sc.exe
Associated Error Codes
Below lists error codes and symbolic names found for this module.
| Code | Found in | Description |
|---|---|---|
| 0x1 | 1011 | DESCRIPTION:
SC is a command line program used for communicating with the
Service Control Manager and services.
USAGE:
sc |
| 0x2 | 1011 | QUERY and QUERYEX OPTIONS: If the query command is followed by a service name, the status for that service is returned. Further options do not apply in this case. If the query command is followed by nothing or one of the options listed below, the services are enumerated. type= Type of services to enumerate (driver, service, userservice, all) (default = service) state= State of services to enumerate (inactive, all) (default = active) bufsize= The size (in bytes) of the enumeration buffer (default = %1) ri= The resume index number at which to begin the enumeration (default = 0) group= Service group to enumerate (default = all groups) SYNTAX EXAMPLES sc query - Enumerates status for active services & drivers sc query eventlog - Displays status for the eventlog service sc queryex eventlog - Displays extended status for the eventlog service sc query type= driver - Enumerates only active drivers sc query type= service - Enumerates only Win32 services sc query state= all - Enumerates all services & drivers sc query bufsize= 50 - Enumerates with a 50 byte buffer sc query ri= 14 - Enumerates with resume index = 14 sc queryex group= "" - Enumerates active services not in a group sc query type= interact - Enumerates all interactive services sc query type= driver group= NDIS - Enumerates all NDIS drivers |
| 0x3 | 1011 | DESCRIPTION:
Modifies a service entry in the registry and Service Database.
USAGE:
sc |
| 0x4 | 1011 | DESCRIPTION:
Creates a service entry in the registry and Service Database.
USAGE:
sc |
| 0x5 | 78.11011 | DESCRIPTION:
Changes the actions upon failure
USAGE:
sc |
| 0x6 | 78.11011 | DESCRIPTION:
Starts a service running.
USAGE:
sc |
| 0x7 | 78.11011 | DESCRIPTION:
Sends a PAUSE control request to a service.
USAGE:
sc |
| 0x8 | 78.11011 | DESCRIPTION:
Sends an INTERROGATE control request to a service.
USAGE:
sc |
| 0x9 | 78.11011 | DESCRIPTION:
Sends a CONTROL code to a service.
USAGE:
sc |
| 0xa | 78.11011 | DESCRIPTION:
Sends a CONTINUE control request to a service.
USAGE:
sc |
| 0xb | 78.11011 | DESCRIPTION:
Sends a STOP control request to a service.
USAGE:
sc |
| 0xc | 78.11011 | DESCRIPTION:
Sets the description string for a service.
USAGE:
sc |
| 0xd | 78.11011 | DESCRIPTION:
Queries the configuration information for a service.
USAGE:
sc |
| 0xe | 78.11011 | DESCRIPTION:
Retrieves the description string of a service.
USAGE:
sc |
| 0xf | 78.11011 | DESCRIPTION:
Retrieves the actions performed on service failure.
USAGE:
sc |
| 0x10 | 78.11011 | DESCRIPTION:
Queries the Lock Status for a SC Manager Database.
USAGE:
sc |
| 0x11 | 78.11011 | DESCRIPTION:
Deletes a service entry from the registry.
If the service is running, or another process has an
open handle to the service, the service is simply marked
for deletion.
USAGE:
sc |
| 0x12 | 78.11011 | DESCRIPTION:
Indicates whether the last boot should be saved as the
last-known-good boot configuration on the local machine.
If specified, the server name is ignored.
