Find out why Windows says your USB drive is "in use", fix it, and eject it.
When Windows refuses to eject an external drive, it rarely says who is holding it. Drive In Use lists every program that has something open on the drive and tells you what to do about each one. Then it ejects the drive the same way "Safely Remove Hardware" does.
- See what holds the drive: open files, folders, and handles to the whole volume in every process, plus programs and DLLs running from the drive and memory-mapped files.
- Know what to do: a plain hint for every result, for example "Everything keeps D: open to watch for file changes. Quit it from its tray icon, or stop indexing the drive: ..."
- Act on it: switch to the program's window, close the Explorer windows showing the drive, or, with a warning first, force-close the program's handle or end the program.
- Eject: from the window, the tray icon, or the hotkey Win+Shift+E. If Windows refuses, it tells you why and who is blocking it.
- Windows' eject log: what Windows recorded about earlier refused ejects (Kernel-PnP event 225).
- Sortable lists, each program's command line, tray icon, dark mode.
- A single
.exewith no installer and no dependencies, plus a command-line version.
How it compares with other tools: docs/ALTERNATIVES.md.
- Windows 10 (1809 or later) or Windows 11, 64-bit
- .NET Framework 4.5 or later, which is built into Windows 10 and 11
Download the zip from the latest release, unzip it
anywhere, and run DriveInUse.exe. There is nothing to install. The program isn't code-signed yet, so
Windows SmartScreen may say "Windows protected your PC"; click More info > Run anyway.
Or build it from source (it takes a few seconds, no SDK needed):
git clone https://github.com/ramich/drive-in-use.git
cd drive-in-use
.\build.ps1This produces bin\DriveInUse.exe (the app) and bin\DriveInUse-cli.exe (the command-line version).
- Start
DriveInUse.exe, pick the drive, and click Scan (F5). - Select a row to see what to do about it, and use Show window, Close Explorer windows, Close handle, or End process. Click a column header to sort.
- Click Eject (Ctrl+E).
Run it as administrator (File > Restart as administrator) to also see services and other users' processes, such as the search indexer or a background indexing service. Protected processes like Microsoft Defender can't be inspected even then; they are listed greyed out.
The app lives in the tray: closing the window or pressing Esc hides it, and the tray menu can eject drives directly. Only one copy runs; starting it again brings the window forward.
| Option | What it does |
|---|---|
DriveInUse D: |
Open with drive D: selected (the system drive is only listed when named like this) |
DriveInUse --tray |
Start hidden in the tray, for example from shell:startup |
DriveInUse --exit |
Close the running copy |
DriveInUse --hide-paths |
Leave paths and command lines out of the window, for screenshots |
> DriveInUse-cli D:
D: = \Device\HarddiskVolume7 elevated: no (run as admin to see system processes) scan: 1.7s
Everything.exe 2768 Volume D:\ (x2)
What to do:
Everything.exe (2768): Everything keeps D: open to watch for file changes. Quit Everything from its tray icon, or stop indexing the drive: Tools > Options > Indexes > NTFS, select D:, untick "Include in database".
DriveInUse-cli --device D: shows which device Eject would remove, without ejecting anything.
- Open handles: lists every handle in the system (
NtQuerySystemInformation), copies the file handles of each process, and keeps the ones on the drive. Name lookups run on a worker thread with a timeout, because some handles (pipes with pending I/O) block forever. - Loaded programs and mapped files: walks each process's memory map (
VirtualQueryEx+GetMappedFileName). These hold the drive without any handle. - Eject: finds the drive's USB device and calls
CM_Request_Device_Eject, the same call "Safely Remove Hardware" makes. Windows' refusal reason and the blocker's name are shown as-is.
- Nothing is written to the drive, and nothing is sent over the network.
- Other processes are only read, never changed. The exceptions are Close handle and End process, which you have to confirm. Close handle re-checks each handle right before closing it, so a handle number the program has reused for something else is left alone.
- Settings (theme, Esc, hotkey) are stored in
HKCU\Software\DriveInUse.
.\build.ps1 uses the C# compiler that ships with Windows (.NET Framework 4.x).
- Version: taken from the top
## [x.y.z] - yyyy-mm-ddentry in CHANGELOG.md. To release a new version, add an entry there. - Changelog: compiled into the app (Help > Changelog); it is never read from disk at runtime.
- Icon:
src\app.ico, drawn bytools\make-icon.ps1. Run it again only if you change the design.
| File | Contents |
|---|---|
src\Core.cs |
Scanning, eject, event log |
src\Hints.cs |
The "what to do" hints |
src\Gui.cs |
Main window and tray |
src\Theme.cs |
Light and dark themes, settings |
src\Windows.cs |
Finding a process's window, Explorer windows |
src\Cli.cs |
Command-line version |
Copyright (C) 2026 ramich
Drive In Use is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. If you distribute a changed version, its source code has to be available under the same license.
It is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the LICENSE for details.