WAM.SYS (LEGACY_WAM) - is it spyware or unused IBM driver ?

Operating System, Common Application & ThinkPad Utilities Questions...
Post Reply
Message
Author
Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2260
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

WAM.SYS (LEGACY_WAM) - is it spyware or unused IBM driver ?

#1 Post by Puppy » Tue Jan 18, 2005 3:24 pm

I found strange driver and related service in my registry with description "Wicked Access by Mark". It looks like a spyware at first glance. Google didn't help much except one posting which has additional information from the registry where imagepath to the (non-existing) WAM service was: \??\C:\Program Files\IBM\IBM Rapid Restore Ultra\WAM.sys

I don't have such file on my disk. Can someone confirm that the registry key (LEGACY_WAM) is on his/her machine as well ? I still can not believe that IBM would choose such stupid description for part of their product.
Last edited by Puppy on Mon Jan 24, 2005 9:06 am, edited 2 times in total.

s0larian
Junior Member
Junior Member
Posts: 289
Joined: Sat Jun 05, 2004 5:15 am
Location: Munich, Germany

#2 Post by s0larian » Tue Jan 18, 2005 6:24 pm

I have R&R 2.0 installed, but there is no key called LEGACY_WAM in the registry.
T40p 2373-g1g: 1.6 GHz, 1536 MB RAM, 160 GB @ 5400 rpm drive, 64 MB Video, IBM a/b/g II, CD-RW/DVD Combo II, M10 Fan, Ubuntu 8.04

Leeper
Sophomore Member
Posts: 176
Joined: Tue Apr 27, 2004 1:30 pm
Location: PDX
Contact:

#3 Post by Leeper » Tue Jan 18, 2005 7:17 pm

I know I have seen this somewhere and it ends up being a safe file haveing to do with IBM.

I will keep digging but I do remember it as not being spyware.

Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2260
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

#4 Post by Puppy » Sat Jan 22, 2005 9:42 pm

I did complete reinstall and the seems to be there again.

Anyway, could someone else please confirm that you have the key in your registry as well. I'm getting little bit nervous ;-) It seems to be related to Rapid Restore Ultra 4.0 but who knows ...

The key is located in the registry at following locations:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WAM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WAM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WAM

Thanks.

Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2260
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

#5 Post by Puppy » Sun Jan 23, 2005 8:23 am

More on this issue. I restored registry hive file from backup I've made after fresh reinstall and the WAM registry keys were there as well. So it looks like it is part of IBM preinstall. But the driver name still does not make me feeling "safe" because it reminds a stealth virus/spyware loader.

I don't think I could ever get a response from IBM ;-) I asked someone with T41 and he didn't confirmed presence of these registry keys.

Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2260
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

#6 Post by Puppy » Fri Jan 28, 2005 5:44 am

Hmmm ... am I really alone with this issue ?

Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2260
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

#7 Post by Puppy » Tue May 09, 2006 5:18 am

Confirmed, the driver is part of IBM software. I found another reference to it in a support forum http://forums.spywareinfo.com/lofiversi ... 60434.html

experttease
Posts: 23
Joined: Tue Aug 21, 2007 9:44 am
Location: Bristol,UK

#8 Post by experttease » Sat Oct 20, 2007 6:45 am

I get this service trying to start each time windows starts, and Comodo Antivirus stops it each time with its HIPS Aplication Control (don't really know what it is). whether I block it or allow it comodo never remembers my choice and it starts on reboot. It's pretty annoying. Any ideas? Comodo Antivirus is still in beta.

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Windows OS (Versions prior to Windows 7)”

Who is online

Users browsing this forum: No registered users and 4 guests