USAGE:
sc |
| 0x13 | 78.11011 | DESCRIPTION:
Gets the display name associated with a particular service
USAGE:
sc |
| 0x14 | 78.11011 | DESCRIPTION:
Gets the key name associated with a particular service,
using the display name as input
USAGE:
sc |
| 0x15 | 78.11011 | DESCRIPTION:
Enumerates the Services that are dependent on this one
USAGE:
sc |
| 0x16 | 78.11011 | DESCRIPTION:
Displays a service's security descriptor in SDDL format
USAGE:
sc |
| 0x17 | 78.11011 | DESCRIPTION:
Sets a service's security descriptor
USAGE:
sc |
| 0x23 | 78.11011 | SERVICE_NAME: %1 DESCRIPTION: %2 |
| 0x24 | 78.11011 | Name = %1 |
| 0x25 | 78.11011 | %1 |
| 0x26 | 78.11011 | IsLocked : TRUE |
| 0x27 | 78.11011 | IsLocked : FALSE |
| 0x28 | 78.11011 | LockOwner : %1 LockDuration : %2 (seconds since acquired) |
| 0x29 | 78.11011 | [SC] Tag = %1 |
| 0x2a | 78.11011 | [SC] %1: entriesread = %2 |
| 0x2b | 78.11011 | |
| 0x2d | 78.11011 | Active database is locked. To unlock via API, press u: |
| 0x2e | 78.11011 | [SC] Will be unlocking database by exiting |
| 0x2f | 78.11011 | SERVICE_NAME: %1 %2 TYPE : %3 %4 %5 STATE : %6 %7 (%8, %9, %10) WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 |
| 0x30 | 78.11011 | SERVICE_NAME: %1 DISPLAY_NAME: %2 TYPE : %3 %4 %5 STATE : %6 %7 (%8, %9, %10) WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 |
| 0x31 | 78.11011 | SERVICE_NAME: %1 %2 TYPE : %3 %4 %5 STATE : %6 %7 (%8, %9, %10) WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 PID : %17 FLAGS : %18 |
| 0x32 | 78.11011 | SERVICE_NAME: %1 DISPLAY_NAME: %2 TYPE : %3 %4 %5 STATE : %6 %7 (%8, %9, %10) WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 PID : %17 FLAGS : %18 |
| 0x33 | 78.11011 | SERVICE_NAME: %1 RESET_PERIOD (in seconds) : %2 REBOOT_MESSAGE : %3 COMMAND_LINE : %4 |
| 0x34 | 78.11011 | FAILURE_ACTIONS : RESTART -- Delay = %1 milliseconds. |
| 0x35 | 78.11011 | RESTART -- Delay = %1 milliseconds. |
| 0x36 | 78.11011 | FAILURE_ACTIONS : REBOOT -- Delay = %1 milliseconds. |
| 0x37 | 78.11011 | REBOOT -- Delay = %1 milliseconds. |
| 0x38 | 78.11011 | FAILURE_ACTIONS : RUN PROCESS -- Delay = %1 milliseconds. |
| 0x39 | 78.11011 | RUN PROCESS -- Delay = %1 milliseconds. |
| 0x3a | 78.11011 | SERVICE_NAME: %1 TYPE : %2 %3 %4 START_TYPE : %5 %6 ERROR_CONTROL : %7 %8 BINARY_PATH_NAME : %9 LOAD_ORDER_GROUP : %10 TAG : %11 DISPLAY_NAME : %12 DEPENDENCIES : %13 |
| 0x3b | 78.11011 | : %1 |
| 0x3c | 78.11011 | SERVICE_START_NAME : %1 |
| 0x64 | 78.11011 | [SC] %1 SUCCESS |
| 0x65 | 78.11011 | [SC] %1 FAILED %2: %3 |
| 0x66 | 78.11011 | [SC] %1 needs %2 bytes |
| 0x67 | 78.11011 | [SC] %1: more data, need %2 bytes start resume at index %3 |
| 0x68 | 78.11011 | [SC] %1: more data, need %2 bytes |
| 0x69 | 78.11011 | ERROR: Invalid %1 field |
| 0x6a | 78.11011 | ERROR: Invalid Option |
| 0x6b | 78.11011 | ERROR: Cannot specify a service name when enumerating a group |
| 0x6c | 78.11011 | ERROR: A service name is required |
| 0x6d | 78.11011 | ERROR: Unrecognized command |
| 0x6e | 78.11011 | ERROR: The reset and actions options must be set simultaneously |
| 0x6f | 78.11011 | u |
| 0x71 | 78.11011 | DESCRIPTION:
Changes the failure actions flag setting of a service.
If this setting is 0 (default), the Service Control Manager
(SCM) enables configured failure actions on the service
only if the service process terminates with the service in
a state other than SERVICE_STOPPED. If this setting is 1,
the SCM enables configured failure actions on the service
if the service enters the SERVICE_STOPPED state with a Win32
exit code other than 0 in addition to the service process
termination as above. This setting is ignored if the service
does not have any failure actions configured.
USAGE:
sc |
| 0x72 | 78.11011 | DESCRIPTION:
Retrieves the failure actions flag setting of a service.
If this setting is 0 (default), the Service Control Manager
(SCM) enables configured failure actions on the service
only if the service process terminates with the service in
a state other than SERVICE_STOPPED. If this setting is 1,
the SCM enables configured failure actions on the service
if the service enters the SERVICE_STOPPED state with a Win32
exit code other than 0 in addition to the service process
termination as above. This setting is ignored if the service
does not have any failure actions configured.
