$Extend\$UsnJrnl

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Can anyone tell me what $Extend\$UsnJrnl is? I was trying to backup a PC,
and found that this file/folder was 23GB in size!
 
That's part of the internal structure of the NTFS file system. I don't
know whether 23GB is a reasonable size. If it's not a reasonable size
then your computer may be infected with malware.
 
Maybe it's used for indexing? He did have some unauthorized software
installed on his machine, but I removed some of it. It is no longer an issue
since I gave him a new PC and then had one of my network guys manually remove
that file so that we could backup the rest of his machine. I was just
curious as to what that is used for.
 
Laura:

Put '$Extend\$UsnJrnl' into a Google search. There are loads of
references to it. Best I can see is that it is a hidden NTFS file used
for Encryption information storage and/or File Info. Pretty much
everyone tell the user to leave it alone BUT one entry said that it
shouldn't be too large if you don't regularly use encyption. Sounds to
me like perhaps a Rootkit has gotten ahold of it and caused expansion.
One Google entry was for Rootkit information (from Microsoft actually).

GP

--->
 
Laura said:
Maybe it's used for indexing? He did have some unauthorized software
installed on his machine, but I removed some of it. It is no longer an issue
since I gave him a new PC and then had one of my network guys manually remove
that file so that we could backup the rest of his machine. I was just
curious as to what that is used for.

It's known that Windows Live Messenger 8.1 creates this indexing service so
users can share files and folders within the application. This service can
severe defragment the metadata files on the hard drive and it won't
'dissapear' even after WLM is uninstalled.

I run "fsutil usn deletejournal /D C:" to get rid of this defragmented
indexing service.
 
Back
Top