Windows

Where Are Windows Services Definitions Stored?

Windows keeps service definitions in the registry under Services with binaries on disk. Key layout and admin tools.

Last updated

Windows defines every service in the registry under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, one subkey per service with ImagePath, Start type, account and dependencies. The actual executables live wherever ImagePath points, commonly system32 or program folders. EventLog and performance subkeys hang nearby.

The registry is storage, not interface: services.msc, sc.exe and PowerShell cmdlets are the editors, and hand-crafted keys miss required values. CurrentControlSet itself is a pointer to one ControlSet00x copy, which is why offline hives look different. Deleting a service marks it for removal at reboot rather than vanishing instantly. Same layout since NT days.

Where Windows services stores this, by platform

Windows
HKLM\SYSTEM\CurrentControlSet\Services

One subkey per service with ImagePath, Start type, account and DependOnService. Manage via services.msc, sc.exe or PowerShell; never hand-craft keys. CurrentControlSet points at the live ControlSet copy. Deletions pend until reboot. Binaries live at their ImagePath locations, not in the registry.

Frequently asked questions

why does my windows service fail to start

Check the ImagePath value in the service's registry key first. Most failures are a moved or deleted executable, a wrong service account password, or a missing dependency. services.msc shows the error code; the registry shows what the service actually tried to run. Fix the path or account, not the symptom.

can i create a service in regedit

Use sc.exe or PowerShell, not regedit. sc create and Set-Service write the keys with correct types and security; hand-made keys miss required values and permissions. The registry is the storage, not the interface. Even Microsoft's own tools go through the service control manager API.

why is my deleted service still listed

The service is marked for deletion and vanishes on next reboot, or when all handles close. Close services.msc and any querying tools, then reboot if it persists. The registry key lingers in the marked state until then. Orphaned EventLog subkeys sometimes remain afterward and are harmless.

Notice an outdated path? Let us know.