destroy<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::Stop<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType></details>|<details><summary>Expand for full list:<br>API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HANDLE-L1-1-0.DLL::CloseHandle<br>API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0.DLL::GetProcAddress<br>API-MS-WIN-CORE-SYSINFO-L1-1-0.DLL::GetSystemTimeAsFileTime<br>API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn<br>CJsonHelper::SetValue<br>LogLevelW<br>OLEAUT32.DLL::VariantClear<br>OLEAUT32.DLL::VariantInit<br>WaasMedic::CSandboxRpcWrapper::ConnectToSandbox<br>WaasMedic::CSandboxRpcWrapper::CreateSandbox</summary>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::SandBoxFreePluginLibrary<br>WaasMedic::CSandboxRpcWrapper::SandBoxShutdown<br>WaasMedic::CSandboxRpcWrapper::SandboxLoadLibrary<br>WaasMedic::CSandboxRpcWrapper::SandboxPluginAction<br>WaasMedic::CWaasRemediation::AppendPluginName<br>WaasMedic::CWaasRemediation::CheckIfPluginIsRunnable<br>WaasMedic::CWaasRemediation::ExecutePerformAction<br>WaasMedic::CWaasRemediation::IsPluginNeedToSkipBasedOnPluginList<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::ReportPluginError<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings<br>WaasMedic::SafeAlloc<br>WaasMedic::SafeFree<br>WaasMedic::TelemetryProvider::DetectionActivity::StartActivity<br>WaasMedic::TelemetryProvider::EnumeratePluginActivity::StartActivity<br>WaasMedic::TelemetryProvider::RemediationActivity::StartActivity<br>WaasMedic::TelemetryProvider::ReportDetectionCompleted<br>WaasMedic::TelemetryProvider::ReportDetectionFailed<br>WaasMedic::TelemetryProvider::ReportDetectionStarted<br>WaasMedic::TelemetryProvider::ReportRemediationCompleted<br>WaasMedic::TelemetryProvider::ReportRemediationFailed<br>WaasMedic::TelemetryProvider::ReportRemediationStarted<br>WaasMedic::TelemetryProvider::SandboxActivity::StartActivity<br>WaasMedic::TimeHelper::FileTimeToVariant<br>WaasMedic::ws2s<br>__security_check_cookie<br>_com_issue_error<br>_guard_dispatch_icall<br>memset<br>operator_delete[]<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_><br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::Destroy<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::Stop<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType></details>|
|calling|WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx|WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx|
|paramcount|12|12|
|`address`|180009a1c|180009a68|
|sig|long __thiscall RunPluginsInCapsule(CWaasRemediation * this, bool param_1, tagUpdateImpactLevel param_2, ICancellable * param_3, ushort * param_4, RunMode param_5, ushort * param_6, char * param_7, ulong * param_8, ulong * param_9, bool * param_10, ushort * * param_11)|long __thiscall RunPluginsInCapsule(CWaasRemediation * this, bool param_1, tagUpdateImpactLevel param_2, ICancellable * param_3, ushort * param_4, RunMode param_5, ushort * param_6, char * param_7, ulong * param_8, ulong * param_9, bool * param_10, ushort * * param_11)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### WaasMedic::CWaasRemediation::RunPluginsInCapsule Called Diff


```diff
--- WaasMedic::CWaasRemediation::RunPluginsInCapsule called
+++ WaasMedic::CWaasRemediation::RunPluginsInCapsule called
@@ -1 +0,0 @@
-API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree
```