USAGE:
sc |
| 0x73 | 78.11011 | SERVICE_NAME: %1 FAILURE_ACTIONS_ON_NONCRASH_FAILURES: TRUE |
| 0x74 | 78.11011 | SERVICE_NAME: %1 FAILURE_ACTIONS_ON_NONCRASH_FAILURES: FALSE |
| 0x75 | 78.11011 | DESCRIPTION:
Changes the service security identifier (SID) type
setting of a service.
If this setting is "unrestricted", the Service Control
Manager (SCM) will add this service's SID to the service
process token when the service process starts the next
time due to the first service in the process being started.
This setting is valid only for Win32 user mode services.
If this setting is "restricted", the Service Control
Manager (SCM) will add this service's SID to the service
process token when the service process starts the next
time due to the first service in the process being started.
In addition, this service's SID will also be added to
the restricting SID list in the process token. The process
token will be a restricted token. See MSDN for details on
restricted token. This setting is valid only for Win32
user mode services. In addition, for a share process service,
all services cohosted in the process must have this SID type
set for this to take effect.
If this setting is "none", the SCM will not add the service's
SID to the service process token.
USAGE:
sc |
| 0x76 | 78.11011 | DESCRIPTION:
Queries the service security identifier (SID) type
setting of a service.
If this setting is "unrestricted", the Service Control
Manager (SCM) will add this service's SID to the service
process token when the service process starts the next
time due to the first service in the process being started.
This setting is valid only for Win32 user mode services.
If this setting is "restricted", the Service Control
Manager (SCM) will add this service's SID to the service
process token when the service process starts the next
time due to the first service in the process being started.
In addition, this service's SID will also be added to
the restricting SID list in the process token. The process
token will be a restricted token. See MSDN for details on
restricted token. This setting is valid only for Win32
user mode services. In addition, for a share process service,
all services cohosted in the process must have this SID type
set for this to take effect.
If this setting is "none", the SCM will not add the service's
SID to the service process token.
USAGE:
sc |
| 0x77 | 78.11011 | SERVICE_NAME: %1 SERVICE_SID_TYPE: UNRESTRICTED |
| 0x78 | 78.11011 | SERVICE_NAME: %1 SERVICE_SID_TYPE: NONE |
| 0x79 | 78.11011 | SERVICE_NAME: %1 PRIVILEGES : %2 |
| 0x7a | 78.11011 | : %1 |
| 0x7b | 78.11011 | DESCRIPTION:
Queries the required privileges setting for a service.
The privilege settings take effect when the
service process starts due to the first service in
the process being started. At that time, the Service
Control Manager (SCM) computes the union of all privileges
required by all services that will be hosted in the same
process and then creates the process with those
privileges. An absence of this setting is taken to imply
that the service requires all the privileges that
the security subsystem allows for a process running
in the service's configured account.
USAGE:
sc |
| 0x7c | 78.11011 | DESCRIPTION:
Changes the required privileges setting of a service.
The privilege settings take effect when the
service process starts due to the first service in
the process being started. At that time, the Service
Control Manager (SCM) computes the union of all privileges
required by all services that will be hosted in the same
process and then creates the process with those
privileges. An absence of this setting is taken to imply
that the service requires all the privileges that
the security subsystem allows for the process running
in the service's configured account.
USAGE:
sc |
| 0x7d | 78.11011 | SERVICE_NAME: %1 SERVICE_SID_TYPE: RESTRICTED |
