| Login

Search this Blog


Links I like to keep around




Here are the most recent postings to this blog. Use the archive calendar or search to find other entries.
Jul26

Written by:R Teachout
7/26/2007 3:20 PM

A perfect use of this is to remove a service left over rootkitreveler or a psexec service like ASHDBDK linked to a non-existant temp file in the users temp directory. (sysinternals services)

Open a command shell (Start->Run->CMD or Start->Programs->Accessories->Command Prompt), then for each service entry, type:

SC DELETE

e.g. SC DELETE MQHIG

You can also use SC \\SERVER DELETE MQHIG to remove from a remote machine (As long as your authentication passes)

This exists on XP/2003 + (not on 2000, but you CAN remote remove from a 2000 machine if you run SC on an XP machine, etc.)

(Note: SC should be used with caution - it can remove any service!!!)

Here is the SC /? results for reference

DESCRIPTION:
        SC is a command line program used for communicating with the
        NT Service Controller and services.
USAGE:
        sc [command] [service name] ...

        The option has the form "\\ServerName"
        Further help on commands can be obtained by typing: "sc [command]"
        Commands:
          query-----------Queries the status for a service, or
                          enumerates the status for types of services.
          queryex---------Queries the extended status for a service, or
                          enumerates the status for types of services.
          start-----------Starts a service.
          pause-----------Sends a PAUSE control request to a service.
          interrogate-----Sends an INTERROGATE control request to a service.
          continue--------Sends a CONTINUE control request to a service.
          stop------------Sends a STOP request to a service.
          config----------Changes the configuration of a service (persistant).
          description-----Changes the description of a service.
          failure---------Changes the actions taken by a service upon failure.
          qc--------------Queries the configuration information for a service.
          qdescription----Queries the description for a service.
          qfailure--------Queries the actions taken by a service upon failure.
          delete----------Deletes a service (from the registry).
          create----------Creates a service. (adds it to the registry).
          control---------Sends a control to a service.
          sdshow----------Displays a service's security descriptor.
          sdset-----------Sets a service's security descriptor.
          GetDisplayName--Gets the DisplayName for a service.
          GetKeyName------Gets the ServiceKeyName for a service.
          EnumDepend------Enumerates Service Dependencies.

        The following commands don't require a service name:
        sc
          boot------------(ok | bad) Indicates whether the last boot should
                          be saved as the last-known-good boot configuration
          Lock------------Locks the Service Database
          QueryLock-------Queries the LockStatus for the SCManager Database
EXAMPLE:
        sc start MyService

Tags:

Your name:
Title:
Comment:
Security Code
Enter the code shown above in the box below
Add Comment   Cancel  

In an open world, who needs Windows or Gates
-Unknown

Inspired by Nina