• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Solved A corruption was found in a file system index structure. The file reference number is 0x30000000212ea.

Status
Not open for further replies.

Marco Oliveras

PCHF Member
Feb 2, 2023
35
2
23
A corruption was found in a file system index structure. The file reference number is 0x30000000212ea. The name of the file is "\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR". The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".

Im having this error code on my window logs I was wondering if anyone knew how to either delete the folder or fix the file
 
Install unlocker.
Then install Everything search.
Right Click on the VoidTools application and Run As Administrator.
Type WinRaR into the Everything Search Window.
Now Click on Edit Then Select all.
Right click highlighted items.
Select unlocker in drop down menu.
Then select delete.
Then hit ok.
 
Did you use everything search engine?


Right Click on the VoidTools application and Run As Administrator.
Type WinRaR into the Everything Search Window.
Now Click on Edit Then Select all.
Right click highlighted items.

And select copy to clipboard.
Post the result here.
 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk

These are the results
 
Open a notepad and copy the content of the code box below, paste into open notepad and save it to your desktop as clean.bat then right click on clean.bat and run as admin.

Code:
del /s /q C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
del /s /q C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk
del /s /q C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk
 
We will be able to nuke it with this tool. Run this for me please.

Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.
If you are unsure if your operating system is 32 or 64 Bit please go HERE.
Once downloaded right click the FRST desktop icon and select "Run as administrator" from the menu
If you receive any security warnings, or the User Account Control warning opens at any time whilst using FRST you can safely allow FRST to proceed.
FRST will open with two dialogue boxes, accept the disclaimer.
  1. Accept the default whitelist options,
  2. If the additions.txt options box is not checked please select it.
  3. Then select Scan
  4. Frst will take a few minutes to scan your computer, and when finished will produce two log files on your desktop, FRST.txt, and Addition.txt. They will display immediately on the desktop, but can be reopened later as a notepad file.





2016-08-12_152002.jpg


Please Attach the contents of these logs in your next post for review by our Security Team
 
Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.

Code:
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
RemoveProxy:
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
C:\Users\Owner\AppData\Local\2476191251
C:\Users\Owner\AppData\Local\3663574423
C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.45.5.0_x64__6rarf9sa4v8jt
ShortcutWithArgument: C:\Users\Owner\Desktop\Build It.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=jleoijhialapfdgmkbjiphndkhnhhpaf
ShortcutWithArgument: C:\Users\Owner\Desktop\Tracker Network.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=ifcifgfhefiglkpogbbibhepmfjkmejl
ShortcutWithArgument: C:\Users\Owner\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__eikjhbkpemdappjfcmdeeeamdpkgabmk\SoundCloud.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) ->  --profile-directory=Default --app-id=eikjhbkpemdappjfcmdeeeamdpkgabmk --app-url=hxxps://soundcloud.com/discover --app-launch-source=4
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Build It.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=jleoijhialapfdgmkbjiphndkhnhhpaf
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Tracker Network.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=ifcifgfhefiglkpogbbibhepmfjkmejl
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SoundCloud.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) ->  --profile-directory=Default --app-id=eikjhbkpemdappjfcmdeeeamdpkgabmk --app-url=hxxps://soundcloud.com/discover --app-launch-source=4
AlternateDataStreams: C:\ProgramData:err [1484]
AlternateDataStreams: C:\Windows\system32\9EarsSurroundSound.dll:72B1DE377E [3442]
AlternateDataStreams: C:\Users\All Users:err [1484]
AlternateDataStreams: C:\ProgramData\Application Data:err [1484]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini:B1DA6C571C [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk:B026C77744 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BakkesMod.lnk:14E057C8D9 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix Workspace.lnk:7464C599B4 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini:41964AA945 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk:8096E45125 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk:E77773B271 [3442]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk:F20EF51E1F [3442]
AlternateDataStreams: C:\Users\Owner\AppData\Local\Temp:$DATA [16]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [7434]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk
C:\Windows\system32\drivers\etc\hosts
Hosts:
FirewallRules: [{82915ED8-2C08-4BEE-B103-ED6A811F7710}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe => No File
FirewallRules: [TCP Query User{93B10DEF-9549-405A-A5A5-F08A5927CE83}C:\users\owner\appdata\local\discord\app-1.0.9004\discord.exe] => (Allow) C:\users\owner\appdata\local\discord\app-1.0.9004\discord.exe => No File
FirewallRules: [UDP Query User{28AFE870-96AC-426E-9703-7F69D24BBAF9}C:\users\owner\appdata\local\discord\app-1.0.9004\discord.exe] => (Allow) C:\users\owner\appdata\local\discord\app-1.0.9004\discord.exe => No File
FirewallRules: [{6FDE2969-7453-484C-ADFC-0F1EFDB0727A}] => (Allow) C:\Program Files (x86)\iMobie\PhoneRescue\xldownload\download\MiniThunderPlatform.exe => No File
FirewallRules: [{063A4512-C3A7-41F2-A88A-68D3ED76FDE8}] => (Allow) C:\Program Files (x86)\iMobie\PhoneRescue\xldownload\download\MiniThunderPlatform.exe => No File
FirewallRules: [{FA3EBEA6-F655-406C-B469-2CA345051171}] => (Allow) C:\Program Files (x86)\Overwolf\0.216.0.26\OverwolfBrowser.exe => No File
FirewallRules: [{1ED7F6F7-701F-4748-BB15-C5C3B28B4DE8}] => (Allow) C:\Program Files (x86)\Overwolf\0.216.0.26\OverwolfBrowser.exe => No File
FirewallRules: [{247D9A58-005A-484F-A869-1D4937EBF9D3}] => (Block) C:\Program Files (x86)\Overwolf\0.216.0.26\OverwolfBrowser.exe => No File
FirewallRules: [{89BBD2F7-9EE0-4DCD-8207-547AF3D29230}] => (Block) C:\Program Files (x86)\Overwolf\0.216.0.26\OverwolfBrowser.exe => No File
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
CMD: del /f /s /q %windir%\prefetch\*.*
CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*"
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
CMD: ipconfig /flushdns
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
emptytemp:
Reboot:
End::
 
Status
Not open for further replies.