### WaasMedic::CWaasRemediation::RunPluginsInCapsule Diff


```diff
--- WaasMedic::CWaasRemediation::RunPluginsInCapsule
+++ WaasMedic::CWaasRemediation::RunPluginsInCapsule
@@ -1,885 +1,868 @@
 
 /* WARNING: Function: __security_check_cookie replaced with injection: security_check_cookie */
 /* WARNING: Function: _guard_dispatch_icall replaced with injection: guard_dispatch_icall */
 /* WARNING: Exceeded maximum restarts with more pending */
 /* private: long __cdecl WaasMedic::CWaasRemediation::RunPluginsInCapsule(bool,enum
    tagUpdateImpactLevel,struct WaasMedic::ICancellable * __ptr64,unsigned short const * __ptr64,enum
    WaasMedic::RunMode,unsigned short const * __ptr64,char const * __ptr64,unsigned long *
    __ptr64,unsigned long * __ptr64,bool * __ptr64,unsigned short * __ptr64 * __ptr64) __ptr64 */
 
 long __thiscall
 WaasMedic::CWaasRemediation::RunPluginsInCapsule
           (CWaasRemediation *this,bool param_1,tagUpdateImpactLevel param_2,ICancellable *param_3,
           ushort *param_4,RunMode param_5,ushort *param_6,char *param_7,ulong *param_8,
           ulong *param_9,bool *param_10,ushort **param_11)
 
 {
   int *piVar1;
   longlong *plVar2;
   code *pcVar3;
   void *pvVar4;
   undefined8 uVar5;
   char cVar6;
   bool bVar7;
   uint uVar8;
   long lVar9;
   DWORD DVar10;
   uint uVar11;
   uint uVar12;
   uint uVar13;
   int iVar14;
   HRESULT HVar15;
   LPCSTR lpProcName;
   FARPROC pFVar16;
   void *pvVar17;
   undefined8 *puVar18;
   ulonglong uVar19;
   uchar uVar20;
   _union_2707 *p_Var21;
   CWaasRemediation *this_00;
   wchar_t *pwVar22;
   wchar_t *pwVar23;
   undefined4 uVar24;
   ushort *puVar25;
   ulonglong uVar26;
   _union_2707 *p_Var27;
   undefined1 uVar28;
   _union_2707 *p_Var29;
   undefined4 uVar30;
   undefined1 auStackY_598 [32];
   undefined1 local_558 [16];
   int local_548 [2];
   uint local_540;
   uint local_53c;
   _union_2707 local_538;
   tagUpdateImpactLevel local_520;
   uint local_51c;
   _union_2707 *local_518;
   longlong local_510;
   _FILETIME local_508;
   _union_2707 *local_500;
   _union_2707 local_4f8;
-  LPVOID local_4e0;
+  void *local_4e0;
   void *pvStack_4d8;
   undefined8 local_4d0;
   HANDLE pvStack_4c8;
   ushort *local_4b8;
   ushort *local_4b0;
   ulong *local_4a8;
   ulong *local_4a0;
   bool *local_498;
   ICancellable *local_490;
   _union_2707 local_488;
   _union_2707 local_470;
   undefined8 local_458;
   _union_2707 local_450;
   ulonglong uStack_438;
   _union_2707 local_430;
   undefined **local_408;
   undefined8 local_400;
   undefined ***local_3f8;
   undefined8 local_3f0;
   undefined4 local_3e8;
   undefined4 *local_3e0;
   undefined4 *local_3d8;
   undefined4 local_3d0;
   undefined1 local_3cc;
   undefined4 local_3a8 [2];
   char *local_3a0;
   undefined8 local_398;
   undefined1 local_390;
   undefined8 local_388;
   undefined1 local_380 [144];
   undefined8 local_2f0;
   undefined8 local_2e8;
   undefined8 local_2e0;
   undefined8 local_2d8;
   undefined **local_2c8;
   undefined8 local_2c0;
   undefined ***local_2b8;
   undefined8 local_2b0;
   undefined4 local_2a8;
   undefined4 *local_2a0;
   undefined4 *local_298;
   undefined4 local_290;
   undefined1 local_28c;
   undefined4 local_268 [2];
   char *local_260;
   undefined8 local_258;
   undefined1 local_250;
   undefined8 local_248;
   undefined1 local_240 [144];
   undefined8 local_1b0;
   undefined8 local_1a8;
   undefined8 local_1a0;
   undefined8 local_198;
   undefined **local_188;
   undefined8 local_180;
   undefined ***local_178;
   undefined8 local_170;
   undefined4 local_168;
   undefined4 *local_160;
   undefined4 *local_158;
   undefined4 local_150;
   undefined1 local_14c;
   undefined4 local_128 [2];
   char *local_120;
   undefined8 local_118;
   undefined1 local_110;
   undefined8 local_108;
   undefined1 local_100 [144];
   undefined8 local_70;
   undefined8 local_68;
   undefined8 local_60;
   undefined8 local_58;
   ulonglong local_48;
   
   local_458 = 0xfffffffffffffffe;
   local_48 = __security_cookie ^ (ulonglong)auStackY_598;
   local_4b8 = param_4;
   local_4b0 = param_6;
   local_538._16_8_ = param_7;
   local_4a8 = param_8;
   local_4a0 = param_9;
   local_498 = param_10;
   local_518 = (_union_2707 *)param_11;
   uVar19 = 0;
   uVar8 = 0;
   uVar13 = 0;
   local_558[2] = '\x01';
   local_548[0] = 0;
   local_500 = (_union_2707 *)0x0;
-  local_4e0 = (LPVOID)0x0;
+  local_4e0 = (void *)0x0;
   pvStack_4d8 = (void *)0x0;
   local_4d0 = 0;
   pvStack_4c8 = (HANDLE)0x0;
   local_510 = 0;
   local_180 = 0;
   local_178 = &local_188;
   local_170 = 0;
   local_168 = 0;
   local_160 = local_128;
   local_158 = &local_150;
   local_150 = 0;
   local_14c = 0;
   local_110 = 0;
   local_128[0] = 0;
   local_120 = "SandboxActivity";
   local_118 = 0;
   local_108 = 1;
   local_70 = 0;
   p_Var29 = (_union_2707 *)param_3;
   local_558[3] = param_1;
   local_538.decVal.u2 = (_union_1719)this;
   local_520 = param_2;
   local_490 = param_3;
   memset(local_100,0,0x90);
   local_68 = 0;
   local_60 = 0;
   local_58 = 0;
   local_188 = &TelemetryProvider::SandboxActivity::_vftable_;
   TelemetryProvider::SandboxActivity::StartActivity((SandboxActivity *)&local_188,param_7,param_6);
   local_2c0 = 0;
   local_2b8 = &local_2c8;
   local_2b0 = 0;
   local_2a8 = 0;
   local_2a0 = local_268;
   local_298 = &local_290;
   local_290 = 0;
   local_28c = 0;
   local_250 = 0;
   local_268[0] = 0;
   local_260 = "EnumeratePluginActivity";
   local_258 = 0;
   local_248 = 1;
   local_1b0 = 0;
   memset(local_240,0,0x90);
   local_1a8 = 0;
   local_1a0 = 0;
   local_198 = 0;
   local_2c8 = &TelemetryProvider::EnumeratePluginActivity::_vftable_;
   TelemetryProvider::EnumeratePluginActivity::StartActivity
             ((EnumeratePluginActivity *)&local_2c8,param_7,param_6);
   if (*(longlong *)(this + 0x48) == 0) {
     uVar11 = 0x80029c4a;
   }
   else {
     LogLevelW('\x04',(ushort *)L"Caller request enumeration ");
     std::
     basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::
     basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
               ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
                 *)&local_430.n2,(ushort *)L"EnumeratePlugins");
     lpProcName = (LPCSTR)ws2s((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
                                *)&local_450.n2);
     if (0xf < *(ulonglong *)(lpProcName + 0x18)) {
       lpProcName = *(LPCSTR *)lpProcName;
     }
     pFVar16 = GetProcAddress(*(HMODULE *)(this + 0x48),lpProcName);
     if (0xf < uStack_438) {
       pvVar4 = (void *)CONCAT62(local_450._2_6_,
                                 CONCAT11(local_450.n2.vt._1_1_,local_450.n2.vt._0_1_));
       pvVar17 = pvVar4;
       if ((0xfff < uStack_438 + 1) &&
          (pvVar17 = *(void **)((longlong)pvVar4 + -8),
          0x1f < (ulonglong)((longlong)pvVar4 + (-8 - (longlong)pvVar17)))) {
         _o__invalid_parameter_noinfo_noreturn();
         pcVar3 = (code *)swi(3);
         lVar9 = (*pcVar3)();
         return lVar9;
       }
       operator_delete__(pvVar17);
     }
     local_450._16_8_ = 0;
     uStack_438 = 0xf;
     local_450.n2.vt._0_1_ = 0;
     std::
     basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::
     ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
               ((basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>
                 *)&local_430.n2);
     if (pFVar16 == (FARPROC)0x0) {
       DVar10 = GetLastError();
       uVar11 = DVar10 & 0xffff | 0x80070000;
       if ((int)DVar10 < 1) {
         uVar11 = DVar10;
       }
     }
     else {
       uVar11 = (*pFVar16)(local_548);
       if ((int)uVar11 < 0) {
         LogLevelW('\x04',(ushort *)L"Failed to enumerate plugins. hr = 0x%08x",(ulonglong)uVar11);
       }
       else {
         uVar26 = uVar19;
         if (0 < local_548[0]) {
           do {
             puVar25 = (ushort *)((longlong)(int)uVar26 * 0x204 + local_510);
             if (puVar25 == (ushort *)0x0) {
               LogLevelW('\x02',(ushort *)L"PluginId is null for index = %d.",uVar26);
               param_11 = (ushort **)local_518;
               break;
             }
             uVar11 = SetPluginDefaultSettings(this,puVar25);
             if ((int)uVar11 < 0) {
               p_Var29 = (_union_2707 *)(ulonglong)uVar11;
               LogLevelW('\x02',(ushort *)L"Failed to set default setting for %s. hr = 0x%08x",
                         puVar25);
               param_11 = (ushort **)local_518;
               break;
             }
             uVar12 = (int)uVar26 + 1;
             uVar26 = (ulonglong)uVar12;
             param_11 = (ushort **)local_518;
           } while ((int)uVar12 < local_548[0]);
         }
       }
     }
     if ((-1 < (int)uVar11) && (local_510 != 0)) {
       bVar7 = false;
       wil::
       ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
       ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
               *)&local_2c8,0);
       if ((_union_2707 *)param_11 != (_union_2707 *)0x0) {
         uVar11 = local_548[0] * 0x40 + 1;
         p_Var27 = (_union_2707 *)(ulonglong)uVar11;
         local_500 = p_Var27;
         pvVar17 = SafeAlloc((ulonglong)uVar11 * 2,bVar7);
         *param_11 = pvVar17;
         if (pvVar17 == (void *)0x0) {
           pwVar22 = L"Failed to allocate memory for list of plugins.  Size required = %d.";
           uVar20 = '\x02';
 LAB_0:
           LogLevelW(uVar20,(ushort *)pwVar22,p_Var27);
           uVar13 = uVar8;
           goto LAB_1;
         }
       }
-      if (*(TraceLoggingCorrelationVector **)(this + 0x40) == (TraceLoggingCorrelationVector *)0x0)
-      {
-        LogLevelW('\x02',(ushort *)L"null cv passed in.");
-        uVar8 = 0x80004003;
+      uVar8 = CSandboxRpcWrapper::Init
+                        ((CSandboxRpcWrapper *)&local_4e0,
+                         *(TraceLoggingCorrelationVector **)(this + 0x40));
+      local_53c = uVar8;
+      if ((int)uVar8 < 0) {
+        LogLevelW('\x02',(ushort *)L"Failed to initialize sandbox.  hr = 0x%08x",(ulonglong)uVar8);
+        uVar13 = uVar8;
       }
       else {
-        uVar8 = CSandboxRpcWrapper::Init
-                          ((CSandboxRpcWrapper *)&local_4e0,
-                           *(TraceLoggingCorrelationVector **)(this + 0x40));
-        local_53c = uVar8;
-        if (-1 < (int)uVar8) {
-          local_51c = 0;
-          uVar26 = uVar19;
-          if (0 < local_548[0]) {
-            do {
-              uVar8 = (uint)uVar26;
-              uVar24 = 0;
-              p_Var27 = (_union_2707 *)((longlong)(int)uVar19 * 0x204 + local_510);
-              if ((param_3 != (ICancellable *)0x0) &&
-                 (cVar6 = (*(code *)**(undefined8 **)param_3)(param_3), cVar6 != '\0')) {
-                pwVar22 = L"Waas Remediation engine received cancellation request for plugin %s.";
-                uVar20 = '\x04';
-                goto LAB_0;
-              }
-              local_558[1] = '\0';
-              local_558[0] = '\0';
-              local_558[4] = '\0';
-              VariantInit((VARIANTARG *)&local_470.n2);
-              VariantInit((VARIANTARG *)&local_488.n2);
-              VariantInit((VARIANTARG *)&local_4f8.n2);
-              VariantInit((VARIANTARG *)&local_450.n2);
-              p_Var21 = &local_430;
-              VariantInit((VARIANTARG *)&p_Var21->n2);
-              local_508.dwLowDateTime = 0;
-              local_508.dwHighDateTime = 0;
-              uVar13 = 0;
-              uVar30 = 0x78;
-              local_558[5] = '\0';
-              local_548[1] = local_548[1] & 0xffffff00;
-              uVar8 = 0x248001;
-              local_558._8_4_ = 0x248001;
-              local_538._0_4_ = 0x248001;
-              local_558._12_4_ = 0x244001;
-              local_540 = 0x244001;
-              bVar7 = IsPluginNeedToSkipBasedOnPluginList
-                                ((CWaasRemediation *)&p_Var21->n2,local_4b8,(ushort *)p_Var27);
-              if (bVar7) {
-                LogLevelW('\x04',(ushort *)L"Plugin \"%s\" is not specified to run. Nothing to do.."
-                          ,p_Var27);
-                uVar8 = 0x244001;
-              }
-              else {
-                if (local_558[3] == '\0') {
-                  p_Var29 = &local_538;
-                  p_Var21 = p_Var27;
-                  uVar11 = CheckIfPluginIsRunnable
-                                     ((CWaasRemediation *)local_538.decVal.u2,local_520,
-                                      (ushort *)p_Var27,(long *)p_Var29,(long *)&local_540,
-                                      (bool *)local_558,(bool *)(local_558 + 1));
-                  if ((int)uVar11 < 0) {
-                    local_558._12_4_ = local_540;
-                    local_558._8_4_ = uVar11;
-                  }
-                  else {
-                    if ((local_558[0] != '\0') && (local_558[1] != '\0')) {
-                      local_558._8_4_ = local_538._0_4_;
-                      local_558._12_4_ = local_540;
-                      goto LAB_2;
-                    }
-                    uVar8 = 0x244001;
+        local_51c = 0;
+        uVar26 = uVar19;
+        if (0 < local_548[0]) {
+          do {
+            uVar8 = (uint)uVar26;
+            uVar24 = 0;
+            p_Var27 = (_union_2707 *)((longlong)(int)uVar19 * 0x204 + local_510);
+            if ((param_3 != (ICancellable *)0x0) &&
+               (cVar6 = (*(code *)**(undefined8 **)param_3)(param_3), cVar6 != '\0')) {
+              pwVar22 = L"Waas Remediation engine received cancellation request for plugin %s.";
+              uVar20 = '\x04';
+              goto LAB_0;
+            }
+            local_558[1] = '\0';
+            local_558[0] = '\0';
+            local_558[4] = '\0';
+            VariantInit((VARIANTARG *)&local_470.n2);
+            VariantInit((VARIANTARG *)&local_488.n2);
+            VariantInit((VARIANTARG *)&local_4f8.n2);
+            VariantInit((VARIANTARG *)&local_450.n2);
+            p_Var21 = &local_430;
+            VariantInit((VARIANTARG *)&p_Var21->n2);
+            local_508.dwLowDateTime = 0;
+            local_508.dwHighDateTime = 0;
+            uVar13 = 0;
+            uVar30 = 0x78;
+            local_558[5] = '\0';
+            local_548[1] = local_548[1] & 0xffffff00;
+            uVar8 = 0x248001;
+            local_558._8_4_ = 0x248001;
+            local_538._0_4_ = 0x248001;
+            local_558._12_4_ = 0x244001;
+            local_540 = 0x244001;
+            bVar7 = IsPluginNeedToSkipBasedOnPluginList
+                              ((CWaasRemediation *)&p_Var21->n2,local_4b8,(ushort *)p_Var27);
+            if (bVar7) {
+              LogLevelW('\x04',(ushort *)L"Plugin \"%s\" is not specified to run. Nothing to do..",
+                        p_Var27);
+              uVar8 = 0x244001;
+            }
+            else {
+              if (local_558[3] == '\0') {
+                p_Var29 = &local_538;
+                p_Var21 = p_Var27;
+                uVar11 = CheckIfPluginIsRunnable
+                                   ((CWaasRemediation *)local_538.decVal.u2,local_520,
+                                    (ushort *)p_Var27,(long *)p_Var29,(long *)&local_540,
+                                    (bool *)local_558,(bool *)(local_558 + 1));
+                if ((int)uVar11 < 0) {
+                  local_558._12_4_ = local_540;
+                  local_558._8_4_ = uVar11;
+                }
+                else {
+                  if ((local_558[0] != '\0') && (local_558[1] != '\0')) {
                     local_558._8_4_ = local_538._0_4_;
                     local_558._12_4_ = local_540;
+                    goto LAB_2;
                   }
+                  uVar8 = 0x244001;
+                  local_558._8_4_ = local_538._0_4_;
+                  local_558._12_4_ = local_540;
+                }
+              }
+              else {
+                p_Var21 = (_union_2707 *)local_558;
+                uVar11 = Plugin_IsEnabled((CWaasRemediation *)local_538.decVal.u2,(ushort *)p_Var27,
+                                          (bool *)p_Var21);
+                if ((int)uVar11 < 0) {
+                  pwVar22 = L"IsEnabled for %s failed! hr = 0x%08x.";
+                  uVar12 = local_53c;
+                  uVar8 = uVar11;
+LAB_3:
+                  p_Var29 = (_union_2707 *)(ulonglong)uVar12;
+                  LogLevelW('\x02',(ushort *)pwVar22,p_Var27);
+                  uVar11 = uVar8;
+                }
+                else if (local_558[0] == '\0') {
+                  LogLevelW('\x04',(ushort *)L"Plugin \"%s\" is not enabled. Nothing to do..",
+                            p_Var27);
+                  uVar8 = 0x248004;
+                  local_558._8_4_ = 0x248004;
                 }
                 else {
-                  p_Var21 = (_union_2707 *)local_558;
-                  uVar11 = Plugin_IsEnabled((CWaasRemediation *)local_538.decVal.u2,
-                                            (ushort *)p_Var27,(bool *)p_Var21);
-                  if ((int)uVar11 < 0) {
-                    pwVar22 = L"IsEnabled for %s failed! hr = 0x%08x.";
-                    uVar12 = local_53c;
-                    uVar8 = uVar11;
-LAB_3:
-                    p_Var29 = (_union_2707 *)(ulonglong)uVar12;
-                    LogLevelW('\x02',(ushort *)pwVar22,p_Var27);
-                    uVar11 = uVar8;
+LAB_2:
+                  uVar8 = 0;
+                  GetSystemTimeAsFileTime(&local_508);
+                  uVar12 = TimeHelper::FileTimeToVariant
+                                     (&local_508,(ushort)&local_470,(tagVARIANT *)&p_Var21->n2);
+                  if ((int)uVar12 < 0) {
+                    pwVar22 = L"Failed to convert filetime to string for %s! hr = 0x%08x.";
+                    uVar8 = uVar12;
+                    goto LAB_3;
                   }
-                  else if (local_558[0] == '\0') {
-                    LogLevelW('\x04',(ushort *)L"Plugin \"%s\" is not enabled. Nothing to do..",
-                              p_Var27);
-                    uVar8 = 0x248004;
-                    local_558._8_4_ = 0x248004;
-                  }
-                  else {
-LAB_2:
-                    uVar8 = 0;
-                    GetSystemTimeAsFileTime(&local_508);
-                    uVar12 = TimeHelper::FileTimeToVariant
-                                       (&local_508,(ushort)&local_470,(tagVARIANT *)&p_Var21->n2);
-                    if ((int)uVar12 < 0) {
-                      pwVar22 = L"Failed to convert filetime to string for %s! hr = 0x%08x.";
-                      uVar8 = uVar12;
-                      goto LAB_3;
-                    }
-                    if (local_558[2] == '\0') {
+                  if (local_558[2] == '\0') {
 LAB_4:
-                      if (param_5 == 2) {
+                    if (param_5 == 2) {
 LAB_5:
-                        GetSystemTimeAsFileTime(&local_508);
-                        uVar11 = TimeHelper::FileTimeToVariant
-                                           (&local_508,(ushort)&local_488,(tagVARIANT *)&p_Var21->n2
-                                           );
-                        if ((int)uVar11 < 0) {
-                          pwVar23 = L"Failed to convert filetime to string for %s! hr = 0x%08x.";
-                          uVar20 = '\x02';
-                          pwVar22 = (wchar_t *)p_Var27;
-                          uVar13 = uVar11;
+                      GetSystemTimeAsFileTime(&local_508);
+                      uVar11 = TimeHelper::FileTimeToVariant
+                                         (&local_508,(ushort)&local_488,(tagVARIANT *)&p_Var21->n2);
+                      if ((int)uVar11 < 0) {
+                        pwVar23 = L"Failed to convert filetime to string for %s! hr = 0x%08x.";
+                        uVar20 = '\x02';
+                        pwVar22 = (wchar_t *)p_Var27;
+                        uVar13 = uVar11;
 LAB_6:
-                          p_Var29 = (_union_2707 *)(ulonglong)uVar13;
-                          LogLevelW(uVar20,(ushort *)pwVar23,pwVar22);
+                        p_Var29 = (_union_2707 *)(ulonglong)uVar13;
+                        LogLevelW(uVar20,(ushort *)pwVar23,pwVar22);
+                      }
+                      else {
+                        p_Var29 = &local_430;
+                        iVar14 = (**(code **)(**(longlong **)((longlong)local_538.decVal.u2 + 0x18)
+                                             + 0x18))
