Reset_WinCC.vbs Access Denied Line 51: WinCC V7.0 Troubleshooting

David Krause11 min read
SiemensTroubleshootingWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

Engineers running Siemens WinCC V7.0 on legacy Microsoft Windows XP SP3 or Windows Server 2003 R2 workstations occasionally trigger the OEM reset utility Reset_WinCC.vbs to forcibly terminate stuck WinCC processes before relaunching Runtime. When the script is executed, the Windows Script Host aborts with the following dialog instead of performing the cleanup:

Microsoft VBScript Runtime Error
C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs
Access Denied
Error: Line 51

Symptom chain observed in the field:

  • WinCC Explorer refuses to enter Runtime, or Runtime activation stalls at 46% in Alarm Logging.
  • Manually launching Reset_WinCC.vbs via Windows Explorer or Task Scheduler produces the Line 51 Access Denied termination.
  • Subsequent WinCC restart either opens a previously activated project or fails to start Runtime at all.
  • On multi-node OPC server pairs, one node recovers while the second node remains stuck in Alarm Logging initialization.

Because Reset_WinCC.vbs terminates background processes (CCEServer, CCDistManager, WinCC SQL Server wrapper) without orderly shutdown, the error must be resolved before the script can be considered a safe maintenance tool.

2. Environment and Affected Versions

Component Version Confirmed in Source Notes
Siemens WinCC V7.0 (incl. SP3/SP4 updates) Same script shipped through V7.0 + Upd4; older V6.x has a different reset utility
Operating System Windows XP SP3, Windows Server 2003 R2 Both 32-bit; same UAC/IL behavior because UAC is not active on XP/2003
Script Engine Windows Script Host 5.7 (XP) / 5.8 (Server 2003 R2) VBScript runtime delivers Line N errors in this format
Database Microsoft SQL Server 2005 Express bundled with WinCC Must be stopped before deleting building files
OPC Layer SIMATIC NET OPC / WinCC OPC Failure in one node suggests process-level lock

Reference: WinCC V7.0 System Manual (Siemens Support entry ID 38352278) and the public Siemens SIMATIC WinCC product page.

Critical: Windows XP SP3 and Windows Server 2003 R2 are out of mainstream support. If the affected HMI server is reachable, plan a migration to a supported Windows / WinCC version. The procedures below remain valid for the affected release but should be considered interim.

3. Root Cause Analysis

The Access Denied at Line 51 of Reset_WinCC.vbs is produced by a WshShell.Run or Terminate call attempting to kill a WinCC process owned by another user context or protected by NTFS ACLs on the executable / project directory. Three concurrent causes are typical:

  1. Process held by elevated context. On Windows XP SP3, UAC is absent, but the Reset_WinCC.vbs is frequently double-clicked from a user account that is not in the local Administrators group, or the project path is opened from a network share. The script then cannot call WMI Win32_Process.Terminate against CCEServer.exe running as the interactive logon administrator.
  2. NTFS deny ACE on the project or bin directory. WinCC stores the building (rebuild) files in <ProjectPath>\GraCS\<name>_<lang>.pdl and <ProjectPath>\Library\*.pdl. An explicit deny on the Users principal on the project root causes the cleanup portion of the script to throw on the file delete attempt.
  3. SQL Server or alarm-logging service is still holding the project database. Alarm Logging freezes at 46% because the WinCC Archive Manager cannot acquire an exclusive lock on the corresponding MDF/LDF files. Reset_WinCC.vbs at Line 51 attempts to stop a service, the SCM call is rejected because the calling token lacks SE_DEBUG_NAME / SeLockMemoryPrivilege, and the VBScript runtime maps this to Access Denied.

Reference behavior: Microsoft Q&A — VBS script opening error documents the identical Access Denied dialog when a VBS in the Startup folder cannot enumerate the calling shell namespace.

