1. Problem Overview
Engineers running Siemens WinCC V7.0 on legacy Microsoft Windows XP SP3 or Windows Server 2003 R2 workstations occasionally trigger the OEM reset utility Reset_WinCC.vbs to forcibly terminate stuck WinCC processes before relaunching Runtime. When the script is executed, the Windows Script Host aborts with the following dialog instead of performing the cleanup:
Microsoft VBScript Runtime Error
C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs
Access Denied
Error: Line 51
Symptom chain observed in the field:
- WinCC Explorer refuses to enter Runtime, or Runtime activation stalls at 46% in Alarm Logging.
- Manually launching
Reset_WinCC.vbsvia Windows Explorer or Task Scheduler produces the Line 51 Access Denied termination. - Subsequent WinCC restart either opens a previously activated project or fails to start Runtime at all.
- On multi-node OPC server pairs, one node recovers while the second node remains stuck in Alarm Logging initialization.
Because Reset_WinCC.vbs terminates background processes (CCEServer, CCDistManager, WinCC SQL Server wrapper) without orderly shutdown, the error must be resolved before the script can be considered a safe maintenance tool.
2. Environment and Affected Versions
| Component | Version Confirmed in Source | Notes |
|---|---|---|
| Siemens WinCC | V7.0 (incl. SP3/SP4 updates) | Same script shipped through V7.0 + Upd4; older V6.x has a different reset utility |
| Operating System | Windows XP SP3, Windows Server 2003 R2 | Both 32-bit; same UAC/IL behavior because UAC is not active on XP/2003 |
| Script Engine | Windows Script Host 5.7 (XP) / 5.8 (Server 2003 R2) | VBScript runtime delivers Line N errors in this format |
| Database | Microsoft SQL Server 2005 Express bundled with WinCC | Must be stopped before deleting building files |
| OPC Layer | SIMATIC NET OPC / WinCC OPC | Failure in one node suggests process-level lock |
Reference: WinCC V7.0 System Manual (Siemens Support entry ID 38352278) and the public Siemens SIMATIC WinCC product page.
3. Root Cause Analysis
The Access Denied at Line 51 of Reset_WinCC.vbs is produced by a WshShell.Run or Terminate call attempting to kill a WinCC process owned by another user context or protected by NTFS ACLs on the executable / project directory. Three concurrent causes are typical:
-
Process held by elevated context. On Windows XP SP3, UAC is absent, but the
Reset_WinCC.vbsis frequently double-clicked from a user account that is not in the local Administrators group, or the project path is opened from a network share. The script then cannot callWMI Win32_Process.TerminateagainstCCEServer.exerunning as the interactive logon administrator. -
NTFS deny ACE on the project or
bindirectory. WinCC stores the building (rebuild) files in<ProjectPath>\GraCS\<name>_<lang>.pdland<ProjectPath>\Library\*.pdl. An explicit deny on the Users principal on the project root causes the cleanup portion of the script to throw on the file delete attempt. -
SQL Server or alarm-logging service is still holding the project database. Alarm Logging freezes at 46% because the WinCC Archive Manager cannot acquire an exclusive lock on the corresponding MDF/LDF files.
Reset_WinCC.vbsat Line 51 attempts to stop a service, the SCM call is rejected because the calling token lacksSE_DEBUG_NAME/SeLockMemoryPrivilege, and the VBScript runtime maps this to Access Denied.
Reference behavior: Microsoft Q&A — VBS script opening error documents the identical Access Denied dialog when a VBS in the Startup folder cannot enumerate the calling shell namespace.
4. Pre-Diagnostic Checklist
Before altering the script or permissions, capture the operational state of the station:
:: From an elevated command prompt
tasklist /v /fi "imagename eq cceserver.exe"
tasklist /v /fi "imagename eq ccdistmanager.exe"
tasklist /v /fi "imagename eq wincc.exe"
tasklist /v /fi "imagename eq sqlservr.exe"
sc query "WinCC"
sc query "CCArchiveManager"
whoami /groups | findstr /i "S-1-5-32-544"
icacls "C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs"
icacls "D:\Projects\<ProjectName>" /T | findstr /i "deny"
Record:
- Owning user of
CCEServer.exe— if it isSYSTEMor another interactive user, the running context is the cause. - Any explicit deny lines on the project or
bindirectory. - Service state of the WinCC SQL wrapper.
