WAM.SYS blue screen STOP 0x00000050

  • Thread starter Thread starter Lee
  • Start date Start date
L

Lee

OK, so every now and then I get a
Page_Fault_In_NonPaged_Area and WAM.SYS blue screen STOP
0x00000050 are on the screen. I can not find "Wam.sys"
anywhere, nor can I find out how to fix. I know it's a
driver for some hardware piece somewhere, but no idea
where or what. Any help would be greatly appreciated.
 
Thanks and I actually found the web site but didn't see
anything with Wam.sys. So I'm thinking that it's
Spyware, or malware/adware. I found this in the registry
and deleted it. Any thoughts out there?

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WAM]
"Type"=dword:00000001
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"ImagePath"=hex
(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,
6f,00,\

67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,0
0,5c,00,49,00,42,\

00,4d,00,5c,00,49,00,42,00,4d,00,20,00,52,00,61,00,70,00,6
9,00,64,00,20,00,\

52,00,65,00,73,00,74,00,6f,00,72,00,65,00,20,00,55,00,6c,0
0,74,00,72,00,61,\
00,5c,00,57,00,41,00,4d,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Wicked Access by Mark"
"DeleteFlag"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\WAM\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,0
0,00,30,00,00,00,02,\

00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,0
0,00,00,01,00,00,\

00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,0
1,00,00,00,00,00,\

05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,0
0,05,20,00,00,00,\

20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,0
5,0b,00,00,00,00,\

00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2
3,02,00,00,01,01,\

00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,0
0,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\WAM\Enum]
"0"="Root\\LEGACY_WAM\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
 
Hi Lee,

I'm unable to find any information on "WAM" or "Wicked Access by Mark",
however, it looks like a third-party service which was installed by
third-party software. You may open the services applet (services.msc) and
disable the "Wicked Access by Mark" service.

Sincerely,

William Wang
Microsoft Online Support Engineer

Get Secure! - www.microsoft.com/security
=========================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=========================================

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Content-Class: urn:content-classes:message
From: "Lee" <[email protected]>
Sender: "Lee" <[email protected]>
References: <[email protected]>
Subject: Re: WAM.SYS blue screen STOP 0x00000050
Date: Mon, 26 Jul 2004 11:50:43 -0700
Lines: 85
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Thread-Index: AcRzQXQa2mq+T+oiRxausy20GDhEgg==
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
Newsgroups: microsoft.public.windowsxp.hardware
Path: cpmsftngxa06.phx.gbl
Xref: cpmsftngxa06.phx.gbl microsoft.public.windowsxp.hardware:217240
NNTP-Posting-Host: tk2msftngxa11.phx.gbl 10.40.1.163
X-Tomcat-NG: microsoft.public.windowsxp.hardware

Thanks and I actually found the web site but didn't see
anything with Wam.sys. So I'm thinking that it's
Spyware, or malware/adware. I found this in the registry
and deleted it. Any thoughts out there?

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WAM]
"Type"=dword:00000001
"Start"=dword:00000004
"ErrorControl"=dword:00000001
"ImagePath"=hex
(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,50,00,72,00,
6f,00,\

67,00,72,00,61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,0
0,5c,00,49,00,42,\

00,4d,00,5c,00,49,00,42,00,4d,00,20,00,52,00,61,00,70,00,6
9,00,64,00,20,00,\

52,00,65,00,73,00,74,00,6f,00,72,00,65,00,20,00,55,00,6c,0
0,74,00,72,00,61,\
00,5c,00,57,00,41,00,4d,00,2e,00,73,00,79,00,73,00,00,00
"DisplayName"="Wicked Access by Mark"
"DeleteFlag"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\WAM\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,0
0,00,30,00,00,00,02,\

00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,0
0,00,00,01,00,00,\

00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,0
1,00,00,00,00,00,\

05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,0
0,05,20,00,00,00,\

20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,0
5,0b,00,00,00,00,\

00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,2
3,02,00,00,01,01,\

00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,0
0,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\WAM\Enum]
"0"="Root\\LEGACY_WAM\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
-----Original Message-----
Hi

See if the following link helps:

0x00000050: PAGE_FAULT_IN_NONPAGED_AREA
http://aumha.org/win5/kbestop.php#0x50

--

Will Denny
MS-MVP Windows Shell/User
Please reply to the News Groups





.
 
Back
Top