+                                           (*(longlong **)((longlong)local_538.decVal.u2 + 0x18),
+                                            p_Var27,L"ThreadExecutionTimeoutInSeconds");
+                        if (iVar14 < 0) {
+                          p_Var29 = (_union_2707 *)(ulonglong)local_53c;
+                          LogLevelW('\x03',(ushort *)L"Failed to retrieve settings %s! hr = 0x%08x",
+                                    L"ThreadExecutionTimeoutInSeconds");
                         }
                         else {
-                          p_Var29 = &local_430;
-                          iVar14 = (**(code **)(**(longlong **)
-                                                  ((longlong)local_538.decVal.u2 + 0x18) + 0x18))
-                                             (*(longlong **)((longlong)local_538.decVal.u2 + 0x18),
-                                              p_Var27,L"ThreadExecutionTimeoutInSeconds");
-                          if (iVar14 < 0) {
-                            p_Var29 = (_union_2707 *)(ulonglong)local_53c;
-                            LogLevelW('\x03',(ushort *)
-                                             L"Failed to retrieve settings %s! hr = 0x%08x",
-                                      L"ThreadExecutionTimeoutInSeconds");
-                          }
-                          else {
-                            uVar30 = 0x78;
-                            if (local_430.n2.vt == 0x13) {
-                              uVar30 = local_430._8_4_;
-                            }
-                          }
-                          local_400 = 0;
-                          local_3f8 = &local_408;
-                          local_3f0 = 0;
-                          local_3e8 = 0;
-                          local_3e0 = local_3a8;
-                          local_3d8 = &local_3d0;
-                          local_3d0 = 0;
-                          local_3cc = 0;
-                          local_390 = 0;
-                          local_3a8[0] = 0;
-                          local_3a0 = "RemediationActivity";
-                          local_398 = 0;
-                          local_388 = 1;
-                          local_2f0 = 0;
-                          memset(local_380,0,0x90);
-                          local_2e8 = 0;
-                          local_2e0 = 0;
-                          local_2d8 = 0;
-                          local_408 = &TelemetryProvider::RemediationActivity::_vftable_;
-                          p_Var21 = p_Var27;
-                          TelemetryProvider::RemediationActivity::StartActivity
-                                    ((RemediationActivity *)&local_408,(char *)local_538._16_8_,
-                                     (ushort *)p_Var27);
-                          uVar28 = SUB81(p_Var21,0);
-                          TelemetryProvider::ReportRemediationStarted
-                                    ((char *)local_538._16_8_,(ushort *)p_Var27);
-                          uVar11 = ExecutePerformAction((ushort *)p_Var27,uVar30);
-                          if ((int)uVar11 < 0) {
-                            p_Var29 = (_union_2707 *)(ulonglong)uVar11;
-                            p_Var21 = p_Var27;
-                            LogLevelW('\x02',(ushort *)
-                                             L"Plugin \"%s\" failed to perform remediation action with error = 0x%08x"
-                                     );
-                            TelemetryProvider::ReportRemediationFailed
-                                      ((char *)local_538._16_8_,(ushort *)p_Var27,SUB81(p_Var21,0),
-                                       (ushort *)p_Var29,uVar11);
-                            local_558._12_4_ = uVar11;
-                            wil::
-                            ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                            ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                    *)&local_408,uVar11);
-                            local_408 = &TelemetryProvider::RemediationActivity::_vftable_;
-                            goto LAB_7;
-                          }
-                          local_558._12_4_ = 0x244003 - (uVar11 != 0);
-                          TelemetryProvider::ReportRemediationCompleted
-                                    ((char *)local_538._16_8_,(ushort *)p_Var27,(bool)uVar28,
-                                     (ushort *)p_Var29,uVar11);
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                  *)&local_408,0);
-                          local_408 = &TelemetryProvider::RemediationActivity::_vftable_;
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                     *)&local_408);
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::
-                          ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                    ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                      *)&local_408);
-                          uVar5 = local_538.decVal.u2;
-                          if (local_558[3] == '\0') {
-                            iVar14 = (**(code **)(**(longlong **)
-                                                    ((longlong)local_538.decVal.u2 + 0x10) + 0x18))
-                                               (*(longlong **)((longlong)local_538.decVal.u2 + 0x10)
-                                                ,p_Var27,L"PluginRunCount",&local_4f8);
-                            if (-1 < iVar14) {
-                              if (local_4f8.n2.vt != 0x13) {
-                                if (local_4f8.n2.vt == 0) {
-                                  local_4f8.n2.vt = 0x13;
-                                  local_4f8._8_4_ = uVar13;
-                                }
-                                else {
-                                  LogLevelW('\x02',(ushort *)
-                                                                                                      
-                                                  L"Unexpected VARIANT data retrieved for plugin run count. V_VT=%d"
-                                            ,(ulonglong)local_4f8.n2.vt);
-                                  local_4f8._8_4_ = uVar13;
-                                }
-                              }
-                              uVar13 = local_4f8._8_4_ + 1;
-                              plVar2 = *(longlong **)(uVar5 + 0x10);
-                              local_4f8._8_4_ = uVar13;
-                              uVar11 = (**(code **)(*plVar2 + 0x20))
-                                                 (plVar2,p_Var27,L"PluginRunCount",&local_4f8);
-                              if ((int)uVar11 < 0) {
-                                p_Var29 = p_Var27;
-                                LogLevelW('\x02',(ushort *)
-                                                 L"Failed to save state %s for %s! hr = 0x%08x.",
-                                          L"PluginRunCount");
-                                goto LAB_8;
-                              }
-                            }
-                            plVar2 = *(longlong **)(uVar5 + 0x18);
-                            p_Var29 = &local_450;
-                            iVar14 = (**(code **)(*plVar2 + 0x18))(plVar2,p_Var27,L"ACTIONLIMIT");
-                            if (iVar14 < 0) {
-                              pwVar22 = L"ACTIONLIMIT";
-                              pwVar23 = L"Failed to retrieve settings %s! hr = 0x%08x";
-                              uVar20 = '\x03';
-                              uVar13 = local_53c;
-                              goto LAB_6;
-                            }
-                            if (((CONCAT11(local_450.n2.vt._1_1_,local_450.n2.vt._0_1_) == 0x13) &&
-                                (uVar24 = local_450._8_4_, local_450._8_4_ == 0xffffffff)) ||
-                               (uVar13 != uVar24)) {
-                              local_558[5] = '\0';
-                              uVar8 = 0;
-                            }
-                            else {
-                              local_558[5] = '\x01';
-                              uVar8 = 0;
-                            }
+                          uVar30 = 0x78;
+                          if (local_430.n2.vt == 0x13) {
+                            uVar30 = local_430._8_4_;
                           }
                         }
-                      }
-                      else {
-                        local_558[1] = '\0';
-                        TelemetryProvider::ReportDetectionStarted
-                                  ((char *)local_538._16_8_,(ushort *)p_Var27);
                         local_400 = 0;
                         local_3f8 = &local_408;
                         local_3f0 = 0;
                         local_3e8 = 0;
                         local_3e0 = local_3a8;
                         local_3d8 = &local_3d0;
                         local_3d0 = 0;
                         local_3cc = 0;
                         local_390 = 0;
                         local_3a8[0] = 0;
-                        local_3a0 = "DetectionActivity";
+                        local_3a0 = "RemediationActivity";
                         local_398 = 0;
                         local_388 = 1;
                         local_2f0 = 0;
                         memset(local_380,0,0x90);
                         local_2e8 = 0;
                         local_2e0 = 0;
                         local_2d8 = 0;
-                        local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
-                        TelemetryProvider::DetectionActivity::StartActivity
-                                  ((DetectionActivity *)&local_408,(char *)local_538._16_8_,
+                        local_408 = &TelemetryProvider::RemediationActivity::_vftable_;
+                        p_Var21 = p_Var27;
+                        TelemetryProvider::RemediationActivity::StartActivity
+                                  ((RemediationActivity *)&local_408,(char *)local_538._16_8_,
                                    (ushort *)p_Var27);
-                        uVar11 = CSandboxRpcWrapper::SandboxPluginAction
-                                           ((ushort *)p_Var27,(ushort *)L"Plugin_DetectCondition",
-                                            local_558 + 1);
+                        uVar28 = SUB81(p_Var21,0);
+                        TelemetryProvider::ReportRemediationStarted
+                                  ((char *)local_538._16_8_,(ushort *)p_Var27);
+                        uVar11 = ExecutePerformAction((ushort *)p_Var27,uVar30);
                         if ((int)uVar11 < 0) {
-                          local_558[2] = '\x01';
                           p_Var29 = (_union_2707 *)(ulonglong)uVar11;
                           p_Var21 = p_Var27;
-                          LogLevelW('\x02',(ushort *)L"DetectCondition for %s failed! hr = 0x%08x.")
-                          ;
-                          TelemetryProvider::ReportDetectionFailed
+                          LogLevelW('\x02',(ushort *)
+                                           L"Plugin \"%s\" failed to perform remediation action with error = 0x%08x"
+                                   );
+                          TelemetryProvider::ReportRemediationFailed
                                     ((char *)local_538._16_8_,(ushort *)p_Var27,SUB81(p_Var21,0),
                                      (ushort *)p_Var29,uVar11);
-                          uVar13 = ReportPluginError((ushort *)p_Var27,(ushort *)L"Detection",uVar11
-                                                    );
-                          if ((int)uVar13 < 0) {
-                            p_Var29 = (_union_2707 *)(ulonglong)uVar13;
-                            LogLevelW('\x02',(ushort *)
-                                             L"ReportPluginError failed for %s! hr = 0x%08x",p_Var27
-                                     );
-                          }
-                          local_558._8_4_ = uVar11;
+                          local_558._12_4_ = uVar11;
                           wil::
                           ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
                           ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
                                   *)&local_408,uVar11);
-                          local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                     *)&local_408);
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::
-                          ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                    ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                      *)&local_408);
-                          uVar26 = (ulonglong)uVar11;
-                          uVar8 = 0;
+                          local_408 = &TelemetryProvider::RemediationActivity::_vftable_;
+                          goto LAB_7;
                         }
-                        else {
-                          local_558[4] = local_558[1] != '\0';
-                          local_558._8_4_ = 0x248003 - (local_558[1] != '\0');
-                          TelemetryProvider::ReportDetectionCompleted
-                                    ((char *)local_538._16_8_,(ushort *)p_Var27,(bool)local_558[4],
-                                     (ushort *)p_Var29,uVar11);
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                  *)&local_408,0);
-                          if (local_558[4] == '\0') {
-                            LogLevelW('\x04',(ushort *)
-                                             L"Plugin \"%s\" did not detect the remediation condition. Nothing to do."
-                                      ,p_Var27);
-                            local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
+                        local_558._12_4_ = 0x244003 - (uVar11 != 0);
+                        TelemetryProvider::ReportRemediationCompleted
+                                  ((char *)local_538._16_8_,(ushort *)p_Var27,(bool)uVar28,
+                                   (ushort *)p_Var29,uVar11);
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                *)&local_408,0);
+                        local_408 = &TelemetryProvider::RemediationActivity::_vftable_;
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                   *)&local_408);
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::
+                        ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                  ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                    *)&local_408);
+                        uVar5 = local_538.decVal.u2;
+                        if (local_558[3] == '\0') {
+                          iVar14 = (**(code **)(**(longlong **)
+                                                  ((longlong)local_538.decVal.u2 + 0x10) + 0x18))
+                                             (*(longlong **)((longlong)local_538.decVal.u2 + 0x10),
+                                              p_Var27,L"PluginRunCount",&local_4f8);
+                          if (-1 < iVar14) {
+                            if (local_4f8.n2.vt != 0x13) {
+                              if (local_4f8.n2.vt == 0) {
+                                local_4f8.n2.vt = 0x13;
+                                local_4f8._8_4_ = uVar13;
+                              }
+                              else {
+                                LogLevelW('\x02',(ushort *)
+                                                 L"Unexpected VARIANT data retrieved for plugin run count. V_VT=%d"
+                                          ,(ulonglong)local_4f8.n2.vt);
+                                local_4f8._8_4_ = uVar13;
+                              }
+                            }
+                            uVar13 = local_4f8._8_4_ + 1;
+                            plVar2 = *(longlong **)(uVar5 + 0x10);
+                            local_4f8._8_4_ = uVar13;
+                            uVar11 = (**(code **)(*plVar2 + 0x20))
+                                               (plVar2,p_Var27,L"PluginRunCount",&local_4f8);
+                            if ((int)uVar11 < 0) {
+                              p_Var29 = p_Var27;
+                              LogLevelW('\x02',(ushort *)
+                                               L"Failed to save state %s for %s! hr = 0x%08x.",
+                                        L"PluginRunCount");
+                              goto LAB_8;
+                            }
+                          }
+                          plVar2 = *(longlong **)(uVar5 + 0x18);
+                          p_Var29 = &local_450;
+                          iVar14 = (**(code **)(*plVar2 + 0x18))(plVar2,p_Var27,L"ACTIONLIMIT");
+                          if (iVar14 < 0) {
+                            pwVar22 = L"ACTIONLIMIT";
+                            pwVar23 = L"Failed to retrieve settings %s! hr = 0x%08x";
+                            uVar20 = '\x03';
+                            uVar13 = local_53c;
+                            goto LAB_6;
+                          }
+                          if (((CONCAT11(local_450.n2.vt._1_1_,local_450.n2.vt._0_1_) == 0x13) &&
+                              (uVar24 = local_450._8_4_, local_450._8_4_ == 0xffffffff)) ||
+                             (uVar13 != uVar24)) {
+                            local_558[5] = '\0';
+                            uVar8 = 0;
                           }
                           else {
-                            if (local_4a8 != (ulong *)0x0) {
-                              *local_4a8 = *local_4a8 + 1;
-                            }
-                            this_00 = (CWaasRemediation *)0x4;
-                            p_Var21 = p_Var27;
-                            LogLevelW('\x04',(ushort *)
-                                             L"Plugin \"%s\" detected the remediation condition.");
-                            if ((local_518 != (_union_2707 *)0x0) &&
-                               (p_Var21 = local_518, p_Var29 = local_500,
-                               uVar11 = AppendPluginName(this_00,(ushort *)p_Var27,
-                                                         (ushort **)local_518,(__uint64)local_500),
-                               (int)uVar11 < 0)) {
-                              p_Var21 = p_Var27;
-                              p_Var29 = local_518;
-                              LogLevelW('\x02',(ushort *)
-                                               L"Failed to append plugin name \"%s\" to \"%s\"! hr = 0x%08x."
-                                       );
-                            }
-                            local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
-                            if (param_5 != 1) {
-                              wil::
-                              ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                              ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                         *)&local_408);
-                              wil::
-                              ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                              ::
-                              ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                        ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                          *)&local_408);
-                              goto LAB_5;
-                            }
+                            local_558[5] = '\x01';
+                            uVar8 = 0;
                           }
-LAB_7:
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                     *)&local_408);
-                          wil::
-                          ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                          ::
-                          ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                    ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
-                                      *)&local_408);
                         }
                       }
                     }
                     else {
-                      uVar11 = CSandboxRpcWrapper::CreateSandbox((CSandboxRpcWrapper *)&local_4e0);
+                      local_558[1] = '\0';
+                      TelemetryProvider::ReportDetectionStarted
+                                ((char *)local_538._16_8_,(ushort *)p_Var27);
+                      local_400 = 0;
+                      local_3f8 = &local_408;
+                      local_3f0 = 0;
+                      local_3e8 = 0;
