Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0x80070002

0x80070002 and 0x80070003: update files missing from SoftwareDistribution

11 min read Updated October 4, 2026 Windows Update & Setup

Fix it now

0x80070002 is ERROR_FILE_NOT_FOUND and 0x80070003 is ERROR_PATH_NOT_FOUND: the update agent was told to use a file, went looking, and neither the file nor the folder above it was there. The download cache and the agent’s database have drifted apart, so the cure is to discard the cache and let Windows rebuild it.

Run these in an elevated Command Prompt, in order. All four services must be stopped before the renames

net stop wuauserv
net stop cryptSvc
net stop bits
net stop msiserver
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
ren C:\Windows\System32\catroot2 catroot2.old
net start wuauserv
net start cryptSvc
net start bits
net start msiserver
  1. Check for updates. The first scan takes considerably longer than usual because the database is being rebuilt from nothing; leave it running rather than cancelling and retrying.
  2. If a rename is refused, something is still holding the folder. Restart the machine and do the renames before anything else has started.
  3. For 0x80070003 specifically, Microsoft’s guidance is to open the newest %windir%\Logs\CBS\CBS.log and search for , error to find the invalid path, then match it to the timestamp.
  4. Once updates install successfully, delete the two renamed folders to reclaim the space.

Renaming SoftwareDistribution resets the update history shown in Settings. It does not uninstall anything: installed updates live in the component store, not in this folder.

If the scan completes and updates install, you are finished. If it fails the same way, the next section covers the four other reasons a path the database promised is not there.

Why it happens

SoftwareDistribution holds two things the update agent depends on. The Download folder holds payload the machine has fetched but not yet installed. The DataStore folder holds a database recording what the machine has been offered, what it has downloaded, where the files were put and what has already been installed. The two are supposed to agree with each other.

They stop agreeing for ordinary reasons. A disk cleanup deletes the payload but not the database entries pointing at it. A download is interrupted when the disk fills or the machine loses power. A reference image is captured with a populated store and then deployed to machines that inherit records of updates they never received. In each case the agent asks the file system for a path the database promised, and the file system says it is not there.

The two headline codes are plain Win32 errors: file not found and path not found. Microsoft’s guidance for 0x80070003 adds something useful, though, which is that the servicing stack could not access a specific path and the newest CBS.log holds the invalid path. That is worth reading before the reset, because a path that points somewhere impossible tells you more than a rebuilt cache does.

The data store codes that arrive alongside them are frequently misdescribed. 0x8024000D is WU_E_XML_MISSINGDATA: the agent could not find required information in the update’s XML data. 0x80248008 is WU_E_DS_MISSINGDATA, meaning the data store is missing required information or has a NULL in a table column that requires a non-null value; that is missing data, not missing structure, and the missing-structure code is a different one. 0x8024801C is WU_E_DS_RESETREQUIRED: the data store requires a session reset, so the agent must release the session and retry with a new one. That is a session reset, not proof that the on-disk cache has to be rebuilt.

The download cache and the data store have drifted apart

You have this one if Scans fail or downloads restart repeatedly, and there is no policy or network peculiarity to blame.

  1. Follow the rename procedure above, with all four services stopped first.
  2. Start the services and run a fresh scan.
  3. Allow the first scan to take considerably longer than normal.
  4. Delete the renamed folders once updates are installing again.

The machine points at an update server that is gone or wrong

You have this one if Only managed machines fail, and the policy branch names a server that has been decommissioned or renamed.

  1. Read WUServer and WUStatusServer under HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate.
  2. Correct them through the ‘Specify intranet Microsoft update service location’ policy under Computer Configuration – Administrative Templates – Windows Components – Windows Update, not by editing the registry, so the change survives the next refresh.
  3. Run gpupdate /force, restart the update service and rescan.
  4. If the machine should no longer be managed, remove the policy rather than pointing it at a dead server.

UseWUServer lives under the AU subkey of that same policy branch. It is read from the policy branch only; a value created under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate is never read by the update agent.

Cloned machines share one update client identity

You have this one if A fleet deployed from one image, where the update server only ever sees a handful of clients and the rest never appear.

  1. Stop the update service, then delete the four client identity values Microsoft names: PingID, AccountDomainSid, SusClientId and SusClientIDValidation, under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate.
  2. Start the service again and run wuauclt.exe /resetauthorization /detectnow.
  3. Wait ten to fifteen minutes, then check whether the client appears in the update server’s console.
  4. Fix the reference image so future deployments do not carry a populated store or an identifier.

The disk filled or the volume has errors

You have this one if Downloads fail part way through, and the system volume is nearly full or the event log records disk errors.

  1. Free space on the system volume and aim for a comfortable margin rather than the minimum.
  2. Run chkdsk C: /scan, which runs an online scan on an NTFS volume without a dismount.
  3. Repeat the cache reset once the volume is healthy.
  4. Replace failing storage before spending more time on updates.

The data store is damaged rather than merely inconsistent

You have this one if 0x80248008 or 0x8024801C appear alongside the file and path errors, and the reset alone does not help.

  1. Repeat the reset, this time confirming every listed service is genuinely stopped before renaming.
  2. If a rename is refused, restart and do it before anything else has started.
  3. Follow with DISM /Online /Cleanup-Image /RestoreHealth and sfc /scannow.
  4. Rescan and confirm the store rebuilds.