5. Resolution Path A — Privileged Execution
Use this path when the script simply needs to be re-launched under the correct security context.
- Log out of WinCC Runtime. Press Shift+Alt while WinCC Explorer opens so that the last activated project does not start automatically.
- Open a command prompt:
Start > Run > cmd.exe— not from inside a WinCC dialog. - Verify the local Administrators group membership:
net localgroup Administrators. The active user must be listed. - Launch the script with explicit credentials through
runaswhen a domain user policy restricts local admin caching:runas /user:<HOSTNAME>\Administrator "cscript.exe \"C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs\"". - If a domain policy disables
runas, schedule the script throughatasSYSTEM:at 00:01 /interactive cmd /c cscript.exe "C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs"— requiresScheduleservice running and the operator to be a member of the local Power Users or higher.
at requires the console session to be at the physical keyboard, not over RDP, otherwise the script will run but its VBS dialogs are never visible. Use a scheduled task in the Control Panel — Scheduled Tasks GUI when the console is at the SCADA node.6. Resolution Path B — Repair Project / Bin NTFS ACLs
Use this path when icacls above shows explicit deny entries or the project resides on a redirected/UNC path.
- Stop all WinCC services in order:
net stop "WinCC"
net stop "CCArchiveManager"
net stop "CCDistManager"
net stop "CCEServer"(if present) - Reset NTFS ACLs on the WinCC installation:
icacls "C:\Program Files\Siemens" /reset /T /C
icacls "C:\Program Files\Siemens\WinCC" /grant "BUILTIN\Administrators":(OI)(CI)F /T /C - Reset ACLs on the WinCC project root:
icacls "D:\Projects\<ProjectName>" /reset /T /C
icacls "D:\Projects\<ProjectName>" /grant "BUILTIN\Administrators":(OI)(CI)F /T /C - Strip any explicit deny lines:
icacls "D:\Projects\<ProjectName>" /remove:g *S-1-1-0 /T(removes deny for Everyone if previously applied) - If the project lives on a UNC path, copy it locally, fix permissions, run the script, then push the cleaned copy back with
robocopy /MIR /R:1 /W:1 /NPand reapply share-level Change only to the operators group.
7. Resolution Path C — Orderly Reset of SQL, Alarm Logging, and Runtime
This is the canonical "Stop SQL server → Delete building files → Restart SQL → Start Runtime" procedure referenced in the original report. Expand it for forensic clarity:
- Exit WinCC Runtime. Use Shift+Ctrl at WinCC startup to prevent auto-activation.
- Stop the WinCC-bound SQL instance:
net stop "MSSQL$WINCC"(default instance name; check withsc queryex type= service state= all | findstr /i SQL). - Verify no WinCC process still holds the database files:
handle.exe -a "D:\Projects\<ProjectName>\*.mdf"(Sysinternals). - Delete the project building / compile cache:
del /s /q /f "D:\Projects\<ProjectName>\GraCS\*_*.pdl"
del /s /q /f "D:\Projects\<ProjectName>\Library\*.pdl"
Leave the source.pdlfiles whose names contain no underscore-language suffix; they are the originals. - Compact and reattach the project MDF/LDF:
sqlcmd -S .\WINCC -E -Q "DBCC CHECKDB('<ProjectName>_R') WITH NO_INFOMSGS;" - Start SQL:
net start "MSSQL$WINCC" - Open WinCC Explorer, allow Alarm Logging to rebuild past 46% (allow 3–6 minutes on a 2003-class server).
