Subject: Re: WAM.SYS blue screen STOP 0x00000050
Date: Mon, 26 Jul 2004 11:50:43 -0700
Lines: 85
Message-ID: <
[email protected]>
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Thread-Index: AcRzQXQa2mq+T+oiRxausy20GDhEgg==
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
Newsgroups: microsoft.public.windowsxp.hardware
Path: cpmsftngxa06.phx.gbl
Xref: cpmsftngxa06.phx.gbl microsoft.public.windowsxp.hardware:217240
NNTP-Posting-Host: tk2msftngxa11.phx.gbl 10.40.1.163
X-Tomcat-NG: microsoft.public.windowsxp.hardware
Thanks and I actually found the web site but didn't see
anything with Wam.sys. So I'm thinking that it's
Spyware, or malware/adware. I found this in the registry
and deleted it. Any thoughts out there?
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WAM]
"Type"=dword:00000001
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"ImagePath"=hex
(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,
6f,00,\
67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,0
0,5c,00,49,00,42,\
00,4d,00,5c,00,49,00,42,00,4d,00,20,00,52,00,61,00,70,00,6
9,00,64,00,20,00,\
52,00,65,00,73,00,74,00,6f,00,72,00,65,00,20,00,55,00,6c,0
0,74,00,72,00,61,\
00,5c,00,57,00,41,00,4d,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Wicked Access by Mark"
"DeleteFlag"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\WAM\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,0
0,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,0
0,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,0
1,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,0
0,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,0
5,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2
3,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,0
0,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\WAM\Enum]
"0"="Root\\LEGACY_WAM\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
-----Original Message-----
Hi
See if the following link helps:
0x00000050: PAGE_FAULT_IN_NONPAGED_AREA
http://aumha.org/win5/kbestop.php#0x50
--
Will Denny
MS-MVP Windows Shell/User
Please reply to the News Groups
.