+                      local_3e0 = local_3a8;
+                      local_3d8 = &local_3d0;
+                      local_3d0 = 0;
+                      local_3cc = 0;
+                      local_390 = 0;
+                      local_3a8[0] = 0;
+                      local_3a0 = "DetectionActivity";
+                      local_398 = 0;
+                      local_388 = 1;
+                      local_2f0 = 0;
+                      memset(local_380,0,0x90);
+                      local_2e8 = 0;
+                      local_2e0 = 0;
+                      local_2d8 = 0;
+                      local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
+                      TelemetryProvider::DetectionActivity::StartActivity
+                                ((DetectionActivity *)&local_408,(char *)local_538._16_8_,
+                                 (ushort *)p_Var27);
+                      uVar11 = CSandboxRpcWrapper::SandboxPluginAction
+                                         ((ushort *)p_Var27,(ushort *)L"Plugin_DetectCondition",
+                                          local_558 + 1);
+                      if ((int)uVar11 < 0) {
+                        local_558[2] = '\x01';
+                        p_Var29 = (_union_2707 *)(ulonglong)uVar11;
+                        p_Var21 = p_Var27;
+                        LogLevelW('\x02',(ushort *)L"DetectCondition for %s failed! hr = 0x%08x.");
+                        TelemetryProvider::ReportDetectionFailed
+                                  ((char *)local_538._16_8_,(ushort *)p_Var27,SUB81(p_Var21,0),
+                                   (ushort *)p_Var29,uVar11);
+                        uVar13 = ReportPluginError((ushort *)p_Var27,(ushort *)L"Detection",uVar11);
+                        if ((int)uVar13 < 0) {
+                          p_Var29 = (_union_2707 *)(ulonglong)uVar13;
+                          LogLevelW('\x02',(ushort *)L"ReportPluginError failed for %s! hr = 0x%08x"
+                                    ,p_Var27);
+                        }
+                        local_558._8_4_ = uVar11;
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                *)&local_408,uVar11);
+                        local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                   *)&local_408);
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::
+                        ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                  ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                    *)&local_408);
+                        uVar26 = (ulonglong)uVar11;
+                        uVar8 = 0;
+                      }
+                      else {
+                        local_558[4] = local_558[1] != '\0';
+                        local_558._8_4_ = 0x248003 - (local_558[1] != '\0');
+                        TelemetryProvider::ReportDetectionCompleted
+                                  ((char *)local_538._16_8_,(ushort *)p_Var27,(bool)local_558[4],
+                                   (ushort *)p_Var29,uVar11);
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                *)&local_408,0);
+                        if (local_558[4] == '\0') {
+                          LogLevelW('\x04',(ushort *)
+                                           L"Plugin \"%s\" did not detect the remediation condition. Nothing to do."
+                                    ,p_Var27);
+                          local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
+                        }
+                        else {
+                          if (local_4a8 != (ulong *)0x0) {
+                            *local_4a8 = *local_4a8 + 1;
+                          }
+                          this_00 = (CWaasRemediation *)0x4;
+                          p_Var21 = p_Var27;
+                          LogLevelW('\x04',(ushort *)
+                                           L"Plugin \"%s\" detected the remediation condition.");
+                          if ((local_518 != (_union_2707 *)0x0) &&
+                             (p_Var21 = local_518, p_Var29 = local_500,
+                             uVar11 = AppendPluginName(this_00,(ushort *)p_Var27,
+                                                       (ushort **)local_518,(__uint64)local_500),
+                             (int)uVar11 < 0)) {
+                            p_Var21 = p_Var27;
+                            p_Var29 = local_518;
+                            LogLevelW('\x02',(ushort *)
+                                             L"Failed to append plugin name \"%s\" to \"%s\"! hr = 0x%08x."
+                                     );
+                          }
+                          local_408 = &TelemetryProvider::DetectionActivity::_vftable_;
+                          if (param_5 != 1) {
+                            wil::
+                            ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                            ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                       *)&local_408);
+                            wil::
+                            ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                            ::
+                            ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                      ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                        *)&local_408);
+                            goto LAB_5;
+                          }
+                        }
+LAB_7:
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                   *)&local_408);
+                        wil::
+                        ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                        ::
+                        ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                  ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
+                                    *)&local_408);
+                      }
+                    }
+                  }
+                  else {
+                    uVar11 = CSandboxRpcWrapper::CreateSandbox((CSandboxRpcWrapper *)&local_4e0);
+                    uVar19 = (ulonglong)uVar11;
+                    if ((int)uVar11 < 0) {
+                      p_Var29 = (_union_2707 *)(ulonglong)uVar11;
+                      LogLevelW('\x02',(ushort *)
+                                       L"Failed to create sandbox process for %s.  hr = 0x%08x",
+                                p_Var27);
+                    }
+                    else {
+                      lVar9 = CSandboxRpcWrapper::ConnectToSandbox((CSandboxRpcWrapper *)&local_4e0)
+                      ;
+                      if (lVar9 < 1) {
+                        uVar11 = CSandboxRpcWrapper::ConnectToSandbox
+                                           ((CSandboxRpcWrapper *)&local_4e0);
+                      }
+                      else {
+                        uVar11 = CSandboxRpcWrapper::ConnectToSandbox
+                                           ((CSandboxRpcWrapper *)&local_4e0);
+                        uVar11 = uVar11 & 0xffff | 0x80010000;
+                      }
                       uVar19 = (ulonglong)uVar11;
                       if ((int)uVar11 < 0) {
-                        p_Var29 = (_union_2707 *)(ulonglong)uVar11;
-                        LogLevelW('\x02',(ushort *)
-                                         L"Failed to create sandbox process for %s.  hr = 0x%08x",
-                                  p_Var27);
+                        LogLevelW('\x02',(ushort *)L"Unable to establish connection hr = 0x%08x",
+                                  uVar19);
                       }
                       else {
-                        lVar9 = CSandboxRpcWrapper::ConnectToSandbox
-                                          ((CSandboxRpcWrapper *)&local_4e0);
-                        if (lVar9 < 1) {
-                          uVar11 = CSandboxRpcWrapper::ConnectToSandbox
-                                             ((CSandboxRpcWrapper *)&local_4e0);
+                        uVar11 = CSandboxRpcWrapper::SandboxLoadLibrary(local_4b0);
+                        uVar19 = (ulonglong)uVar11;
+                        if (-1 < (int)uVar11) {
+                          local_558[2] = '\0';
+                          goto LAB_4;
                         }
-                        else {
-                          uVar11 = CSandboxRpcWrapper::ConnectToSandbox
-                                             ((CSandboxRpcWrapper *)&local_4e0);
-                          uVar11 = uVar11 & 0xffff | 0x80010000;
-                        }
-                        uVar19 = (ulonglong)uVar11;
-                        if ((int)uVar11 < 0) {
-                          LogLevelW('\x02',(ushort *)L"Unable to establish connection hr = 0x%08x",
-                                    uVar19);
-                        }
-                        else {
-                          uVar11 = CSandboxRpcWrapper::SandboxLoadLibrary(local_4b0);
-                          uVar19 = (ulonglong)uVar11;
-                          if (-1 < (int)uVar11) {
-                            local_558[2] = '\0';
-                            goto LAB_4;
-                          }
-                          LogLevelW('\x02',(ushort *)L"Failed to load library on the WaaSMedicAgent"
-                                   );
-                        }
+                        LogLevelW('\x02',(ushort *)L"Failed to load library on the WaaSMedicAgent");
                       }
-                      uVar8 = (uint)uVar19;
-                      uVar26 = uVar19;
-                      uVar11 = uVar8;
                     }
+                    uVar8 = (uint)uVar19;
+                    uVar26 = uVar19;
+                    uVar11 = uVar8;
                   }
                 }
+              }
 LAB_8:
-                uVar24 = uVar11;
-                if (((int)uVar24 < 0) && (local_4a0 != (ulong *)0x0)) {
-                  *local_4a0 = *local_4a0 + 1;
-                }
-              }
-              uVar5 = local_538.decVal.u2;
-              uVar13 = (uint)uVar26;
-              if ((local_470.n2.vt == 8) && (local_470.decVal.u2.Lo64 != 0)) {
-                p_Var29 = &local_470;
-                iVar14 = (**(code **)(**(longlong **)((longlong)local_538.decVal.u2 + 0x10) + 0x20))
-                                   (*(longlong **)((longlong)local_538.decVal.u2 + 0x10),p_Var27,
-                                    L"LastDetectionRunTime");
-                if (iVar14 < 0) {
-                  p_Var29 = p_Var27;
-                  LogLevelW('\x02',(ushort *)L"Failed to save state %s for %s!",
-                            L"LastDetectionRunTime");
-                }
-              }
-              if ((local_488.n2.vt == 8) && (local_488.decVal.u2.Lo64 != 0)) {
-                p_Var29 = &local_488;
-                iVar14 = (**(code **)(**(longlong **)(uVar5 + 0x10) + 0x20))
-                                   (*(longlong **)(uVar5 + 0x10),p_Var27,L"LastRemediationRunTime");
-                if (iVar14 < 0) {
-                  p_Var29 = p_Var27;
-                  LogLevelW('\x02',(ushort *)L"Failed to save state %s for %s!",
-                            L"LastRemediationRunTime");
-                }
-              }
-              SafeFree((void *)0x0);
-              if (*(longlong *)(uVar5 + 0x20) != 0) {
-                piVar1 = (int *)(*(longlong *)(uVar5 + 0x20) + 0x80);
+              uVar24 = uVar11;
+              if (((int)uVar24 < 0) && (local_4a0 != (ulong *)0x0)) {
+                *local_4a0 = *local_4a0 + 1;
+              }
+            }
+            uVar5 = local_538.decVal.u2;
+            uVar13 = (uint)uVar26;
+            if ((local_470.n2.vt == 8) && (local_470.decVal.u2.Lo64 != 0)) {
+              p_Var29 = &local_470;
+              iVar14 = (**(code **)(**(longlong **)((longlong)local_538.decVal.u2 + 0x10) + 0x20))
+                                 (*(longlong **)((longlong)local_538.decVal.u2 + 0x10),p_Var27,
+                                  L"LastDetectionRunTime");
+              if (iVar14 < 0) {
+                p_Var29 = p_Var27;
+                LogLevelW('\x02',(ushort *)L"Failed to save state %s for %s!",
+                          L"LastDetectionRunTime");
+              }
+            }
+            if ((local_488.n2.vt == 8) && (local_488.decVal.u2.Lo64 != 0)) {
+              p_Var29 = &local_488;
+              iVar14 = (**(code **)(**(longlong **)(uVar5 + 0x10) + 0x20))
+                                 (*(longlong **)(uVar5 + 0x10),p_Var27,L"LastRemediationRunTime");
+              if (iVar14 < 0) {
+                p_Var29 = p_Var27;
+                LogLevelW('\x02',(ushort *)L"Failed to save state %s for %s!",
+                          L"LastRemediationRunTime");
+              }
+            }
+            SafeFree((void *)0x0);
+            if (*(longlong *)(uVar5 + 0x20) != 0) {
+              piVar1 = (int *)(*(longlong *)(uVar5 + 0x20) + 0x80);
+              *piVar1 = *piVar1 + 1;
+              puVar18 = *(undefined8 **)(uVar5 + 0x20);
+              if ((CJsonHelper *)*puVar18 != (CJsonHelper *)0x0) {
+                CJsonHelper::SetValue((CJsonHelper *)*puVar18,(ushort *)p_Var27,uVar8);
+                puVar18 = *(undefined8 **)(uVar5 + 0x20);
+              }
+              if ((CJsonHelper *)puVar18[1] != (CJsonHelper *)0x0) {
+                CJsonHelper::SetValue((CJsonHelper *)puVar18[1],(ushort *)p_Var27,local_558._8_4_);
+                puVar18 = *(undefined8 **)(uVar5 + 0x20);
+              }
+              if ((CJsonHelper *)puVar18[4] != (CJsonHelper *)0x0) {
+                CJsonHelper::SetValue((CJsonHelper *)puVar18[4],(ushort *)p_Var27,local_558._12_4_);
+              }
+              if ((int)uVar24 < 0) {
+                piVar1 = (int *)(*(longlong *)(uVar5 + 0x20) + 0x84);
                 *piVar1 = *piVar1 + 1;
-                puVar18 = *(undefined8 **)(uVar5 + 0x20);
-                if ((CJsonHelper *)*puVar18 != (CJsonHelper *)0x0) {
-                  CJsonHelper::SetValue((CJsonHelper *)*puVar18,(ushort *)p_Var27,uVar8);
-                  puVar18 = *(undefined8 **)(uVar5 + 0x20);
-                }
-                if ((CJsonHelper *)puVar18[1] != (CJsonHelper *)0x0) {
-                  CJsonHelper::SetValue((CJsonHelper *)puVar18[1],(ushort *)p_Var27,local_558._8_4_)
-                  ;
-                  puVar18 = *(undefined8 **)(uVar5 + 0x20);
-                }
-                if ((CJsonHelper *)puVar18[4] != (CJsonHelper *)0x0) {
-                  CJsonHelper::SetValue
-                            ((CJsonHelper *)puVar18[4],(ushort *)p_Var27,local_558._12_4_);
-                }
-                if ((int)uVar24 < 0) {
-                  piVar1 = (int *)(*(longlong *)(uVar5 + 0x20) + 0x84);
-                  *piVar1 = *piVar1 + 1;
-                }
-                if ((int)uVar13 < 0) {
-                  *(uint *)(*(longlong *)(uVar5 + 0x20) + 0x68) = uVar13;
-                }
-              }
-              if (local_558[3] == '\0') {
-                uVar8 = local_548[1];
-                if ((((-1 < (int)uVar24) && (local_520 == 3)) && (local_558[0] != '\0')) &&
-                   ((local_558[4] != '\0' && (uVar8 = local_548[1] & 0xff, local_558[5] != '\0'))))
-                {
-                  uVar8 = 1;
-                }
-                if (local_498 != (bool *)0x0) {
-                  *local_498 = (bool)(*local_498 & (byte)uVar8);
-                }
-              }
-              HVar15 = VariantClear((VARIANTARG *)&local_430.n2);
-              if (HVar15 < 0) {
+              }
+              if ((int)uVar13 < 0) {
+                *(uint *)(*(longlong *)(uVar5 + 0x20) + 0x68) = uVar13;
+              }
+            }
+            if (local_558[3] == '\0') {
+              uVar8 = local_548[1];
+              if ((((-1 < (int)uVar24) && (local_520 == 3)) && (local_558[0] != '\0')) &&
+                 ((local_558[4] != '\0' && (uVar8 = local_548[1] & 0xff, local_558[5] != '\0')))) {
+                uVar8 = 1;
+              }
+              if (local_498 != (bool *)0x0) {
+                *local_498 = (bool)(*local_498 & (byte)uVar8);
+              }
+            }
+            HVar15 = VariantClear((VARIANTARG *)&local_430.n2);
+            if (HVar15 < 0) {
                     /* WARNING: Subroutine does not return */
-                _com_issue_error(HVar15);
-              }
-              HVar15 = VariantClear((VARIANTARG *)&local_450.n2);
-              if (HVar15 < 0) {
+              _com_issue_error(HVar15);
+            }
+            HVar15 = VariantClear((VARIANTARG *)&local_450.n2);
+            if (HVar15 < 0) {
                     /* WARNING: Subroutine does not return */
-                _com_issue_error(HVar15);
-              }
-              HVar15 = VariantClear((VARIANTARG *)&local_4f8.n2);
-              if (HVar15 < 0) {
+              _com_issue_error(HVar15);
+            }
+            HVar15 = VariantClear((VARIANTARG *)&local_4f8.n2);
+            if (HVar15 < 0) {
                     /* WARNING: Subroutine does not return */
-                _com_issue_error(HVar15);
-              }
-              HVar15 = VariantClear((VARIANTARG *)&local_488.n2);
-              if (HVar15 < 0) {
+              _com_issue_error(HVar15);
+            }
+            HVar15 = VariantClear((VARIANTARG *)&local_488.n2);
+            if (HVar15 < 0) {
                     /* WARNING: Subroutine does not return */
-                _com_issue_error(HVar15);
-              }
-              HVar15 = VariantClear((VARIANTARG *)&local_470.n2);
-              if (HVar15 < 0) {
+              _com_issue_error(HVar15);
+            }
+            HVar15 = VariantClear((VARIANTARG *)&local_470.n2);
+            if (HVar15 < 0) {
                     /* WARNING: Subroutine does not return */
-                _com_issue_error(HVar15);
-              }
-              local_51c = local_51c + 1;
-              uVar19 = (ulonglong)local_51c;
-              param_3 = local_490;
-            } while ((int)local_51c < local_548[0]);
-          }
-          goto LAB_1;
+              _com_issue_error(HVar15);
+            }
+            local_51c = local_51c + 1;
+            uVar19 = (ulonglong)local_51c;
+            param_3 = local_490;
+          } while ((int)local_51c < local_548[0]);
         }
       }
-      LogLevelW('\x02',(ushort *)L"Failed to initialize sandbox.  hr = 0x%08x",(ulonglong)uVar8);
-      uVar13 = uVar8;
       goto LAB_1;
     }
   }
   LogLevelW('\x02',(ushort *)L"Plugin enumeration failed or nullptr returned.  hr=0x%08x",
             (ulonglong)uVar11);
   wil::
   ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
   ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
           *)&local_2c8,uVar11);
   uVar13 = 0;
 LAB_1:
   uVar8 = CSandboxRpcWrapper::SandBoxFreePluginLibrary();
   if (((int)uVar8 < 0) &&
      (LogLevelW('\x02',(ushort *)L"SandBoxFreePluginLibrary failed. hr = 0x%08x",(ulonglong)uVar8),
      -1 < (int)uVar13)) {
     uVar13 = uVar8;
   }
   wil::
   ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
   ::Stop((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
           *)&local_188,uVar13);
   local_2c8 = &TelemetryProvider::EnumeratePluginActivity::_vftable_;
   wil::
   ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
   ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
              *)&local_2c8);
   wil::
   ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
   ::
   ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
             ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
               *)&local_2c8);
   local_188 = &TelemetryProvider::SandboxActivity::_vftable_;
   wil::
   ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
   ::Destroy((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
              *)&local_188);
   wil::
   ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
   ::
   ~ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
             ((ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>
               *)&local_188);
   CSandboxRpcWrapper::SandBoxShutdown((CSandboxRpcWrapper *)&local_4e0);
-  if (local_4e0 != (LPVOID)0x0) {
-    CoTaskMemFree(local_4e0);
-    local_4e0 = (LPVOID)0x0;
+  if (local_4e0 != (void *)0x0) {
+    SafeFree(local_4e0);
   }
   SafeFree(pvStack_4d8);
   pvStack_4d8 = (void *)0x0;
   if ((longlong)pvStack_4c8 - 1U < 0xfffffffffffffffe) {
     CloseHandle(pvStack_4c8);
   }
   return uVar8;
 }
 