- Activate Runtime. Confirm with:
tasklist /fi "imagename eq pdlrt.exe"— the Runtime process must be present.
8. Project Recovery Key Combinations
| Hotkey | Effect | Use Case |
|---|---|---|
| Shift + Alt | Prevents WinCC Explorer from opening the last project | Use to manually recover from a corrupted or auto-activating project |
| Shift + Ctrl | Prevents Runtime auto-activation of the last activated project | Use when WinCC opens the project but must not enter Runtime |
| Ctrl + F8 (in Alarm Logging CS) | Disables / re-enables a stuck archive segment | Use when Alarm Logging freezes at 46% to clear the active segment |
Shift during WinCC.exe startup |
Starts WinCC in "reset" mode (no project) | Use before running Reset_WinCC.vbs to avoid recursive activation |
9. Hardening Reset_WinCC.vbs to Avoid Line 51 Failure
If operations still requires the script, wrap it with a guarded entry point that fails fast on permission problems instead of aborting mid-loop. The original Line 51 typically issues objProcess.Terminate(); replace it with an explicit elevation check.
' Header for hardened reset_wincc.vbs
Option Explicit
Const PROC_CCE = "CCEServer.exe"
Const PROC_DIST = "CCDistManager.exe"
Const PROC_PDLRT = "pdlrt.exe"
Sub EnsureAdmin()
Dim wmi, col, it, isAdmin
Set wmi = GetObject("winmgmts:\\.\root\cimv2")
Set col = wmi.ExecQuery _
("SELECT * FROM Win32_Group WHERE Name = 'Administrators'")
For Each it In col
Dim members
Set members = wmi.ExecQuery _
("ASSOCIATORS OF {Win32_Group.Name='" & it.Name & _
",Domain='" & it.Domain & "'} " & _
"WHERE ResultClass = Win32_UserAccount")
Dim u
For Each u In members
If LCase(u.Name) = LCase(CreateObject("WScript.Network").UserName) Then
Exit Sub
End If
Next
Next
MsgBox "Reset_WinCC.vbs must be executed as a member of local Administrators.", _
vbCritical, "WinCC Reset"
WScript.Quit 1
End Sub
Sub SafeKill(procName)
Dim svc, col, p, rc
Set svc = GetObject("winmgmts:\\.\root\cimv2")
Set col = svc.ExecQuery("SELECT * FROM Win32_Process WHERE Name='" & _
procName & "'")
For Each p In col
rc = p.Terminate()
If rc <> 0 Then
Err.Raise vbObjectError + 1000, "SafeKill", _
"Access Denied while terminating " & procName & _
" (rc=" & rc & ")"
End If
Next
End Sub
EnsureAdmin()
SafeKill PROC_CCE
SafeKill PROC_DIST
SafeKill PROC_PDLRT
Save the wrapper at the same path as the original and run it via cscript.exe — the Line 51 Access Denied dialog is replaced with a meaningful error code (HRESULT).
10. Diagnostic Decision Matrix
| Symptom | Likely Cause | First Action |
|---|---|---|
| Line 51 Access Denied, running under local admin | Project on UNC or denied ACE | Run Path B ACL repair |
| Alarm Logging stalls at 46% on one OPC node only | Stale process holding database | Run Path C SQL/Alarm reset |
| Line 51 error on every launch, even as Administrator | WinCC services still running under SYSTEM | Stop services in Path B step 1, then rerun |
| Script completes but Runtime still does not start | Corrupt building files only | Delete *_*.pdl files, allow rebuild |
| Line 51 error after Windows patch day | Group Policy pushed new deny ACE on Program Files | Compare icacls baseline, escalate to AD admin |
11. State Machine — Runtime Recovery Flow
12. Verification
- Open WinCC Explorer with Shift+Alt held — confirm it opens without auto-loading the last project.
- Open the project manually, then hold Shift+Ctrl during activation — confirm Runtime does not start automatically.