4. Pre-Diagnostic Checklist

Before altering the script or permissions, capture the operational state of the station:

:: From an elevated command prompt
tasklist /v /fi "imagename eq cceserver.exe"
tasklist /v /fi "imagename eq ccdistmanager.exe"
tasklist /v /fi "imagename eq wincc.exe"
tasklist /v /fi "imagename eq sqlservr.exe"
sc query "WinCC"  
sc query "CCArchiveManager"
whoami /groups | findstr /i "S-1-5-32-544"
icacls "C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs"
icacls "D:\Projects\<ProjectName>" /T | findstr /i "deny"

Record:

  • Owning user of CCEServer.exe — if it is SYSTEM or another interactive user, the running context is the cause.
  • Any explicit deny lines on the project or bin directory.
  • Service state of the WinCC SQL wrapper.

5. Resolution Path A — Privileged Execution

Use this path when the script simply needs to be re-launched under the correct security context.

  1. Log out of WinCC Runtime. Press Shift+Alt while WinCC Explorer opens so that the last activated project does not start automatically.
  2. Open a command prompt: Start > Run > cmd.exe — not from inside a WinCC dialog.
  3. Verify the local Administrators group membership: net localgroup Administrators. The active user must be listed.
  4. Launch the script with explicit credentials through runas when a domain user policy restricts local admin caching: runas /user:<HOSTNAME>\Administrator "cscript.exe \"C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs\"".
  5. If a domain policy disables runas, schedule the script through at as SYSTEM: at 00:01 /interactive cmd /c cscript.exe "C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs" — requires Schedule service running and the operator to be a member of the local Power Users or higher.
Engineer field note: On Windows Server 2003 R2, the Interactive flag of at requires the console session to be at the physical keyboard, not over RDP, otherwise the script will run but its VBS dialogs are never visible. Use a scheduled task in the Control Panel — Scheduled Tasks GUI when the console is at the SCADA node.

6. Resolution Path B — Repair Project / Bin NTFS ACLs

Use this path when icacls above shows explicit deny entries or the project resides on a redirected/UNC path.

  1. Stop all WinCC services in order:
    net stop "WinCC"
    net stop "CCArchiveManager"
    net stop "CCDistManager"
    net stop "CCEServer" (if present)
  2. Reset NTFS ACLs on the WinCC installation:
    icacls "C:\Program Files\Siemens" /reset /T /C
    icacls "C:\Program Files\Siemens\WinCC" /grant "BUILTIN\Administrators":(OI)(CI)F /T /C
  3. Reset ACLs on the WinCC project root:
    icacls "D:\Projects\<ProjectName>" /reset /T /C
    icacls "D:\Projects\<ProjectName>" /grant "BUILTIN\Administrators":(OI)(CI)F /T /C
  4. Strip any explicit deny lines:
    icacls "D:\Projects\<ProjectName>" /remove:g *S-1-1-0 /T (removes deny for Everyone if previously applied)
  5. If the project lives on a UNC path, copy it locally, fix permissions, run the script, then push the cleaned copy back with robocopy /MIR /R:1 /W:1 /NP and reapply share-level Change only to the operators group.

7. Resolution Path C — Orderly Reset of SQL, Alarm Logging, and Runtime

This is the canonical "Stop SQL server → Delete building files → Restart SQL → Start Runtime" procedure referenced in the original report. Expand it for forensic clarity:

  1. Exit WinCC Runtime. Use Shift+Ctrl at WinCC startup to prevent auto-activation.
  2. Stop the WinCC-bound SQL instance:
    net stop "MSSQL$WINCC" (default instance name; check with sc queryex type= service state= all | findstr /i SQL).
  3. Verify no WinCC process still holds the database files:
    handle.exe -a "D:\Projects\<ProjectName>\*.mdf" (Sysinternals).
  4. Delete the project building / compile cache:
    del /s /q /f "D:\Projects\<ProjectName>\GraCS\*_*.pdl"
    del /s /q /f "D:\Projects\<ProjectName>\Library\*.pdl"
    Leave the source .pdl files whose names contain no underscore-language suffix; they are the originals.
  5. Compact and reattach the project MDF/LDF:
    sqlcmd -S .\WINCC -E -Q "DBCC CHECKDB('<ProjectName>_R') WITH NO_INFOMSGS;"
  6. Start SQL: net start "MSSQL$WINCC"
  7. Open WinCC Explorer, allow Alarm Logging to rebuild past 46% (allow 3–6 minutes on a 2003-class server).
  8. Activate Runtime. Confirm with: tasklist /fi "imagename eq pdlrt.exe" — the Runtime process must be present.