```


# Modified (No Code Changes)


*Slightly modified functions have no code changes, rather differnces in:*
- refcount
- length
- called
- calling
- name
- fullname

## __local_stdio_printf_options

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|__local_stdio_printf_options|__local_stdio_printf_options|
|fullname|__local_stdio_printf_options|__local_stdio_printf_options|
|`refcount`|7|8|
|length|8|8|
|called|||
|`calling`|__scrt_initialize_default_local_stdio_options<br>_vsnprintf<br>_vsnprintf_s<br>_vsnwprintf<br>initialize_legacy_wide_specifiers<br>initialize_msvcrt_compatibility<br>sprintf_s|__scrt_initialize_default_local_stdio_options<br>_vsnprintf<br>_vsnprintf_s<br>_vsnwprintf<br>initialize_legacy_wide_specifiers<br>initialize_msvcrt_compatibility<br>sprintf_s<br>swprintf_s|
|paramcount|0|0|
|`address`|18002c934|18002d4f4|
|sig|__uint64 * __fastcall __local_stdio_printf_options(void)|__uint64 * __fastcall __local_stdio_printf_options(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### __local_stdio_printf_options Calling Diff


```diff
--- __local_stdio_printf_options calling
+++ __local_stdio_printf_options calling
@@ -7,0 +8 @@
+swprintf_s
```


## basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.84|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|fullname|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|`refcount`|13|18|
|length|133|133|
|called|memmove<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*>|memmove<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*>|
|`calling`|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_AddFileToMap<br>CreatePath<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule</summary>WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs</details>|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_AddFileToMap<br>CreatePath<br>WaasMedic::CSandboxRpcWrapper::CreateSandbox<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly</summary>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs<br>WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString<br>WaasMedic::ValidateOriginalFileName</details>|
|paramcount|2|2|
|`address`|18000b6dc|18000b70c|
|sig|undefined __thiscall basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this, ushort * param_1)|undefined __thiscall basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this, ushort * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> Calling Diff


```diff
--- std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> calling
+++ std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> calling
@@ -2,0 +3 @@
+WaasMedic::CSandboxRpcWrapper::CreateSandbox
@@ -12,0 +14,3 @@
+WaasMedic::GetRandomString
+WaasMedic::GetSha256HashOfString
+WaasMedic::ValidateOriginalFileName
```


## API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|LocalFree|LocalFree|
|fullname|API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree|API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree|
|`refcount`|8|9|
|length|0|0|
|called|||
|`calling`|CreatePath<br>SP<unsigned_char,SP_HLOCAL<unsigned_char>_>::Reset<br>WaasMedic::CProtectionUtil::ApplyPermissionsOnRegistryKey<br>WaasMedic::CProtectionUtil::ApplySecurityDescriptorOnRegistrySubkey<br>_com_error::`vector_deleting_destructor'<br>_com_error::~_com_error<br>wil::unique_any_t<wil::details::unique_storage<wil::details::resource_policy<void*___ptr64,void*___ptr64_(__cdecl*)(void*___ptr64),&void*___ptr64___cdecl_LocalFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<wil::details::unique_storage<wil::details::resource_policy<void*___ptr64,void*___ptr64_(__cdecl*)(void*___ptr64),&void*___ptr64___cdecl_LocalFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>_>|CreatePath<br>SP<unsigned_char,SP_HLOCAL<unsigned_char>_>::Reset<br>WaasMedic::CProtectionUtil::ApplyPermissionsOnRegistryKey<br>WaasMedic::CProtectionUtil::ApplySecurityDescriptorOnRegistrySubkey<br>WaasMedic::ValidateOriginalFileName<br>_com_error::`vector_deleting_destructor'<br>_com_error::~_com_error<br>wil::unique_any_t<wil::details::unique_storage<wil::details::resource_policy<void*___ptr64,void*___ptr64_(__cdecl*)(void*___ptr64),&void*___ptr64___cdecl_LocalFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<wil::details::unique_storage<wil::details::resource_policy<void*___ptr64,void*___ptr64_(__cdecl*)(void*___ptr64),&void*___ptr64___cdecl_LocalFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>_>|
|paramcount|1|1|
|`address`|EXTERNAL:000000c5|EXTERNAL:000000cc|
|sig|HLOCAL __stdcall LocalFree(HLOCAL hMem)|HLOCAL __stdcall LocalFree(HLOCAL hMem)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree Calling Diff


```diff
--- API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree calling
+++ API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalFree calling
@@ -4,0 +5 @@
+WaasMedic::ValidateOriginalFileName
```


## StringCchPrintfW

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|0.98|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|StringCchPrintfW|StringCchPrintfW|
|fullname|StringCchPrintfW|StringCchPrintfW|
|`refcount`|29|31|
|length|118|118|
|called|_vsnwprintf|_vsnwprintf|
|`calling`|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_CreateLogFileName<br>VersionSPrintfHelper<br>WaasMedic::CSettingsProvider::Clear<br>WaasMedic::CSettingsProvider::GetValue<br>WaasMedic::CSettingsProvider::SetValue<br>WaasMedic::CStateProvider::Clear<br>WaasMedic::CStateProvider::GetValue<br>WaasMedic::CStateProvider::SetValue<br>WaasMedic::CWERReporter::EnumerateAndAddFilesToWerReport<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWERReporter::GetTemporaryLogFilePath</summary>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CopyDirectory<br>WaasMedic::OneSettings::InitializeMachineProperties<br>WaasMedic::OneSettings::ParseJsonBlob<br>WaasMedic::RegGetPersistedRootPath<br>WaasMedic::RegGetPersistedSubkeyPath<br>`wil::details::RecognizeCaughtExceptionFromCallback'::__l1::catch$0<br>`wil::details::ResultFromCaughtExceptionInternal'::__l1::catch$1<br>`wil::details::ResultFromCaughtExceptionInternal'::__l1::catch$4<br>`wil::details::ResultFromCaughtExceptionInternal'::__l1::catch$5<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::Acquire</details>|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_CreateLogFileName<br>VersionSPrintfHelper<br>WaasMedic::CSettingsProvider::Clear<br>WaasMedic::CSettingsProvider::GetValue<br>WaasMedic::CSettingsProvider::SetValue<br>WaasMedic::CStateProvider::Clear<br>WaasMedic::CStateProvider::GetValue<br>WaasMedic::CStateProvider::SetValue<br>WaasMedic::CWERReporter::EnumerateAndAddFilesToWerReport<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWERReporter::GetTemporaryLogFilePath</summary>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CopyDirectory<br>WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString<br>WaasMedic::OneSettings::InitializeMachineProperties<br>WaasMedic::OneSettings::ParseJsonBlob<br>WaasMedic::RegGetPersistedRootPath<br>WaasMedic::RegGetPersistedSubkeyPath<br>`wil::details::RecognizeCaughtExceptionFromCallback'::__l1::catch$0<br>`wil::details::ResultFromCaughtExceptionInternal'::__l1::catch$1<br>`wil::details::ResultFromCaughtExceptionInternal'::__l1::catch$4<br>`wil::details::ResultFromCaughtExceptionInternal'::__l1::catch$5<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::Acquire</details>|
|paramcount|3|3|
|address|1800014f8|1800014f8|
|sig|long __cdecl StringCchPrintfW(ushort * param_1, __uint64 param_2, ushort * param_3, ...)|long __cdecl StringCchPrintfW(ushort * param_1, __uint64 param_2, ushort * param_3, ...)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### StringCchPrintfW Calling Diff


```diff
--- StringCchPrintfW calling
+++ StringCchPrintfW calling
@@ -13,0 +14,2 @@
+WaasMedic::GetRandomString
+WaasMedic::GetSha256HashOfString
```


## API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|VerQueryValueW|VerQueryValueW|
|fullname|API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW|API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW|
|`refcount`|2|4|
|length|0|0|
|called|||
|`calling`|GetOSVersionFromFile|GetOSVersionFromFile<br>WaasMedic::ValidateOriginalFileName|
|paramcount|4|4|
|`address`|EXTERNAL:000000f6|EXTERNAL:000000cb|
|sig|BOOL __stdcall VerQueryValueW(LPCVOID pBlock, LPCWSTR lpSubBlock, LPVOID * lplpBuffer, PUINT puLen)|BOOL __stdcall VerQueryValueW(LPCVOID pBlock, LPCWSTR lpSubBlock, LPVOID * lplpBuffer, PUINT puLen)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW Calling Diff


```diff
--- API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW calling
+++ API-MS-WIN-CORE-VERSION-L1-1-0.DLL::VerQueryValueW calling
@@ -1,0 +2 @@
+WaasMedic::ValidateOriginalFileName
```


## API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|_o__wcsicmp|_o__wcsicmp|
|fullname|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp|
|`refcount`|12|13|
|length|0|0|
|called|||
|`calling`|RtlpFindNamedVerChild<br>WaasMedic::CSettingsProvider::GetSettingsVarTypeFromName<br>WaasMedic::CWERReporter::EnumerateAndAddFilesToWerReport<br>WaasMedic::CWERReporter::NeedToSkipWERReport<br>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CWERReporter::ReportError<br>WaasMedic::CopyDirectory<br>WaasMedic::RegGetPersistedRootPath|RtlpFindNamedVerChild<br>WaasMedic::CSettingsProvider::GetSettingsVarTypeFromName<br>WaasMedic::CWERReporter::EnumerateAndAddFilesToWerReport<br>WaasMedic::CWERReporter::NeedToSkipWERReport<br>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CWERReporter::ReportError<br>WaasMedic::CopyDirectory<br>WaasMedic::RegGetPersistedRootPath<br>WaasMedic::ValidateOriginalFileName|
|paramcount|0|0|
|address|EXTERNAL:0000000d|EXTERNAL:0000000d|
|sig|undefined _o__wcsicmp(void)|undefined _o__wcsicmp(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp Calling Diff


```diff
--- API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp calling
+++ API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__wcsicmp calling
@@ -8,0 +9 @@
+WaasMedic::ValidateOriginalFileName
```


## dtor$0

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|dtor$0|dtor$0|
|fullname|`WaasMedic::CWaasRemediation::SetPluginDefaultSettings'::__l1::dtor$0|`WaasMedic::CWaasRemediation::SetPluginDefaultSettings'::__l1::dtor$0|
|`refcount`|1|2|
|length|12|12|
|called|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling|||
|paramcount|2|2|
|`address`|18002ea9f|18002f6cf|
|sig|undefined __fastcall dtor$0(undefined8 param_1, longlong param_2)|undefined __fastcall dtor$0(undefined8 param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## __security_check_cookie