| 0x7e | 78.11011 | SDDL right Right value ---------- ----------- GA - GENERIC_ALL GR - GENERIC_READ GW - GENERIC_WRITE GX - GENERIC_EXECUTE RC - READ_CONTROL SD - DELETE WD - WRITE_DAC WO - WRITE_OWNER RP - SERVICE_START WP - SERVICE_STOP CC - SERVICE_QUERY_CONFIG DC - SERVICE_CHANGE_CONFIG LC - SERVICE_QUERY_STATUS SW - SERVICE_ENUMERATE_DEPENDENTS LO - SERVICE_INTERROGATE DT - SERVICE_PAUSE_CONTINUE CR - SERVICE_USER_DEFINED_CONTROL |
| 0x7f | 78.11011 | SDDL right Right value ---------- ----------- GA - GENERIC_ALL KA - GENERIC_ALL GR - GENERIC_READ GW - GENERIC_WRITE GX - GENERIC_EXECUTE RC - READ_CONTROL SD - DELETE WD - WRITE_DAC WO - WRITE_OWNER RP - SC_MANAGER_QUERY_LOCK_STATUS WP - SC_MANAGER_MODIFY_BOOT_CONFIG CC - SC_MANAGER_CONNECT DC - SC_MANAGER_CREATE_SERVICE LC - SC_MANAGER_ENUMERATE_SERVICE SW - SC_MANAGER_LOCK |
| 0x80 | 78.11011 | SERVICE_NAME: %1 %2 TYPE : %3 %4 %5 STATE : %6 %7 WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 |
| 0x81 | 78.11011 | SERVICE_NAME: %1 DISPLAY_NAME: %2 TYPE : %3 %4 %5 STATE : %6 %7 WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 |
| 0x82 | 78.11011 | SERVICE_NAME: %1 %2 TYPE : %3 %4 %5 STATE : %6 %7 WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 PID : %17 FLAGS : %18 |
| 0x83 | 78.11011 | SERVICE_NAME: %1 DISPLAY_NAME: %2 TYPE : %3 %4 %5 STATE : %6 %7 WIN32_EXIT_CODE : %11 (0x%12) SERVICE_EXIT_CODE : %13 (0x%14) CHECKPOINT : 0x%15 WAIT_HINT : 0x%16 PID : %17 FLAGS : %18 |
| 0x84 | 78.11011 | WARNING: The service %1 is configured as interactive whose support is being deprecated. The service may not function properly. |
| 0x85 | 8.11011 | NAME: %1 SERVICE SID: %2 STATUS: Active |
| 0x86 | 78.11011 | DESCRIPTION: Displays the service SID string corresponding to an arbitrary name. The name can be that of an existing or non-existent service. USAGE: sc showsid [name] |
| 0x87 | 78.11011 | [SC] %1 FAILED with error %2. |
| 0x88 | 8.11011 | DESCRIPTION:
Changes the trigger parameters of a service.
USAGE:
sc |
| 0x89 | 78.11011 | SERVICE_NAME: %1 |
| 0x8a | 78.11011 | DEVICE INTERFACE ARRIVAL : %1 [INTERFACE CLASS GUID] |
| 0x8b | 78.11011 | CUSTOM : %1 [ETW PROVIDER UUID] |
| 0x8c | 78.11011 | IP ADDRESS AVAILABILITY : %1 [NO IP ADDRESS AVAILABLE] |
| 0x8d | 78.11011 | HUMAN INTERFACE DEVICE : %1 [INTERFACE CLASS GUID] |
| 0x8e | 78.11011 | DESCRIPTION:
Retrieves the trigger information of a service.
USAGE:
sc |
| 0x8f | 78.11011 | DATA : %1 |
| 0x90 | 78.11011 | The service %1 has not registered for any start or stop triggers. |
| 0x91 | 78.11011 | START SERVICE |
| 0x92 | 78.11011 | STOP SERVICE |
| 0x93 | 78.11011 | IP ADDRESS AVAILABILITY : %1 [FIRST IP ADDRESS AVAILABLE] |
| 0x94 | 78.11011 | DOMAIN JOINED STATUS : %1 [DOMAIN JOINED] |
| 0x95 | 78.11011 | DOMAIN JOINED STATUS : %1 [NOT DOMAIN JOINED] |
| 0x96 | 78.11011 | DESCRIPTION:
Changes the preferred NUMA node for a Win32 service.
This setting is valid only for own process services.
To delete an existing setting, set the node number as -1.
If an invalid preferred node number is supplied, then the
change request will fail.
USAGE:
sc |
| 0x97 | 78.11011 | DESCRIPTION:
Queries the preferred NUMA node for a Win32 service.
This setting is valid only for own process services.
If the service has no preferred node setting, then
the query will fail.
USAGE:
sc |
| 0x98 | 78.11011 | PREFERRED NODE : %1 |
| 0x99 | 78.11011 | [NOTE: Since the service start type is disabled, the triggers are inactive.] |
| 0x9a | 78.11011 | FIREWALL PORT EVENT : %1 [PORT OPEN] |
| 0x9b | 78.11011 | FIREWALL PORT EVENT : %1 [PORT CLOSE] |
| 0x9c | 78.11011 | GROUP POLICY : %1 [MACHINE POLICY PRESENT] |
| 0x9d | 78.11011 | GROUP POLICY : %1 [USER POLICY PRESENT] |
| 0x9e | 8.11011 | NAME: %1 SERVICE SID: %2 STATUS: Inactive |
| 0xa2 | 8.11011 | NETWORK EVENT : %1 [RPC INTERFACE EVENT] |
| 0xa3 | 8.11011 | NETWORK EVENT : %1 [NAMED PIPE EVENT] |
| 0xa6 | 8.11011 | CUSTOM SYSTEM STATE CHANGE EVENT : %1 |
| 0xa7 | 8.11011 | This error may occur if another service is already using a Named Pipe or RPC trigger for the same endpoint or interface as the given service. |
| 0xa8 | 8.11011 | DESCRIPTION:
Changes whether the account in which the service runs
uses a managed password.
