OK some weird things happened while on MSN messenger today I posted them on the IE forum but here it is:

"start the application sharing feature so I could see her desktop. The app share thing took forever to start working and we were never able to connect. THEN all of a sudden a bunch of IE boxes with "This page cannot be displayed" kept poppin up and I mean they kept poppin up all over the screen and I couldn't stop them. Yikes. So I disconnected and tried to reconnect my internet but I couldn't. It told me my connection was working but I kept getting a "This page cannot be displayed" and if I started Messenger it told me that I couldn't connect because of a firewall. I only use the Win xp firewall at the moment. Anyways 10 minutes later my service seems to be working fine but all those windows popping up has left me a little worried. If my computer is up to date then can I get viruses by connecting to an infected computer over MSMessenger? I did a virus scan and it didn't find anything, except for a 158MB file from a game which I'm assuming is an error. Any help would be appreciated. 2 other things: When this happened I noticed a process called rsvp.exe running that I've never seen before. Also there is a process called dvpapi.exe running and I don't know where I got that virus scanner from."


Anyways, after running every scan I could find, I shut my computer off and 2 minutes later it BOOTS BACK UP!!! It's never done that before. I went to the system/device manager and made sure my modem wasn't set to wake up on anything (all I could think of doing) but it didn't work and sure enough my computer still boots back up by itself. !?!?!? I keep the net connection disabled when I'm not using it. Please someone help.

Dani AI

Generated

A short, practical summary and next steps that build on what , and already checked.

Your symptoms (lots of “This page cannot be displayed” popups during an MSN app‑share session, a process named rsvp.exe, a dvpapi.exe process, and the machine powering itself on) point at three separate, fixable areas: the legitimate QoS/RSVP service, a third‑party antivirus component, and BIOS/network wake settings. rsvp.exe is normally the Windows QoS (Resource Reservation) service used by conferencing/streaming code — that makes it plausible it showed up during app‑sharing — but malware sometimes uses the same filename, so confirm the file is the real system component. (file.net)

dvpapi.exe is commonly the runtime for certain bundled antivirus engines (Command/Authentium/Commtouch family) and usually lives under C:\Program Files\Common Files\…. If you don’t recognize the product, check the process’ file location and digital signature before condemning or deleting it. Use the file’s Properties → Digital Signatures (or signtool verify from Microsoft’s toolkit) to confirm the publisher. If the file is in C:\Windows or C:\Windows\System32 but not signed by Microsoft/known vendor, treat it as suspicious. (file.net)

PME (Power Management Event) is essentially the BIOS name for Wake‑on‑LAN/Wake‑by‑PCI; disabling the PME/WOL option in BIOS normally stops remote/network packets from powering the PC back on. Also check the network adapter’s Power Management tab in Device Manager (uncheck “Allow this device to wake the computer”) and any router/events that could send magic packets. (intel.com)

Quick triage checklist: (1) In Task Manager or Process Explorer find rsvp.exe/dvpapi.exe → right‑click → open file location and check signer. (2) Run Autoruns to inspect services/startup entries. (3) Run current, on‑demand scanners (for example Microsoft Safety Scanner and Malwarebytes) and submit any doubtful executables to VirusTotal for a second opinion. If multiple engines flag a file, quarantine and remove; if not, leave signed Microsoft files alone. Back up essential data before heavy cleanup or reinstallation. (learn.microsoft.com)

If anything looks odd (a file with a non‑System32 path, an unsigned Microsoft‑named file, or repeated unexplained wake events after disabling PME), report the exact file paths and the Autoruns/Process Explorer entries and recheck — those details let responders point to the precise removal steps.

Ypu have a bit of a problem there RSVP.exe is a backdoor trogan horse which messes about with Internet explorer more information is available at symantecs site http://securityresponse.symantec.com/avcenter/venc/data/backdoor.spotcom.html

Dvpapi.exe may be some spyware on your computer although I saw a mention of it being part of Command Antivirus software so the best thing to do would be to download adaware and scan your system for spyware.

OK I checked that rsvp link out it says the virus is called "msrsvp.exe" and it creates a certain entry in the registry. I checked and I only have a rsvp.exe and no modifications were made to my registry so I have a legitimate file right?

By the way, I fixed my computer from rebooting itself finally by going into the BIOS and disabling the "wake up on PME" or something; it was the only option that was active. What is PME and why would that solve the problem? I'm worried because it just started waking up after it started acting weird in all these other ways. THx!

Don't know about you.. but why don't you try surfing this website....

Here you would be able to check out if you really have a problem....

Ok I done a little more investigation of rsvp.exe and it appears to have something to do with netmeeting. so no worries there.

Wake on PME is Wake on Lan which is to do with powering on Pcs remotely over the network, i'm not sure why disableing it would fix your rebooting problem but it might explain the automatic wake up glad you have it sorted.

Thx all!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.