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|__security_check_cookie|__security_check_cookie|
|fullname|__security_check_cookie|__security_check_cookie|
|`refcount`|141|145|
|length|33|33|
|called|__report_gsfailure|__report_gsfailure|
|`calling`|<details><summary>Expand for full list:<br>CCorrelationVectorHelper::SetAndExtendCV<br>CJsonHelper::Init<br>CJsonHelper::_GetValue<<lambda_142bbb5a18063f8f3b48ec9338a7e8dc>_><br>CJsonHelper::_SetValue<br>CMedicEtwConsumer::_AddFileToMap<br>CMedicEtwConsumer::_CreateLogFileName<br>CMedicEtwConsumer::_GetExistingLogFiles<br>CMedicEtwConsumer::_StartTracing<br>CreatePath<br>GetMedicLogDir<br>GetOSVersionFromFile</summary>GetTraceSettingsRegKey<br>LogLevelA<br>LogLevelW<br>TraceLoggingCorrelationVector::TraceLoggingCorrelationVector<br>TraceLoggingCorrelationVector::TraceLoggingCorrelationVector<br>TraceLoggingCorrelationVector::ValidateImpl<br>TraceLoggingRegister<br>VersionSPrintfHelper<br>WaaSRemediationAgent::LaunchDetectionOnly<br>WaaSRemediationAgent::LaunchRemediation<br>WaaSRemediationAgent::LaunchRemediationHelper<br>WaaSRemediationAgent::LaunchRemediationOnly<br>WaaSRemediationAgent::SetAndExtendCV<br>WaasMedic::CSandboxRpcWrapper::CreateSandbox<br>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CSettingsProvider::Clear<br>WaasMedic::CSettingsProvider::GetValue<br>WaasMedic::CSettingsProvider::SetValue<br>WaasMedic::CStateProvider::Clear<br>WaasMedic::CStateProvider::GetValue<br>WaasMedic::CStateProvider::SetValue<br>WaasMedic::CSvcUtil::ServiceStop<br>WaasMedic::CSvcUtil::VerifyServiceState<br>WaasMedic::CSvcUtil::WaitForServiceState<br>WaasMedic::CWERReporter::AddDirectoriesToWERReport<br>WaasMedic::CWERReporter::CopyLogsDirToTempDir<br>WaasMedic::CWERReporter::CreateWERReport<br>WaasMedic::CWERReporter::EnumerateAndAddFilesToWerReport<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWERReporter::GetTemporaryLogFilePath<br>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CWERReporter::ReportError<br>WaasMedic::CWaasMedic::LaunchRemediation<br>WaasMedic::CWaasMedic::SetAndExtendCV<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Init<br>WaasMedic::CWaasRemediation::LoadPluginLibrary<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings<br>WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs<br>WaasMedic::CloudSettingsProvider::Init<br>WaasMedic::CloudSettingsProvider::Run<br>WaasMedic::CopyDirectory<br>WaasMedic::MiscUtil::PopulateClientVersionString<br>WaasMedic::OneSettings::GetCloudSettings<br>WaasMedic::OneSettings::Initialize<br>WaasMedic::OneSettings::InitializeMachineProperties<br>WaasMedic::OneSettings::ParseJsonBlob<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath<br>WaasMedic::RegCreateKeyHelperPrivate<br>WaasMedic::RegDelAllValuesInKey<br>WaasMedic::RegDelTree<br>WaasMedic::RegDelValue<br>WaasMedic::RegGetPersistedRootPath<br>WaasMedic::RegGetPersistedSubkeyPath<br>WaasMedic::RegGetValueAsVariant<br>WaasMedic::RegSetValueFromVariant<br>WaasMedic::RegSetValue_Helper<br>WaasMedic::SafeRegQueryValueCchAllocHelper<br>WaasMedic::SafeRegQueryValueCchHelper<br>WaasMedic::TasksHelper::CreateOrUpdateTask<br>WaasMedic::TasksHelper::DeleteTask<br>WaasMedic::TasksHelper::EnableTask<br>WaasMedic::TasksHelper::Initialize<br>WaasMedic::TelemetryCoreProvider::ReportSummary<br>WaasMedic::TelemetryProvider::DetectionActivity::StartActivity<br>WaasMedic::TelemetryProvider::DetectionActivity::StopActivity<br>WaasMedic::TelemetryProvider::EnumeratePluginActivity::StartActivity<br>WaasMedic::TelemetryProvider::EnumeratePluginActivity::StopActivity<br>WaasMedic::TelemetryProvider::RemediationActivity::StartActivity<br>WaasMedic::TelemetryProvider::RemediationActivity::StopActivity<br>WaasMedic::TelemetryProvider::ReportDetectionCompleted<br>WaasMedic::TelemetryProvider::ReportDetectionFailed<br>WaasMedic::TelemetryProvider::ReportDetectionStarted<br>WaasMedic::TelemetryProvider::ReportDetectionsOnlyCompleted<br>WaasMedic::TelemetryProvider::ReportDetectionsOnlyFailed<br>WaasMedic::TelemetryProvider::ReportDetectionsOnlyStarted<br>WaasMedic::TelemetryProvider::ReportEngineCompleted<br>WaasMedic::TelemetryProvider::ReportEngineFailed<br>WaasMedic::TelemetryProvider::ReportEngineStarted<br>WaasMedic::TelemetryProvider::ReportRegUtilQueryValueFailed<br>WaasMedic::TelemetryProvider::ReportRegistryKeyProtectionResult<br>WaasMedic::TelemetryProvider::ReportRegistryValueProtectionResult<br>WaasMedic::TelemetryProvider::ReportRemediationCompleted<br>WaasMedic::TelemetryProvider::ReportRemediationFailed<br>WaasMedic::TelemetryProvider::ReportRemediationStarted<br>WaasMedic::TelemetryProvider::ReportRemediationsOnlyCompleted<br>WaasMedic::TelemetryProvider::ReportRemediationsOnlyFailed<br>WaasMedic::TelemetryProvider::ReportRemediationsOnlyStarted<br>WaasMedic::TelemetryProvider::ReportSecurityDescriptorProtectionResult<br>WaasMedic::TelemetryProvider::ReportTaskProtectionResult<br>WaasMedic::TelemetryProvider::SandboxActivity::StartActivity<br>WaasMedic::TelemetryProvider::SandboxActivity::StopActivity<br>WaasMedic::TimeHelper::FileTimeToString<br>WaasMedic::TimeHelper::FileTimeToVariant<br>WaasMedic::TimeHelper::StringToFileTime<br>WaasMedic::WaasCurrencyDetector::ComputeCurrencyState<br>WaasMedic::WaasCurrencyDetector::Run<br>_LogMsgErrorA<br>_LogMsgErrorW<br>_LogMsgInfoA<br>_LogMsgInfoW<br>_LogMsgVerboseA<br>_LogMsgVerboseW<br>_LogMsgWarningA<br>_LogMsgWarningW<br>_TlgWriteActivityAutoStop<70368744177664,5><br>__GSHandlerCheckCommon<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::NotifyFailure<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::Stop<br>wil::GetFailureLogString<br>wil::ResultException::what<br>wil::TraceLoggingProvider::ReportTelemetryFailure<br>wil::TraceLoggingProvider::ReportTraceLoggingFailure<br>wil::details::GetModuleInformation<br>wil::details::ReportFailure<br>wil::details::ReportFailure_CaughtException<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::MakeAndInitialize<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64></details>|<details><summary>Expand for full list:<br>CCorrelationVectorHelper::SetAndExtendCV<br>CJsonHelper::Init<br>CJsonHelper::_GetValue<<lambda_142bbb5a18063f8f3b48ec9338a7e8dc>_><br>CJsonHelper::_SetValue<br>CMedicEtwConsumer::_AddFileToMap<br>CMedicEtwConsumer::_CreateLogFileName<br>CMedicEtwConsumer::_GetExistingLogFiles<br>CMedicEtwConsumer::_StartTracing<br>CreatePath<br>GetMedicLogDir<br>GetOSVersionFromFile</summary>GetTraceSettingsRegKey<br>LogLevelA<br>LogLevelW<br>TraceLoggingCorrelationVector::TraceLoggingCorrelationVector<br>TraceLoggingCorrelationVector::TraceLoggingCorrelationVector<br>TraceLoggingCorrelationVector::ValidateImpl<br>TraceLoggingRegister<br>VersionSPrintfHelper<br>WaaSRemediationAgent::LaunchDetectionOnly<br>WaaSRemediationAgent::LaunchRemediation<br>WaaSRemediationAgent::LaunchRemediationHelper<br>WaaSRemediationAgent::LaunchRemediationOnly<br>WaaSRemediationAgent::SetAndExtendCV<br>WaasMedic::CSandboxRpcWrapper::CreateSandbox<br>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CSettingsProvider::Clear<br>WaasMedic::CSettingsProvider::GetValue<br>WaasMedic::CSettingsProvider::SetValue<br>WaasMedic::CStateProvider::Clear<br>WaasMedic::CStateProvider::GetValue<br>WaasMedic::CStateProvider::SetValue<br>WaasMedic::CSvcUtil::ServiceStop<br>WaasMedic::CSvcUtil::VerifyServiceState<br>WaasMedic::CSvcUtil::WaitForServiceState<br>WaasMedic::CWERReporter::AddDirectoriesToWERReport<br>WaasMedic::CWERReporter::CopyLogsDirToTempDir<br>WaasMedic::CWERReporter::CreateWERReport<br>WaasMedic::CWERReporter::EnumerateAndAddFilesToWerReport<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWERReporter::GetTemporaryLogFilePath<br>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CWERReporter::ReportError<br>WaasMedic::CWaasMedic::LaunchRemediation<br>WaasMedic::CWaasMedic::SetAndExtendCV<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Init<br>WaasMedic::CWaasRemediation::LoadPluginLibrary<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings<br>WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs<br>WaasMedic::CloudSettingsProvider::Init<br>WaasMedic::CloudSettingsProvider::Run<br>WaasMedic::CopyDirectory<br>WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString<br>WaasMedic::MiscUtil::PopulateClientVersionString<br>WaasMedic::OneSettings::GetCloudSettings<br>WaasMedic::OneSettings::Initialize<br>WaasMedic::OneSettings::InitializeMachineProperties<br>WaasMedic::OneSettings::ParseJsonBlob<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath<br>WaasMedic::RegCreateKeyHelperPrivate<br>WaasMedic::RegDelAllValuesInKey<br>WaasMedic::RegDelTree<br>WaasMedic::RegDelValue<br>WaasMedic::RegGetPersistedRootPath<br>WaasMedic::RegGetPersistedSubkeyPath<br>WaasMedic::RegGetValueAsVariant<br>WaasMedic::RegSetValueFromVariant<br>WaasMedic::RegSetValue_Helper<br>WaasMedic::SafeRegQueryValueCchAllocHelper<br>WaasMedic::SafeRegQueryValueCchHelper<br>WaasMedic::TasksHelper::CreateOrUpdateTask<br>WaasMedic::TasksHelper::DeleteTask<br>WaasMedic::TasksHelper::EnableTask<br>WaasMedic::TasksHelper::Initialize<br>WaasMedic::TelemetryCoreProvider::ReportSummary<br>WaasMedic::TelemetryProvider::DetectionActivity::StartActivity<br>WaasMedic::TelemetryProvider::DetectionActivity::StopActivity<br>WaasMedic::TelemetryProvider::EnumeratePluginActivity::StartActivity<br>WaasMedic::TelemetryProvider::EnumeratePluginActivity::StopActivity<br>WaasMedic::TelemetryProvider::RemediationActivity::StartActivity<br>WaasMedic::TelemetryProvider::RemediationActivity::StopActivity<br>WaasMedic::TelemetryProvider::ReportDetectionCompleted<br>WaasMedic::TelemetryProvider::ReportDetectionFailed<br>WaasMedic::TelemetryProvider::ReportDetectionStarted<br>WaasMedic::TelemetryProvider::ReportDetectionsOnlyCompleted<br>WaasMedic::TelemetryProvider::ReportDetectionsOnlyFailed<br>WaasMedic::TelemetryProvider::ReportDetectionsOnlyStarted<br>WaasMedic::TelemetryProvider::ReportEngineCompleted<br>WaasMedic::TelemetryProvider::ReportEngineFailed<br>WaasMedic::TelemetryProvider::ReportEngineStarted<br>WaasMedic::TelemetryProvider::ReportRegUtilQueryValueFailed<br>WaasMedic::TelemetryProvider::ReportRegistryKeyProtectionResult<br>WaasMedic::TelemetryProvider::ReportRegistryValueProtectionResult<br>WaasMedic::TelemetryProvider::ReportRemediationCompleted<br>WaasMedic::TelemetryProvider::ReportRemediationFailed<br>WaasMedic::TelemetryProvider::ReportRemediationStarted<br>WaasMedic::TelemetryProvider::ReportRemediationsOnlyCompleted<br>WaasMedic::TelemetryProvider::ReportRemediationsOnlyFailed<br>WaasMedic::TelemetryProvider::ReportRemediationsOnlyStarted<br>WaasMedic::TelemetryProvider::ReportSecurityDescriptorProtectionResult<br>WaasMedic::TelemetryProvider::ReportTaskProtectionResult<br>WaasMedic::TelemetryProvider::SandboxActivity::StartActivity<br>WaasMedic::TelemetryProvider::SandboxActivity::StopActivity<br>WaasMedic::TimeHelper::FileTimeToString<br>WaasMedic::TimeHelper::FileTimeToVariant<br>WaasMedic::TimeHelper::StringToFileTime<br>WaasMedic::ValidateOriginalFileName<br>WaasMedic::WaasCurrencyDetector::ComputeCurrencyState<br>WaasMedic::WaasCurrencyDetector::Run<br>_LogMsgErrorA<br>_LogMsgErrorW<br>_LogMsgInfoA<br>_LogMsgInfoW<br>_LogMsgVerboseA<br>_LogMsgVerboseW<br>_LogMsgWarningA<br>_LogMsgWarningW<br>_TlgWriteActivityAutoStop<70368744177664,5><br>__GSHandlerCheckCommon<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::NotifyFailure<br>wil::ActivityBase<WaasMedic::TelemetryProvider,1,70368744177664,5,16777216,_TlgReflectorTag_Param0IsProviderType>::Stop<br>wil::GetFailureLogString<br>wil::ResultException::what<br>wil::TraceLoggingProvider::ReportTelemetryFailure<br>wil::TraceLoggingProvider::ReportTraceLoggingFailure<br>wil::details::GetModuleInformation<br>wil::details::ReportFailure<br>wil::details::ReportFailure_CaughtException<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::Acquire<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::MakeAndInitialize<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64></details>|
|paramcount|1|1|
|`address`|18002cd30|18002d8f0|
|sig|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|void __cdecl __security_check_cookie(uintptr_t _StackCookie)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

