Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Purpose of the .exc file in the EFI partition?
#1
What is the .exc file that Hasleo creates in the EFI partition for?

   
Reply
#2
@Zombo,

That is an excellent question.  I just fired up my Partition Master Pro software, and I have one of those .exc files as well.  The date corresponds to when I first installed the Hasleo Backup Suite.

I fired up Google in AI mode, and asked the question: "Why does the Hasleo Backup Suite create an "exc" file in the EFI partition?"

This was the answer I got:

Quote:The Hasleo Backup Suite creates a temporary placeholder or tracking file (often ending in a variation like .exc) in the EFI System Partition (ESP) to manage the Preboot Execution Environment (WinPE) and safely track Sector-Level changes during an active backup/cloning session.

Because the EFI partition contains critical boot files, Hasleo utilizes this space for specific operational tasks:

1. Exclusion Tracking and VSS Coordination

When performing a live backup or system clone, Hasleo interfaces with Windows' Volume Shadow Copy Service (VSS) to take a snapshot of the active volume. The .exc file serves as an exclusion log or pointer metadata file. It informs the backup engine which temporary VSS system files, pagefiles, or active boot sectors are currently locked or should be excluded from being written into the backup image file.

2. Pre-OS (WinPE) Recovery & Boot Menu Integration

Hasleo offers features to add its recovery agent directly into your Windows Boot Menu or to set up a temporary reboot function for a raw partition restore. The software writes small configuration and control files directly to the EFI partition to ensure that if the computer reboots midway through a system-level process, the motherboard's UEFI firmware knows how to safely hand over control to the Hasleo recovery suite.

Is it safe to delete?

During a backup/clone: Do not touch or delete this file while the software is actively processing, as it can cause the backup image to corrupt or fail integrity checks.

After the backup finishes: Hasleo is supposed to automatically purge its temporary workspace files upon a successful operation. If the .exc file remains, it is usually safe to delete. However, because it resides in the sensitive EFI partition, it is best practice to let the software manage it naturally or use the built-in logs to verify the task is fully closed.

FORUM RULE 8 DISCLOSURE:  This post does contain an AI quote.

I hope this helps.  Have a great day.

Regards,
Phil
Reply
#3
As always, please take AI answers with a grain of salt. It often sounds very intelligent but it might still be full of hallucinations.

Here's what @admin said about that file in 2024:

(05-04-2024, 09:08 AM)admin Wrote:
(05-01-2024, 06:16 AM)aldist Wrote: The program creates a small 2kB file C:\D519D51B249349f38D79D76488950CB5.EXC , is this how it should be?

Yes, D519D51B249349f38D79D76488950CB5.EXC is a file created by HBS that is used to exchange information between Windows and WinPE, such as passing information about the partition(s) you want to back up to WinPE.

So it doesn't seem to be related to exclusion tracking or VSS coordination. It just holds basic information for the WinPE instance of HBS.

During restores where HBS needs to boot into WinPE to continue its restore process, there might be other temporary files that also hold important information, like 06975B7E3FCD4185A856CAF94647E435.EXC, which are also required for the HBS process in WinPE to function properly.

Please don't delete those files if you have HBS installed on your system.
Reply
#4
@Zombo,

I defer to my Moderator colleague, @al3x.  He has far more knowledge of HBS than I do.  Like you, I wanted to find out why that file was also on my system; hence, my resort to a clearly-identified AI post that I shared with you.  My conclusion was that it was legitimate file, with a legitimate purpose, and users should not delete it.

Have a great day.

Regards,
Phil
Reply
#5
@Zombo, yes, the file D519D51B249349f38D79D76488950CB5.EXC in the EFI system partition is created by Hasleo Backup Suite. It is used to exchange partition information and other related data between Windows and WinPE.
Reply
#6
(08-07-2026, 01:47 AM)admin Wrote: @Zombo, yes, the file D519D51B249349f38D79D76488950CB5.EXC in the EFI system partition is created by Hasleo Backup Suite. It is used to exchange partition information and other related data between Windows and WinPE.

It seems a majority of the files content is in chinese or chinese hex and some is in english.

I would be more comfortable if it was all in english so I can review the contents.
Reply
#7
(08-26-2026, 02:14 AM)Zombo Wrote:
(08-07-2026, 01:47 AM)admin Wrote: @Zombo, yes, the file D519D51B249349f38D79D76488950CB5.EXC in the EFI system partition is created by Hasleo Backup Suite. It is used to exchange partition information and other related data between Windows and WinPE.

It seems a majority of the files content is in chinese or chinese hex and some is in english.

I would be more comfortable if it was all in english so I can review the contents.

Thank you for your interest in, or perhaps concern about, this file.

The file D519D51B249349f38D79D76488950CB5.EXC you mentioned is located in the EFI system partition and is automatically created by Hasleo Backup Suite. It is a binary data file that serves as a temporary carrier for exchanging partition information and related data between Windows and the WinPE environment.

It should be noted that this file stores binary data that is readable by programs, not human‑readable text. The so‑called "Chinese" or "Chinese hexadecimal" content that appears when the file is opened is merely an illusion caused by forcefully decoding the binary data with a text viewer; the file itself does not store Chinese information in textual form. Therefore, viewing this file directly as text will not yield any meaningful readable content, this is determined by its intended purpose and data structure.

If you have further questions, please feel free to ask, and we will do our best to answer them.

Thank you for your understanding and support.
Reply
#8
(08-26-2026, 03:09 AM)admin Wrote: It should be noted that this file stores binary data that is readable by programs, not human‑readable text.

Yes it looks different when I use my hex and binary editors.

I know in the file that DMIO:ID is referring to the partition GUID.

Still have some parts of it to decipher.
Reply
#9
(08-26-2026, 03:53 AM)Zombo Wrote:
(08-26-2026, 03:09 AM)admin Wrote: It should be noted that this file stores binary data that is readable by programs, not human‑readable text.

Yes it looks different when I use my hex and binary editors.

I know in the file that DMIO:ID is referring to the partition GUID.

Still have some parts of it to decipher.

The format of this file is actually very simple. It stores the mapping between the unique identifiers of all partitions (such as the DMIO:ID you mentioned) and their corresponding drive letters, so that programs running in WinPE can correctly assign drive letters to those partitions. There's really no need to waste time parsing it, unless that's your hobby!  Big Grin
Reply
#10
Hi,

I just moved this topic in its own thread to keep the release thread a little more clean.
Feel free to continue the discussion here if needed Wink

Cheers,
al3x
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)