Analyzed 15 dump

Top 1: total counts = 3

0695f6bc 6468aeed rightsmanager!RM_AutorunScan+0x176
0695f7b8 7591344d ffi_bindings!ffi_call_win32+0x11
0695f7c4 779b9802 kernel32!BaseThreadInitThunk+0xe
0695f804 779b97d5 ntdll!__RtlUserThreadStart+0x70
0695f81c 00000000 ntdll!_RtlUserThreadStart+0x1b

a0ecd80cb56df8111fdd5aac3be40ae5_000.dmp
fa3020d998117abdf8aa91aea1c3c36c_001.dmp
b89b5f3aae7b26dc416be3614d2e3d14_000.dmp

Top 2: total counts = 2

057bf83c 7b71aeed rightsmanager!RM_AutorunScan+0x176
057bf938 763dfcc9 ffi_bindings!ffi_call_win32+0x11
057bf948 778082ae kernel32!BaseThreadInitThunk+0x19
057bf9a4 7780827e ntdll!__RtlUserThreadStart+0x2f
057bf9b4 00000000 ntdll!_RtlUserThreadStart+0x1b

2d6a014feffdc91a9d5b40c356046bc3_001.dmp
adc50be0c225915e93b1f2986a58f690_000.dmp

Top 3: total counts = 1

05dbf6ac 636caeed rightsmanager!RM_AutorunScan+0x176
05dbf7a8 777b7ba9 ffi_bindings!ffi_call_win32+0x11
05dbf7b8 77d3bdab kernel32!BaseThreadInitThunk+0x19
05dbf810 77d3bd2f ntdll!__RtlUserThreadStart+0x2b
05dbf820 00000000 ntdll!_RtlUserThreadStart+0x1b

7f7b3422ef73f18706bc30eac57f2368_000.dmp

Top 4: total counts = 1

ChildEBP RetAddr  
0a2df940 04b606a2 ffi_bindings!ffi_closure_STDCALL+0x25
WARNING: Frame IP not in any known module. Following frames may be wrong.
0a2df954 77a5a853 0x4b606a2
0a2df99c 77a88a47 ntdll!RtlpTpWaitCallback+0x93
0a2df9c4 77a88af9 ntdll!TppExecuteWaitCallback+0x7d
0a2df9dc 77a8620b ntdll!TppWaitCompletion+0x79
0a2dfb9c 756f5d49 ntdll!TppWorkerThread+0x59b
0a2dfbac 77a9d1ab kernel32!BaseThreadInitThunk+0x19
0a2dfc04 77a9d131 ntdll!__RtlUserThreadStart+0x2b
0a2dfc14 00000000 ntdll!_RtlUserThreadStart+0x1b

d47120caa6f09e72bf0a0aa24c343091_000.dmp

Top 5: total counts = 1

ChildEBP RetAddr  
0588fce0 00000000 rightsmanager!memcpy+0x4e

10078099b91ad157a62b84035d2affe8_000.dmp

Top 6: total counts = 1

ChildEBP RetAddr  
0018e8a4 6a8e2d3c KERNELBASE!DebugBreak+0x2
WARNING: Stack unwind information not available. Following frames may be wrong.
00000000 00000000 node+0x2a12d3c

00c9a397a304d5bae64e62415b5409a2_000.dmp

Top 7: total counts = 1

ChildEBP RetAddr  
06e3f944 00000000 KERNELBASE!RaiseException+0x62

b0828b10f13c435a06bae74a0f3e3886_000.dmp

Top 8: total counts = 1

ChildEBP RetAddr  
0b4ef5ec 06ce0632 ffi_bindings!ffi_closure_STDCALL+0x25
WARNING: Frame IP not in any known module. Following frames may be wrong.
0b4ef600 774c01a3 0x6ce0632
0b4ef640 774a0d28 ntdll!RtlpTpWaitCallback+0x94
0b4ef668 774a0991 ntdll!TppWaitpExecuteCallback+0x11b
0b4ef7b8 7543343d ntdll!TppWorkerThread+0x562
0b4ef7c4 77489812 kernel32!BaseThreadInitThunk+0xe
0b4ef804 774897e5 ntdll!__RtlUserThreadStart+0x70
0b4ef81c 00000000 ntdll!_RtlUserThreadStart+0x1b

a7086c637924c044accb4b312e6c0417_000.dmp

Top 9: total counts = 1

ChildEBP RetAddr  
04d3fa38 6c5be780 KERNELBASE!RaiseException+0x62
04d3fa7c 6c5994c0 rightsmanager!_CxxThrowException+0x66
04d3fa98 04d3fac0 rightsmanager!std::_Xbad_alloc+0x1c
WARNING: Frame IP not in any known module. Following frames may be wrong.
04d3fa9c 6c56a440 0x4d3fac0
04d3fac0 6c54e9f3 rightsmanager!std::basic_string,std::allocator >::assign+0xc0
04d3fb40 6c587f86 rightsmanager!CAutorunsCtrl::EnumAutoruns+0x103
04d3fce4 72ae16c7 rightsmanager!RM_AutorunScan+0x176
04d3fd14 76bb0099 iertutil!CUString::Set+0x2884f
04d3fd24 772e7b6e kernel32!BaseThreadInitThunk+0x19
04d3fd80 772e7b3e ntdll!__RtlUserThreadStart+0x2f
04d3fd90 00000000 ntdll!_RtlUserThreadStart+0x1b

e1d58346a28adb10b383cb5f3019efce_000.dmp

Top 10: total counts = 1

ChildEBP RetAddr  
06affc7c 52b4a47b rightsmanager!memcpy+0x4e
06affca8 52b2e9f3 rightsmanager!std::basic_string,std::allocator >::assign+0xfb
06affd28 52b67f86 rightsmanager!CAutorunsCtrl::EnumAutoruns+0x103
06affefc 7677fcc9 rightsmanager!RM_AutorunScan+0x176
06afff0c 77d482ae kernel32!BaseThreadInitThunk+0x19
06afff68 77d4827e ntdll!__RtlUserThreadStart+0x2f
06afff78 00000000 ntdll!_RtlUserThreadStart+0x1b

b4d35205466454ff98cea8f134dbbb6c_000.dmp

Top 11: total counts = 1

ChildEBP RetAddr  
WARNING: Stack unwind information not available. Following frames may be wrong.
0039e728 6dba55ea node+0x10844f6
0039e744 6db78046 node+0x10a55ea
0039e76c 6db5ab9b node+0x1078046
0039e798 6d7444bc node+0x105ab9b
0039e820 6d744913 node+0xc444bc
0039e82c 00c09bb0 node+0xc44913
0039e830 00000000 0xc09bb0

97d03d5815d9b815cb5649ff89a8490c_000.dmp

Top 12: total counts = 1

07cefe74 7b57aeed rightsmanager!RM_AutorunScan+0x186
07ceff70 76f5fcc9 ffi_bindings!ffi_call_win32+0x11
07ceff80 775682ae kernel32!BaseThreadInitThunk+0x19
07ceffdc 7756827e ntdll!__RtlUserThreadStart+0x2f
07ceffec 00000000 ntdll!_RtlUserThreadStart+0x1b

b4159b4349bc1f8ea5193a8a8f034edc_000.dmp