### __security_check_cookie Calling Diff


```diff
--- __security_check_cookie calling
+++ __security_check_cookie calling
@@ -63,0 +64,2 @@
+WaasMedic::GetRandomString
+WaasMedic::GetSha256HashOfString
@@ -116,0 +119 @@
+WaasMedic::ValidateOriginalFileName
@@ -128,0 +132 @@
+std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::find_last_of
```


## API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|CoTaskMemFree|CoTaskMemFree|
|fullname|API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree|API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree|
|`refcount`|35|32|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CSpDynamicString::AppendHR<br>CSpDynamicString::operator=<br>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::OneSettings::GetAllKeyValuePairs<br>WaasMedic::OneSettings::GetCloudSettings<br>WaasMedic::OneSettings::GetEtagFromResponse<br>WaasMedic::OneSettings::InitializeMachineProperties<br>WaasMedic::OneSettings::~OneSettings</summary>wil::unique_any_t<wil::details::unique_storage<wil::details::resource_policy<unsigned_short*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_CoTaskMemFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,unsigned_short*___ptr64,unsigned_short*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<wil::details::unique_storage<wil::details::resource_policy<unsigned_short*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_CoTaskMemFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,unsigned_short*___ptr64,unsigned_short*___ptr64,0,std::nullptr_t>_>_></details>|CSpDynamicString::AppendHR<br>CSpDynamicString::operator=<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::OneSettings::GetAllKeyValuePairs<br>WaasMedic::OneSettings::GetCloudSettings<br>WaasMedic::OneSettings::GetEtagFromResponse<br>WaasMedic::OneSettings::InitializeMachineProperties<br>WaasMedic::OneSettings::~OneSettings<br>wil::unique_any_t<wil::details::unique_storage<wil::details::resource_policy<unsigned_short*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_CoTaskMemFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,unsigned_short*___ptr64,unsigned_short*___ptr64,0,std::nullptr_t>_>_>::~unique_any_t<wil::details::unique_storage<wil::details::resource_policy<unsigned_short*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_CoTaskMemFree(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,unsigned_short*___ptr64,unsigned_short*___ptr64,0,std::nullptr_t>_>_>|
|paramcount|1|1|
|`address`|EXTERNAL:00000097|EXTERNAL:0000009e|
|sig|void __stdcall CoTaskMemFree(LPVOID pv)|void __stdcall CoTaskMemFree(LPVOID pv)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree Calling Diff


```diff
--- API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree calling
+++ API-MS-WIN-CORE-COM-L1-1-0.DLL::CoTaskMemFree calling
@@ -3 +2,0 @@
-WaasMedic::CSandboxRpcWrapper::Init
@@ -5,2 +3,0 @@
-WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper
-WaasMedic::CWaasRemediation::RunPluginsInCapsule
```


## allocate

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.79|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|allocate|allocate|
|fullname|std::allocator<unsigned_short>::allocate|std::allocator<unsigned_short>::allocate|
|`refcount`|4|5|
|length|106|106|
|called|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn<br>operator_new|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn<br>operator_new|
|`calling`|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_3fdb14453883e86a37ebade6a7a0ebb0>,unsigned_short><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_7030d12a21dba11210293044e97fe9c7>,unsigned_short_const_*,unsigned___int64>|WaasMedic::ValidateOriginalFileName<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_3fdb14453883e86a37ebade6a7a0ebb0>,unsigned_short><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_7030d12a21dba11210293044e97fe9c7>,unsigned_short_const_*,unsigned___int64>|
|paramcount|2|2|
|`address`|18000bca0|18000bcd0|
|sig|ushort * __thiscall allocate(allocator<unsigned_short> * this, __uint64 param_1)|ushort * __thiscall allocate(allocator<unsigned_short> * this, __uint64 param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### allocate Calling Diff


```diff
--- std::allocator<unsigned_short>::allocate calling
+++ std::allocator<unsigned_short>::allocate calling
@@ -0,0 +1 @@
+WaasMedic::ValidateOriginalFileName
```


## dtor$2

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|dtor$2|dtor$2|
|fullname|`WaasMedic::CSandboxRpcWrapper::PrepareCommandLine'::__l1::dtor$2|`WaasMedic::CSandboxRpcWrapper::PrepareCommandLine'::__l1::dtor$2|
|`refcount`|1|2|
|length|12|12|
|called|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|calling|||
|paramcount|2|2|
|`address`|18002ebe3|18002f825|
|sig|undefined __fastcall dtor$2(undefined8 param_1, longlong param_2)|undefined __fastcall dtor$2(undefined8 param_1, longlong param_2)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|CoCreateGuid|CoCreateGuid|
|fullname|API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid|API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid|
|`refcount`|3|2|
|length|0|0|
|called|||
|`calling`|WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CWERReporter::GetTemporaryLogFilePath|WaasMedic::CWERReporter::GetTemporaryLogFilePath|
|paramcount|1|1|
|`address`|EXTERNAL:00000098|EXTERNAL:0000009f|
|sig|HRESULT __stdcall CoCreateGuid(GUID * pguid)|HRESULT __stdcall CoCreateGuid(GUID * pguid)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid Calling Diff


```diff
--- API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid calling
+++ API-MS-WIN-CORE-COM-L1-1-0.DLL::CoCreateGuid calling
@@ -1 +0,0 @@
-WaasMedic::CSandboxRpcWrapper::Init
```


## SafeFree

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.79|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|SafeFree|SafeFree|
|fullname|WaasMedic::SafeFree|WaasMedic::SafeFree|
|`refcount`|40|46|
|length|77|77|
|called|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap<br>API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree|
|`calling`|<details><summary>Expand for full list:<br>WaaSRemediationAgent::LaunchDetectionOnly<br>WaaSRemediationAgent::~WaaSRemediationAgent<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWERReporter::ReportError<br>WaasMedic::CWERReporter::~CWERReporter<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings<br>WaasMedic::CloudSettingsProvider::Run</summary>WaasMedic::OneSettings::VerifyCertificiateAuthority<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToRegistryPath<br>WaasMedic::RegGetValueAsVariant<br>WaasMedic::RegQueryBinaryValue<br>WaasMedic::RegQueryStringValueWithDefaultAndExpand<br>WaasMedic::SafeRegQueryValueCchAllocHelper<br>WaasMedic::TaskProtector::ProtectTask<br>WaasMedic::TelemetryCoreProvider::ReportSummary<br>wil::details::lambda_call<<lambda_1b2028bad3b6bb9f7dc005daad845aa3>_>::~lambda_call<<lambda_1b2028bad3b6bb9f7dc005daad845aa3>_></details>|<details><summary>Expand for full list:<br>WaaSRemediationAgent::LaunchDetectionOnly<br>WaaSRemediationAgent::~WaaSRemediationAgent<br>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CSandboxRpcWrapper::~CSandboxRpcWrapper<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWERReporter::ReportError<br>WaasMedic::CWERReporter::~CWERReporter<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings</summary>WaasMedic::CloudSettingsProvider::Run<br>WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString<br>WaasMedic::OneSettings::VerifyCertificiateAuthority<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToRegistryPath<br>WaasMedic::RegGetValueAsVariant<br>WaasMedic::RegQueryBinaryValue<br>WaasMedic::RegQueryStringValueWithDefaultAndExpand<br>WaasMedic::SafeRegQueryValueCchAllocHelper<br>WaasMedic::TaskProtector::ProtectTask<br>WaasMedic::TelemetryCoreProvider::ReportSummary<br>wil::details::lambda_call<<lambda_1b2028bad3b6bb9f7dc005daad845aa3>_>::~lambda_call<<lambda_1b2028bad3b6bb9f7dc005daad845aa3>_></details>|
|paramcount|1|1|
|`address`|18001324c|1800140cc|
|sig|long __cdecl SafeFree(void * param_1)|long __cdecl SafeFree(void * param_1)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### SafeFree Calling Diff


```diff
--- WaasMedic::SafeFree calling
+++ WaasMedic::SafeFree calling
@@ -2,0 +3 @@
+WaasMedic::CSandboxRpcWrapper::Init
@@ -11,0 +13,2 @@
+WaasMedic::GetRandomString
+WaasMedic::GetSha256HashOfString
```


## SafeAllocString

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.72|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|SafeAllocString|SafeAllocString|
|fullname|WaasMedic::SafeAllocString|WaasMedic::SafeAllocString|
|`refcount`|25|26|
|length|210|210|
|called|LogLevelW<br>StringCchCopyW<br>WaasMedic::SafeAlloc|LogLevelW<br>StringCchCopyW<br>WaasMedic::SafeAlloc|
|`calling`|CJsonHelper::AsString<br>CJsonHelper::_GetValue<<lambda_142bbb5a18063f8f3b48ec9338a7e8dc>_><br>WaaSRemediationAgent::Start<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath|CJsonHelper::AsString<br>CJsonHelper::_GetValue<<lambda_142bbb5a18063f8f3b48ec9338a7e8dc>_><br>WaaSRemediationAgent::Start<br>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CWERReporter::GetDefaultWERReportParamsWithScenario<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath|
|paramcount|2|2|
|`address`|1800132a0|180014120|
|sig|long __cdecl SafeAllocString(ushort * param_1, ushort * * param_2)|long __cdecl SafeAllocString(ushort * param_1, ushort * * param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### SafeAllocString Calling Diff


```diff
--- WaasMedic::SafeAllocString calling
+++ WaasMedic::SafeAllocString calling
@@ -3,0 +4 @@
+WaasMedic::CSandboxRpcWrapper::Init
```


## __GSHandlerCheck_EH

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address|
|ratio|1.0|
|i_ratio|0.92|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|__GSHandlerCheck_EH|__GSHandlerCheck_EH|
|fullname|__GSHandlerCheck_EH|__GSHandlerCheck_EH|
|`refcount`|36|41|
|length|127|127|
|called|__CxxFrameHandler3<br>__GSHandlerCheckCommon|__CxxFrameHandler3<br>__GSHandlerCheckCommon|
|calling|||
|paramcount|4|4|
|`address`|18002e630|18002f260|
|sig|undefined __fastcall __GSHandlerCheck_EH(longlong param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|undefined __fastcall __GSHandlerCheck_EH(longlong param_1, undefined8 param_2, undefined8 param_3, longlong param_4)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|False|False|

## substr

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.83|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|substr|substr|
|fullname|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::substr|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::substr|
|`refcount`|3|4|
|length|164|164|
|called|memmove<br>std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*>|memmove<br>std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*>|
|`calling`|WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs|WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs<br>WaasMedic::ValidateOriginalFileName|
|paramcount|3|3|
|`address`|180025c94|1800116e8|
|sig|basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_> __thiscall substr(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this, __uint64 param_1, __uint64 param_2)|basic_string<unsigned_short,struct_std::char_traits<unsigned_short>,class_std::allocator<unsigned_short>_> __thiscall substr(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this, __uint64 param_1, __uint64 param_2)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### substr Calling Diff


```diff
--- std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::substr calling
+++ std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::substr calling
@@ -1,0 +2 @@
+WaasMedic::ValidateOriginalFileName
```


## API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|GetLastError|GetLastError|
|fullname|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError|
|`refcount`|117|119|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_GetExistingLogFiles<br>CreatePath<br>ServiceMain<br>UpdateServiceStatus<br>WaaSRemediationAgent::ExecuteProcOnThread<br>WaaSRemediationAgent::LaunchRemediation<br>WaaSRemediationAgent::Start<br>WaasMedic::CProtectionUtil::ApplyPermissionsOnRegistryKey<br>WaasMedic::CProtectionUtil::ApplySecurityDescriptorOnRegistrySubkey<br>WaasMedic::CSandboxRpcWrapper::CreateSandbox<br>WaasMedic::CSvcUtil::EnableService</summary>WaasMedic::CSvcUtil::ServiceStop<br>WaasMedic::CSvcUtil::VerifyServiceState<br>WaasMedic::CWERReporter::CopyLogsDirToTempDir<br>WaasMedic::CWERReporter::GetTemporaryLogFilePath<br>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CWaasRemediation::Cancel<br>WaasMedic::CWaasRemediation::ExecutePerformAction<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Init<br>WaasMedic::CWaasRemediation::LoadPluginLibrary<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CopyDirectory<br>WaasMedic::IsTrustedLibrary<br>WaasMedic::MiscUtil::SetBelowNormalPriorityState<br>WaasMedic::OneSettings::GetCloudSettings<br>WaasMedic::OneSettings::GetEtagFromResponse<br>WaasMedic::OneSettings::OpenWebRequest<br>WaasMedic::OneSettings::VerifyCertificiateAuthority<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToNamespace<br>WaasMedic::RegQueryStringValueWithDefaultAndExpand<br>WaasMedic::SafeFree<br>WaasMedic::TimeHelper::FileTimeToString<br>WaasMedic::TimeHelper::SyncSystemTime<br>wil::details::GetLastErrorFailHr<br>wil::details::ReportFailure_GetLastError<br>wil::details::ReportFailure_GetLastErrorHr<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64><br>wil::semaphore_t<wil::details::unique_storage<wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::CloseHandle(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,wil::err_returncode_policy>::create</details>|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_GetExistingLogFiles<br>CreatePath<br>ServiceMain<br>UpdateServiceStatus<br>WaaSRemediationAgent::ExecuteProcOnThread<br>WaaSRemediationAgent::LaunchRemediation<br>WaaSRemediationAgent::Start<br>WaasMedic::CProtectionUtil::ApplyPermissionsOnRegistryKey<br>WaasMedic::CProtectionUtil::ApplySecurityDescriptorOnRegistrySubkey<br>WaasMedic::CSandboxRpcWrapper::CreateSandbox<br>WaasMedic::CSvcUtil::EnableService</summary>WaasMedic::CSvcUtil::ServiceStop<br>WaasMedic::CSvcUtil::VerifyServiceState<br>WaasMedic::CWERReporter::CopyLogsDirToTempDir<br>WaasMedic::CWERReporter::GetTemporaryLogFilePath<br>WaasMedic::CWERReporter::RegisterFilesToWERReport<br>WaasMedic::CWaasRemediation::Cancel<br>WaasMedic::CWaasRemediation::ExecutePerformAction<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Init<br>WaasMedic::CWaasRemediation::LoadPluginLibrary<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::Run<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CopyDirectory<br>WaasMedic::IsTrustedLibrary<br>WaasMedic::MiscUtil::SetBelowNormalPriorityState<br>WaasMedic::OneSettings::GetCloudSettings<br>WaasMedic::OneSettings::GetEtagFromResponse<br>WaasMedic::OneSettings::OpenWebRequest<br>WaasMedic::OneSettings::VerifyCertificiateAuthority<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToFolderPath<br>WaasMedic::ProtectedSettingsNamespaceMapper::IsCallerAllowedToWriteToNamespace<br>WaasMedic::RegQueryStringValueWithDefaultAndExpand<br>WaasMedic::SafeFree<br>WaasMedic::TimeHelper::FileTimeToString<br>WaasMedic::TimeHelper::SyncSystemTime<br>WaasMedic::ValidateOriginalFileName<br>wil::details::GetLastErrorFailHr<br>wil::details::ReportFailure_GetLastError<br>wil::details::ReportFailure_GetLastErrorHr<br>wil::details_abi::ProcessLocalStorageData<wil::details_abi::ProcessLocalData>::Release<br>wil::details_abi::SemaphoreValue::GetValueFromSemaphore<br>wil::details_abi::SemaphoreValue::TryGetValue<unsigned___int64><br>wil::semaphore_t<wil::details::unique_storage<wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64),&void___cdecl_wil::details::CloseHandle(void*___ptr64),wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,wil::err_returncode_policy>::create</details>|
|paramcount|0|0|
|`address`|EXTERNAL:00000056|EXTERNAL:0000005c|
|sig|DWORD __stdcall GetLastError(void)|DWORD __stdcall GetLastError(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError Calling Diff


```diff
--- API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError calling
+++ API-MS-WIN-CORE-ERRORHANDLING-L1-1-0.DLL::GetLastError calling
@@ -43,0 +44 @@
+WaasMedic::ValidateOriginalFileName
```