- Re-run
cscript.exe "C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs"— the script must complete without dialogs and exit with code0. - Confirm no orphan processes remain:
tasklist /fi "imagename eq cceserver.exe" /fi "imagename eq ccdistmanager.exe"— both must be absent. - Activate Runtime. Alarm Logging should pass 46% in < 5 minutes; the transition is logged in
WinCC\Diagnosis\AlarmLogging.logas Archive segment 0 opened. - Toggle one digital tag from the PLC; verify the value appears in the WinCC Tag Logging and in the active graphic.
- For multi-node OPC: repeat the procedure on the second node, then issue
net stop "WinCC" && net start "WinCC"on the primary to force a re-handshake.
13. Preventive Best Practices
- Create a dedicated local account
winccsvcthat is a member of Administrators; assign it as the service logon for all WinCC services viaservices.msc → Log On tab. This removes the dependency on whoever is interactively logged in. - Schedule
Reset_WinCC.vbsas a daily 03:00 task with/SYSTEMcredentials; the task can be triggered by a heartbeat from the SCADA "watchdog" tag. - Move projects off UNC paths onto a local NTFS folder; UNC ACLs are evaluated against the share, not the local file, and frequently produce "Access Denied" on
Terminate(). - Run
icacls <projectroot> /save acl.txt /Tas a baseline; restore withicacls /restore acl.txtif a GPO corrupts permissions. - Disable the Fast User Switching feature on Windows XP SP3; switching users mid-Reset is a known cause of Access Denied on file delete.
14. Related WinCC Symptoms and Cross-Reference
| Symptom | Shared Root Cause | Article Cross-Reference |
|---|---|---|
| Alarm Logging stuck at 46% | SQL Server / archive lock | Path C in this article |
| WinCC opens but no graphics | Corrupt GraCS\*_*.pdl
|
Step 4 in Path C |
| OPC partner shows "Server not found" | CCDistManager terminated by Reset | Restart CCDistManager after Reset |
| Runtime crashes with "License not found" | License service terminated by Reset | Re-issue license; do not run Reset during plant production |
15. Frequently Asked Questions
What exactly does Line 51 of Reset_WinCC.vbs do?
Line 51 of the OEM Reset_WinCC.vbs issues a WMI Win32_Process.Terminate() against CCEServer.exe (or the equivalent objShell.Run). When the calling token cannot debug the target process — typically because the process runs under a different user, has been protected by an NTFS deny ACE, or is a service under SYSTEM — the WMI call returns HRESULT 0x80070005 (Access Denied) and the VBScript runtime surfaces it as the Line 51 dialog.
Why does Alarm Logging freeze at 46% on only one of two OPC nodes?
Each node hosts its own SQL Server instance. A process-level lock on the project database is held by the orphaned CCEServer.exe from a previous abnormal termination on that node only. Apply the Path C sequence locally on the affected node; do not stop the working node's SQL because OPC redundancy is broken during that window.
Is it safe to run Reset_WinCC.vbs during a live plant?
No. Reset_WinCC.vbs terminates CCEServer.exe, CCDistManager.exe, pdlrt.exe, and the WinCC-tag-related services without flushing tag archives or alarm queues. Use it only in maintenance windows. For controlled shutdown prefer net stop "WinCC" followed by net stop "CCArchiveManager".
Why does Shift+Alt help recover a stuck WinCC project?
Shift+Alt suppresses the auto-load of the last opened project during WinCC startup, so the operator can open the project manually in Configuration mode without Runtime re-activating the corrupted state. It is documented in the WinCC V7.0 "Working with WinCC" chapter of the WinCC system manual.
How do I remove the "Access Denied" on the WinCC Program Files folder?
Run icacls "C:\Program Files\Siemens\WinCC\bin" /reset /T /C from an elevated command prompt, then re-grant Administrators full control with icacls ... /grant "BUILTIN\Administrators":(OI)(CI)F /T /C. If a GPO keeps reapplying deny entries, set the ACL in Enforce mode via sc sdset for the WinCC service, or move the project to a directory that the GPO does not target.