Start a Conversation

Unsolved

S

1 Message

11408

January 3rd, 2019 00:00

Apoint tries to delete c drive content

Dear support,

Every now and then (3 times in a few months now) when i restart my laptop I see a "Folder Access Denied" popup with the following content:

"You'll need to provide adminitrator permission to delete this folder"

Which is my entire C-drive.

I found that the process responsible for this request is Apoint.exe, using process explorer, which is hosted by the HidMonitorSvc.exe.

The files size of Apoint is 773760 bytes and is located in "C:\Program Files\DellTPad\"

Virus scanners or mallware scanners do not detect anything weird, but the behaviour is somewhat odd i might say. Can You please elaborate somewhat on this?

My system is running Microsoft Windows 10 Pro, Version 10.0.17763 Build 17763.

Thanks in advance

7 Technologist

 • 

12K Posts

January 4th, 2019 17:00

The following will shed more light on that .exe file. It is actually part of the Alps Pointing device (your touchpad). Why it tries to delete the C: drive files sounds awfully strange. Try another anti virus program scan and download and scan with Malwarebytes Free.

https://www.file.net/process/hidmonitorsvc.exe.html

https://www.neuber.com/taskmanager/process/apoint.exe.html

3 Apprentice

 • 

4.3K Posts

January 5th, 2019 08:00

Is this an older system with the old style touchpad?

Are there any updates for the touchpad driver?

I am wondering if Win 10 is having a problem with an older driver which is starting up when it may not be needed.

I certainly agree, if you are seeing a request to delete the entire OS partition, that would not be good.

You might use Autoruns to see if apoint is starting up and uncheck it for testing.

Edit:  I have an older Inspiron 1545 which has the folders and drivers you mention.  But it is running Win 7.  In the Win 10 clean install version, no such folder is present.

4 Posts

January 22nd, 2019 08:00

I'm see the same thing Apoint.exe ("C:\Program Files\DellTPad\Apoint.exe") is set to start on bootup in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Then sometimes I'm seeing a "Folder Access Denied" pop up asking for permission to continue - first time I saw this I blindly clicked "Continue" then noticed it was preparing to delete a whole load of files - fortunately I managed to cancel before damage was done. This is on Windows 10 Pro on a Latitude E5470

4 Posts

January 26th, 2019 04:00

4 Posts

January 26th, 2019 04:00

These show the pop up that appears roughly twice a week, Task Manager showing that it's a child of the Alps Pointer process and finally the properties of that executable.

Untitled.pngUntitled2.pngUntitled3.png

January 28th, 2019 23:00

Any solutions on this

1 Message

February 4th, 2019 13:00

I randomly experience the exact same issue.

Latitude 5580. Windows 10 Pro.

To be honest, it's pretty ridiculous :Indifferent:

1 Message

March 6th, 2019 21:00

I have the same problem on my Latitude E7440. Even I have disabled the app from Startup, it still tries to delete my C drive.

March 13th, 2019 16:00

OMG, I can't believe that I found this thread. I have been fighting this thing for months. Is it a virus attached to the keypad/mouse driver? Key logger? It's been driving me insane. Glad I'm not alone.

I deleted the service, uninstalled touchpad, and took it out of startup.

Hope that does it. I'll stick with the default mouse microsoft driver.

Why the #!!!$* would there be something in that driver or service that would try to delete your whole C drive? Totally insane.

This is my favorite thread in the universe!

March 22nd, 2019 00:00

I have exactly same issue. Any resolution from DELL?

6 Posts

March 22nd, 2019 05:00

I had the exact same thing happen to me today for the first time. I just updated my Win10x64 Dell Precision 7510 laptop to the 1809 release of Win 10 last week.

I wonder if Dell even bothers reading this forum.

8 Wizard

 • 

47K Posts

March 28th, 2019 09:00

Apoint is part of the device driver package for  touchpads manufactured by Alps.

Deleting files comes from malware W32/Chir-B worm, an EXE file infector not the OEM Dell driver.

When run the virus will copy itself into the Windows system folder as runonce.exe and sets the registry entry
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Runonce

to start this new copy of the virus. This will cause the virus to be started when Windows starts up. The virus continually monitors this registry entry so
that any attempt to change or delete the entry.

The worm searches through all local and mapped drives to infect files with the following extensions:

  • .htm
  • .html
  • .exe
  • .scr

 

4 Posts

April 4th, 2019 01:00

Hi, Did some research around W32/Chir-B worm, but couldn't find any mention of it trying to delete all files on a C drive.

Also, there's no HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Runonce entry in my registry or any reference to runonce.exe

Windows Defender and Malwarebytes detect no virus in  runonce.exe in windows\system32 (or in any of the other three versions of it in the Windows directory) nor do they find any viruses anywhere else on my system.

The digital signatures on apoint.exe all check out, so it appears not to be infected.

sfc /scannow also came back with no issues

So I'm really not sure why you think it's a virus and not a bug.

6 Posts

April 4th, 2019 06:00

It is a trojan only in the sense that the ALPS Pointoing Device driver is behaving like a trojan. I updated all the drivers on my laptop and it immediately came up with this same error on the very next power up. The EXE for the ALPS pointing device was updated as well and I scanned it again along with the rest of my computer using Malware Bytes and Windows Defender again. 

The next 2 powerups it has not happened. I have now completely disabled the service and will only turn it on when I need to use it.

Too bad Dell doesn't pay attention to their own support community.

6 Posts

April 4th, 2019 06:00

How do I contact support when the web site does not work? I have tried doing this several times and it is not possible for me to get the contact form to come up. I have tried with 3 different browsers. Here is Chrome:

Capture.JPG

No Events found!

Top