## _Xran

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.5|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|_Xran|_Xran|
|fullname|std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran|std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran|
|`refcount`|2|3|
|length|9|9|
|called|std::_Xout_of_range|std::_Xout_of_range|
|`calling`|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::substr|WaasMedic::ValidateOriginalFileName<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::substr|
|paramcount|0|0|
|`address`|180025e74|1800118c4|
|sig|void __cdecl _Xran(void)|void __cdecl _Xran(void)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### _Xran Calling Diff


```diff
--- std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran calling
+++ std::_String_val<std::_Simple_types<unsigned_short>_>::_Xran calling
@@ -0,0 +1 @@
+WaasMedic::ValidateOriginalFileName
```


## ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|0.81|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|fullname|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>|
|`refcount`|44|59|
|length|98|98|
|called|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn<br>operator_delete[]|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn<br>operator_delete[]|
|`calling`|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_AddFileToMap<br>CreatePath<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::RunEx</summary>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings<br>WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs<br>`CMedicEtwConsumer::_AddFileToMap'::__l1::dtor$0<br>`CreatePath'::__l1::dtor$2<br>`GetMedicLogDir'::__l2::`dynamic_atexit_destructor_for_'s_szLogDir''<br>`GetTraceSettingsRegKey'::__l2::`dynamic_atexit_destructor_for_'traceSettingsRegKey''<br>`WaasMedic::CSandboxRpcWrapper::PrepareCommandLine'::__l1::dtor$0<br>`WaasMedic::CSandboxRpcWrapper::PrepareCommandLine'::__l1::dtor$2<br>`WaasMedic::CWaasRemediation::FreePluginLibrary'::__l1::dtor$0<br>`WaasMedic::CWaasRemediation::RunEx'::__l1::dtor$0<br>`WaasMedic::CWaasRemediation::RunPluginsInCapsule'::__l1::dtor$10<br>`WaasMedic::CWaasRemediation::SetPluginDefaultSettings'::__l1::dtor$0<br>`WaasMedic::CWaasRemediation::SetPluginDefaultSettings'::__l1::dtor$1<br>`WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs'::__l1::dtor$0<br>`WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs'::__l1::dtor$2<br>`public:_static_class_getInstance&___ptr64___cdecl_CMedicEtwConsumer::getInstance(void)'::__l2::`dynamic_atexit_destructor_for_'myInstance''<br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::_Destroy_if_node<br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::_Erase<br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::_Insert_nohint<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>&___ptr64,std::_Tree_node<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>,void*___ptr64>*___ptr64><br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::clear<br>std::list<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::allocator<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>::~list<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::allocator<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_><br>std::pair<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>::~pair<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_></details>|<details><summary>Expand for full list:<br>CMedicEtwConsumer::_AddFileToMap<br>CreatePath<br>WaasMedic::CSandboxRpcWrapper::CreateSandbox<br>WaasMedic::CSandboxRpcWrapper::Init<br>WaasMedic::CSandboxRpcWrapper::PrepareCommandLine<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled</summary>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::RunEx<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::CWaasRemediation::SetPluginDefaultSettings<br>WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs<br>WaasMedic::GetRandomString<br>WaasMedic::GetSha256HashOfString<br>WaasMedic::ValidateOriginalFileName<br>`CMedicEtwConsumer::_AddFileToMap'::__l1::dtor$0<br>`CreatePath'::__l1::dtor$2<br>`GetMedicLogDir'::__l2::`dynamic_atexit_destructor_for_'s_szLogDir''<br>`GetTraceSettingsRegKey'::__l2::`dynamic_atexit_destructor_for_'traceSettingsRegKey''<br>`WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor$0<br>`WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor$0<br>`WaasMedic::CSandboxRpcWrapper::PrepareCommandLine'::__l1::dtor$0<br>`WaasMedic::CSandboxRpcWrapper::PrepareCommandLine'::__l1::dtor$2<br>`WaasMedic::CWaasRemediation::FreePluginLibrary'::__l1::dtor$0<br>`WaasMedic::CWaasRemediation::RunEx'::__l1::dtor$0<br>`WaasMedic::CWaasRemediation::RunPluginsInCapsule'::__l1::dtor$10<br>`WaasMedic::CWaasRemediation::SetPluginDefaultSettings'::__l1::dtor$0<br>`WaasMedic::CWaasRemediation::SetPluginDefaultSettings'::__l1::dtor$1<br>`WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs'::__l1::dtor$0<br>`WaasMedic::CloudSettingsProvider::GetAllKeyValuePairs'::__l1::dtor$2<br>`WaasMedic::GetRandomString'::__l1::dtor$0<br>`WaasMedic::GetSha256HashOfString'::__l1::dtor$0<br>`WaasMedic::ValidateOriginalFileName'::__l1::dtor$1<br>`public:_static_class_getInstance&___ptr64___cdecl_CMedicEtwConsumer::getInstance(void)'::__l2::`dynamic_atexit_destructor_for_'myInstance''<br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::_Destroy_if_node<br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::_Erase<br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::_Insert_nohint<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>&___ptr64,std::_Tree_node<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>,void*___ptr64>*___ptr64><br>std::_Tree<std::_Tmap_traits<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::less<unsigned___int64>,std::allocator<std::pair<unsigned___int64_const_,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>,0>_>::clear<br>std::list<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::allocator<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_>::~list<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>,std::allocator<std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>_><br>std::pair<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_>::~pair<unsigned___int64,std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>_></details>|
|paramcount|1|1|
|`address`|18000b674|18000b6a4|
|sig|void __thiscall ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this)|void __thiscall ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>(basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> * this)|
|sym_type|Function|Function|
|sym_source|ANALYSIS|ANALYSIS|
|external|False|False|

### ~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> Calling Diff


```diff
--- std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> calling
+++ std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_> calling
@@ -2,0 +3,2 @@
+WaasMedic::CSandboxRpcWrapper::CreateSandbox
+WaasMedic::CSandboxRpcWrapper::Init
@@ -14,0 +17,3 @@
+WaasMedic::GetRandomString
+WaasMedic::GetSha256HashOfString
+WaasMedic::ValidateOriginalFileName
@@ -18,0 +24,2 @@
+`WaasMedic::CSandboxRpcWrapper::CreateSandbox'::__l1::dtor$0
+`WaasMedic::CSandboxRpcWrapper::Init'::__l1::dtor$0
@@ -27,0 +35,3 @@
+`WaasMedic::GetRandomString'::__l1::dtor$0
+`WaasMedic::GetSha256HashOfString'::__l1::dtor$0
+`WaasMedic::ValidateOriginalFileName'::__l1::dtor$1
```


## API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|_o__invalid_parameter_noinfo_noreturn|_o__invalid_parameter_noinfo_noreturn|
|fullname|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn|API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn|
|`refcount`|19|20|
|length|0|0|
|called|||
|`calling`|<details><summary>Expand for full list:<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::ws2s<br>std::allocator<unsigned_short>::allocate<br>std::basic_string<char,std::char_traits<char>,std::allocator<char>_>::_Construct<unsigned_short_const*___ptr64></summary>std::basic_string<char,std::char_traits<char>,std::allocator<char>_>::_Reallocate_grow_by<<lambda_9013ee9e23efe4882b67eff5b0ecf103>_><br>std::basic_string<char,std::char_traits<char>,std::allocator<char>_>::_Tidy_deallocate<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_3fdb14453883e86a37ebade6a7a0ebb0>,unsigned_short><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_7030d12a21dba11210293044e97fe9c7>,unsigned_short_const_*,unsigned___int64><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_></details>|<details><summary>Expand for full list:<br>WaasMedic::CWaasRemediation::FreePluginLibrary<br>WaasMedic::CWaasRemediation::GetPluginDefaultSettings<br>WaasMedic::CWaasRemediation::GetSettingsName<br>WaasMedic::CWaasRemediation::Plugin_Init<br>WaasMedic::CWaasRemediation::Plugin_IsActionApplicable<br>WaasMedic::CWaasRemediation::Plugin_IsEnabled<br>WaasMedic::CWaasRemediation::Plugin_IsInteractiveOnly<br>WaasMedic::CWaasRemediation::RunPluginsInCapsule<br>WaasMedic::ws2s<br>std::allocator<unsigned_short>::allocate<br>std::basic_string<char,std::char_traits<char>,std::allocator<char>_>::_Construct<unsigned_short_const*___ptr64></summary>std::basic_string<char,std::char_traits<char>,std::allocator<char>_>::_Reallocate_grow_by<<lambda_9013ee9e23efe4882b67eff5b0ecf103>_><br>std::basic_string<char,std::char_traits<char>,std::allocator<char>_>::_Tidy_deallocate<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_for<<lambda_05cef1f6fdf474c9f3ed207deba0f73b>,unsigned_short_const_*><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_3fdb14453883e86a37ebade6a7a0ebb0>,unsigned_short><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::_Reallocate_grow_by<<lambda_7030d12a21dba11210293044e97fe9c7>,unsigned_short_const_*,unsigned___int64><br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=<br>std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::~basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_></details>|
|paramcount|0|0|
|address|EXTERNAL:00000008|EXTERNAL:00000008|
|sig|undefined _o__invalid_parameter_noinfo_noreturn(void)|undefined _o__invalid_parameter_noinfo_noreturn(void)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn Calling Diff


```diff
--- API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn calling
+++ API-MS-WIN-CRT-PRIVATE-L1-1-0.DLL::_o__invalid_parameter_noinfo_noreturn calling
@@ -16,0 +17 @@
+std::basic_string<unsigned_short,std::char_traits<unsigned_short>,std::allocator<unsigned_short>_>::operator=
```


## OLEAUT32.DLL::LoadRegTypeLib

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|LoadRegTypeLib|LoadRegTypeLib|
|fullname|OLEAUT32.DLL::LoadRegTypeLib|OLEAUT32.DLL::LoadRegTypeLib|
|`refcount`|2|1|
|length|0|0|
|called|||
|`calling`|WaaSRemediationAgent::WaaSRemediationAgent||
|paramcount|5|5|
|`address`|EXTERNAL:00000087|EXTERNAL:00000083|
|sig|HRESULT __stdcall LoadRegTypeLib(GUID * rguid, WORD wVerMajor, WORD wVerMinor, LCID lcid, ITypeLib * * pptlib)|HRESULT __stdcall LoadRegTypeLib(GUID * rguid, WORD wVerMajor, WORD wVerMinor, LCID lcid, ITypeLib * * pptlib)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### OLEAUT32.DLL::LoadRegTypeLib Calling Diff


```diff
--- OLEAUT32.DLL::LoadRegTypeLib calling
+++ OLEAUT32.DLL::LoadRegTypeLib calling
@@ -1 +0,0 @@
-WaaSRemediationAgent::WaaSRemediationAgent
```


## API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc

### Match Info



|Key|waasmedicsvc-2019-12.dll - waasmedicsvc-2020-01.dll|
| :---: | :---: |
|diff_type|refcount,address,calling|
|ratio|1.0|
|i_ratio|1.0|
|m_ratio|1.0|
|b_ratio|1.0|
|match_types|SymbolsHash,ExternalsName|

### Function Meta Diff



|Key|waasmedicsvc-2019-12.dll|waasmedicsvc-2020-01.dll|
| :---: | :---: | :---: |
|name|LocalAlloc|LocalAlloc|
|fullname|API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc|API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc|
|`refcount`|2|3|
|length|0|0|
|called|||
|`calling`|WaaSRemediationAgent::LaunchRemediation|WaaSRemediationAgent::LaunchRemediation<br>WaasMedic::ValidateOriginalFileName|
|paramcount|2|2|
|`address`|EXTERNAL:000000c6|EXTERNAL:000000cd|
|sig|HLOCAL __stdcall LocalAlloc(UINT uFlags, SIZE_T uBytes)|HLOCAL __stdcall LocalAlloc(UINT uFlags, SIZE_T uBytes)|
|sym_type|Function|Function|
|sym_source|IMPORTED|IMPORTED|
|external|True|True|

### API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc Calling Diff


```diff
--- API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc calling
+++ API-MS-WIN-CORE-HEAP-L2-1-0.DLL::LocalAlloc calling
@@ -1,0 +2 @@
+WaasMedic::ValidateOriginalFileName
```




<sub>Generated with `ghidriff` version: 1.0.0 on 2026-09-08T22:50:48</sub>