8. Project Recovery Key Combinations

Hotkey Effect Use Case
Shift + Alt Prevents WinCC Explorer from opening the last project Use to manually recover from a corrupted or auto-activating project
Shift + Ctrl Prevents Runtime auto-activation of the last activated project Use when WinCC opens the project but must not enter Runtime
Ctrl + F8 (in Alarm Logging CS) Disables / re-enables a stuck archive segment Use when Alarm Logging freezes at 46% to clear the active segment
Shift during WinCC.exe startup Starts WinCC in "reset" mode (no project) Use before running Reset_WinCC.vbs to avoid recursive activation

9. Hardening Reset_WinCC.vbs to Avoid Line 51 Failure

If operations still requires the script, wrap it with a guarded entry point that fails fast on permission problems instead of aborting mid-loop. The original Line 51 typically issues objProcess.Terminate(); replace it with an explicit elevation check.

' Header for hardened reset_wincc.vbs
Option Explicit

Const PROC_CCE   = "CCEServer.exe"
Const PROC_DIST  = "CCDistManager.exe"
Const PROC_PDLRT = "pdlrt.exe"

Sub EnsureAdmin()
    Dim wmi, col, it, isAdmin
    Set wmi = GetObject("winmgmts:\\.\root\cimv2")
    Set col = wmi.ExecQuery _
        ("SELECT * FROM Win32_Group WHERE Name = 'Administrators'")
    For Each it In col
        Dim members
        Set members = wmi.ExecQuery _
            ("ASSOCIATORS OF {Win32_Group.Name='" & it.Name & _
            ",Domain='" & it.Domain & "'} " & _
            "WHERE ResultClass = Win32_UserAccount")
        Dim u
        For Each u In members
            If LCase(u.Name) = LCase(CreateObject("WScript.Network").UserName) Then
                Exit Sub
            End If
        Next
    Next
    MsgBox "Reset_WinCC.vbs must be executed as a member of local Administrators.", _
        vbCritical, "WinCC Reset"
    WScript.Quit 1
End Sub

Sub SafeKill(procName)
    Dim svc, col, p, rc
    Set svc = GetObject("winmgmts:\\.\root\cimv2")
    Set col = svc.ExecQuery("SELECT * FROM Win32_Process WHERE Name='" & _
        procName & "'")
    For Each p In col
        rc = p.Terminate()
        If rc <> 0 Then
            Err.Raise vbObjectError + 1000, "SafeKill", _
                "Access Denied while terminating " & procName & _
                " (rc=" & rc & ")"
        End If
    Next
End Sub

EnsureAdmin()
SafeKill PROC_CCE
SafeKill PROC_DIST
SafeKill PROC_PDLRT

Save the wrapper at the same path as the original and run it via cscript.exe — the Line 51 Access Denied dialog is replaced with a meaningful error code (HRESULT).

10. Diagnostic Decision Matrix

Symptom Likely Cause First Action
Line 51 Access Denied, running under local admin Project on UNC or denied ACE Run Path B ACL repair
Alarm Logging stalls at 46% on one OPC node only Stale process holding database Run Path C SQL/Alarm reset
Line 51 error on every launch, even as Administrator WinCC services still running under SYSTEM Stop services in Path B step 1, then rerun
Script completes but Runtime still does not start Corrupt building files only Delete *_*.pdl files, allow rebuild
Line 51 error after Windows patch day Group Policy pushed new deny ACE on Program Files Compare icacls baseline, escalate to AD admin

11. State Machine — Runtime Recovery Flow

WinCC Startup Shift+Alt held? No Project Last Project Run Reset_WinCC.vbs Line 51 Denied? Path A/B/C SQL reset / Clean Activate Runtime