If this setting is "true", the Service Control
Manager (SCM) will request the account password from
NetLogon when starting the service.
If this setting is "false", the SCM will use the
configured account password.
USAGE:
sc |
| 0xa9 | 8.11011 | ACCOUNT MANAGED : %1 |
| 0xaa | 8.11011 | DESCRIPTION:
Queries whether the account configured for this
service has a managed account password.
USAGE:
sc |
| 0xab | 8.11011 | ERROR: Invalid trigger data value |
| 0xac | 8.11011 | DESCRIPTION:
Queries whether the service is marked to start in
a protected process. Note that this setting cannot
be changed.
USAGE:
sc |
| 0xad | 8.11011 | SERVICE %1 PROTECTION LEVEL: NONE. |
| 0xae | 8.11011 | SERVICE %1 PROTECTION LEVEL: WINDOWS. |
| 0xaf | 8.11011 | SERVICE %1 PROTECTION LEVEL: WINDOWS LIGHT. |
| 0xb0 | 8.11011 | SERVICE %1 PROTECTION LEVEL: ANTIMALWARE LIGHT. |
| 0xb1 | 8.11011 | SERVICE %1 PROTECTION LEVEL: INVALID VALUE. |
| 0xb2 | 1011 | DESCRIPTION:
Queries for a user service instance for the current
user in the same session created from the user service
template specified.
USAGE:
sc quserservice |
| 0xb3 | 1011 | USER SERVICE TEMPLATE %1, LOCAL SERVICE INSTANCE %2. |
| 0x1 | 7 | DESCRIPTION:
SC is a command line program used for communicating with the
Service Control Manager and services.
USAGE:
sc |
| 0x2 | 78.1 | QUERY and QUERYEX OPTIONS: If the query command is followed by a service name, the status for that service is returned. Further options do not apply in this case. If the query command is followed by nothing or one of the options listed below, the services are enumerated. type= Type of services to enumerate (driver, service, all) (default = service) state= State of services to enumerate (inactive, all) (default = active) bufsize= The size (in bytes) of the enumeration buffer (default = %1) ri= The resume index number at which to begin the enumeration (default = 0) group= Service group to enumerate (default = all groups) SYNTAX EXAMPLES sc query - Enumerates status for active services & drivers sc query eventlog - Displays status for the eventlog service sc queryex eventlog - Displays extended status for the eventlog service sc query type= driver - Enumerates only active drivers sc query type= service - Enumerates only Win32 services sc query state= all - Enumerates all services & drivers sc query bufsize= 50 - Enumerates with a 50 byte buffer sc query ri= 14 - Enumerates with resume index = 14 sc queryex group= "" - Enumerates active services not in a group sc query type= interact - Enumerates all interactive services sc query type= driver group= NDIS - Enumerates all NDIS drivers |
| 0x3 | 7 | DESCRIPTION:
Modifies a service entry in the registry and Service Database.
USAGE:
sc |
| 0x4 | 7 | DESCRIPTION:
Creates a service entry in the registry and Service Database.
USAGE:
sc |
| 0x70 | 78.1 | y |
| 0x85 | 7 | NAME: %1 SERVICE SID: %2 |
| 0x88 | 7 | DESCRIPTION:
Changes the trigger parameters of a service.
USAGE:
sc |
| 0x1 | 8.1 | DESCRIPTION:
SC is a command line program used for communicating with the
Service Control Manager and services.
USAGE:
sc |
| 0x3 | 8.1 | DESCRIPTION:
Modifies a service entry in the registry and Service Database.
USAGE:
sc |
| 0x4 | 8.1 | DESCRIPTION:
Creates a service entry in the registry and Service Database.
USAGE:
sc |
| 0x9f | 8.1 | DESCRIPTION:
Changes the lowest run level for a service.
This setting is valid only for services of start type
auto start, demand start and disabled and non plug and
play (PNP) driver services. A service cannot have a
lower run level setting than a service it depends on.
A run level of 0 can be specified to delete
the run level setting. If an invalid run level
is supplied, then the change request will fail or
the service will fail to start.
USAGE:
sc |
| 0xa0 | 8.1 | DESCRIPTION:
Queries the lowest run level for a service.
This setting is valid only for services of start type
auto start, demand start and disabled and non plug and
play (PNP) driver services. A service that has no run
level setting specified will have a value of 0.
USAGE:
sc |
| 0xa1 | 8.1 | LOWEST RUNLEVEL : %1 |
| 135 entries | ||