12. Verification

  1. Open WinCC Explorer with Shift+Alt held — confirm it opens without auto-loading the last project.
  2. Open the project manually, then hold Shift+Ctrl during activation — confirm Runtime does not start automatically.
  3. Re-run cscript.exe "C:\Program Files\Siemens\WinCC\bin\reset_wincc.vbs" — the script must complete without dialogs and exit with code 0.
  4. Confirm no orphan processes remain: tasklist /fi "imagename eq cceserver.exe" /fi "imagename eq ccdistmanager.exe" — both must be absent.
  5. Activate Runtime. Alarm Logging should pass 46% in < 5 minutes; the transition is logged in WinCC\Diagnosis\AlarmLogging.log as Archive segment 0 opened.
  6. Toggle one digital tag from the PLC; verify the value appears in the WinCC Tag Logging and in the active graphic.
  7. For multi-node OPC: repeat the procedure on the second node, then issue net stop "WinCC" && net start "WinCC" on the primary to force a re-handshake.

13. Preventive Best Practices

  • Create a dedicated local account winccsvc that is a member of Administrators; assign it as the service logon for all WinCC services via services.msc → Log On tab. This removes the dependency on whoever is interactively logged in.
  • Schedule Reset_WinCC.vbs as a daily 03:00 task with /SYSTEM credentials; the task can be triggered by a heartbeat from the SCADA "watchdog" tag.
  • Move projects off UNC paths onto a local NTFS folder; UNC ACLs are evaluated against the share, not the local file, and frequently produce "Access Denied" on Terminate().
  • Run icacls <projectroot> /save acl.txt /T as a baseline; restore with icacls /restore acl.txt if a GPO corrupts permissions.
  • Disable the Fast User Switching feature on Windows XP SP3; switching users mid-Reset is a known cause of Access Denied on file delete.

14. Related WinCC Symptoms and Cross-Reference

Symptom Shared Root Cause Article Cross-Reference
Alarm Logging stuck at 46% SQL Server / archive lock Path C in this article
WinCC opens but no graphics Corrupt GraCS\*_*.pdl Step 4 in Path C
OPC partner shows "Server not found" CCDistManager terminated by Reset Restart CCDistManager after Reset
Runtime crashes with "License not found" License service terminated by Reset Re-issue license; do not run Reset during plant production

15. Frequently Asked Questions

What exactly does Line 51 of Reset_WinCC.vbs do?

Line 51 of the OEM Reset_WinCC.vbs issues a WMI Win32_Process.Terminate() against CCEServer.exe (or the equivalent objShell.Run). When the calling token cannot debug the target process — typically because the process runs under a different user, has been protected by an NTFS deny ACE, or is a service under SYSTEM — the WMI call returns HRESULT 0x80070005 (Access Denied) and the VBScript runtime surfaces it as the Line 51 dialog.

Why does Alarm Logging freeze at 46% on only one of two OPC nodes?

Each node hosts its own SQL Server instance. A process-level lock on the project database is held by the orphaned CCEServer.exe from a previous abnormal termination on that node only. Apply the Path C sequence locally on the affected node; do not stop the working node's SQL because OPC redundancy is broken during that window.

Is it safe to run Reset_WinCC.vbs during a live plant?

No. Reset_WinCC.vbs terminates CCEServer.exe, CCDistManager.exe, pdlrt.exe, and the WinCC-tag-related services without flushing tag archives or alarm queues. Use it only in maintenance windows. For controlled shutdown prefer net stop "WinCC" followed by net stop "CCArchiveManager".

Why does Shift+Alt help recover a stuck WinCC project?

Shift+Alt suppresses the auto-load of the last opened project during WinCC startup, so the operator can open the project manually in Configuration mode without Runtime re-activating the corrupted state. It is documented in the WinCC V7.0 "Working with WinCC" chapter of the WinCC system manual.

How do I remove the "Access Denied" on the WinCC Program Files folder?

Run icacls "C:\Program Files\Siemens\WinCC\bin" /reset /T /C from an elevated command prompt, then re-grant Administrators full control with icacls ... /grant "BUILTIN\Administrators":(OI)(CI)F /T /C. If a GPO keeps reapplying deny entries, set the ACL in Enforce mode via sc sdset for the WinCC service, or move the project to a directory that the GPO does not target.

Back to blog