Full reference

What each code actually asserts

Code Published name Reading
0x80070002 ERROR_FILE_NOT_FOUND Decimal 2. The system cannot find the file specified
0x80070003 ERROR_PATH_NOT_FOUND Decimal 3. The system cannot find the path specified. Read the newest CBS.log for the invalid path
0x8024000D WU_E_XML_MISSINGDATA The agent could not find required information in the update’s XML data
0x80248008 WU_E_DS_MISSINGDATA The data store is missing required information, or has a NULL in a column that requires a non-null value
0x8024801C WU_E_DS_RESETREQUIRED The data store requires a session reset: release the session and retry with a new one

0x8024801C in particular is worth reading carefully. It asks for a session reset by the agent, which frequently happens without any intervention. Renaming SoftwareDistribution is a reasonable next step if the condition keeps recurring, but it is not what the code means, and treating the two as equivalent leads to resetting the cache on machines that did not need it.

The reset, and what it costs you

Folder What it holds What renaming it costs
C:\Windows\SoftwareDistribution\Download Payload fetched but not yet installed A repeat download of anything pending
C:\Windows\SoftwareDistribution\DataStore The agent’s database of what has been offered, downloaded and installed The update history shown in Settings, and a much slower first scan
C:\Windows\System32\catroot2 The signature catalogue cache Nothing you will notice; Windows rebuilds it

Nothing installed is affected and no installed update is removed. If you need the record of what is on the machine after a reset, Get-HotFix and the Installed Updates view in Control Panel both read from elsewhere and still have it.

The registry that decides where the client looks

Path Values What they do
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate WUServer, WUStatusServer The intranet update server the client scans against, and the one it reports to. Both are set by the ‘Specify intranet Microsoft update service location’ policy
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU UseWUServer REG_DWORD. 1 makes Automatic Updates use the intranet server rather than Windows Update
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate PingID, AccountDomainSid, SusClientId, SusClientIDValidation Client identity. Microsoft documents deleting these four to regenerate the identity of a cloned client

The policy values live under the Policies branch. Prefer changing the Group Policy object that sets them: a local edit that policy overwrites an hour later wastes an afternoon. Export the branch before changing anything.

Resetting a cloned client’s identity

net stop wuauserv
reg Delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v PingID /f
reg Delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v AccountDomainSid /f
reg Delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /f
reg Delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientIDValidation /f
net start wuauserv
wuauclt.exe /resetauthorization /detectnow

This is Microsoft’s published sequence for a WSUS client that will not register, and it is the right answer for an estate built from an image captured after the source machine had already talked to an update server. Give it ten to fifteen minutes before you judge whether the client has appeared. Fix the image as well, or you will be doing this again after the next deployment.

When the reset does not help

  • Read %windir%\Logs\CBS\CBS.log for the invalid path. If it points somewhere that could never exist, the problem is what wrote it rather than the cache.
  • Check whether a disk cleanup script or a third-party optimiser runs on a schedule. Recurring drift usually has a scheduled cause.
  • Check free space. The data store needs room for its transaction logs, and a nearly full volume produces exactly this behaviour.
  • Confirm no backup or endpoint protection product is holding files under SoftwareDistribution open, and exclude the folder from real-time scanning if the product supports it.
  • If the same machine needs this three times, stop resetting and find what is writing into the folder.

Every code this article covers

Code What it points at Source
0x80070002 ERROR_FILE_NOT_FOUND, decimal 2: the system cannot find the file specified Microsoft Learn
0x80070003 ERROR_PATH_NOT_FOUND, decimal 3: the system cannot find the path specified. Microsoft’s guidance is to read the newest CBS.log for the invalid path Microsoft Learn
0x8024000D WU_E_XML_MISSINGDATA: the Windows Update Agent could not find required information in the update’s XML data Microsoft Learn
0x80248008 WU_E_DS_MISSINGDATA: the data store is missing required information, or has a NULL in a table column that requires a non-null value Microsoft Learn
0x8024801C WU_E_DS_RESETREQUIRED: the data store requires a session reset; the agent must release the session and retry with a new one Microsoft Learn

Confirm the fix worked

  1. Confirm SoftwareDistribution and catroot2 have been recreated after the services restarted.
  2. Run a check for updates and confirm the scan completes rather than failing immediately.
  3. Install the updates it offers and confirm they complete and survive a restart.
  4. Confirm Update history is repopulating with the new installs.
  5. On a managed client, confirm it appears in the update server’s console with a current last-contact time.

Questions people ask about this

Will renaming SoftwareDistribution remove my installed updates?

No. Installed updates live in the component store, not in this folder. What you lose is the download cache and the list shown in the history view, both of which rebuild. Nothing is uninstalled, and Get-HotFix still shows what is on the machine.

Does 0x8024801C mean I have to rebuild the cache?

No. It is WU_E_DS_RESETREQUIRED, which asks the agent to release its session and retry with a new one. That often happens without intervention. Renaming SoftwareDistribution is a reasonable next step if it recurs, but it is not what the code means.

Why is the first scan afterwards so slow?

Because the agent is rebuilding its database from scratch and re-evaluating every update it is offered against what is installed. On a machine that is well behind, that takes a long time. Leave it running rather than cancelling and retrying.

Do I have to rename catroot2 as well?

Not always, but it is worth doing when signature or catalogue errors appear alongside the file-not-found ones. Renaming it forces Windows to rebuild the catalogue cache, which rules out a related class of failures in one go.

Does this cost anything?

No. Every step uses commands already on the machine and none of these codes relates to licensing or activation. If a search result tells you this error means your Windows is not genuine, it is wrong.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 0x80070017 and 0x8007045D: install media read errors during Windows Setup License Error 0xC1900101 – 0x4000D and 0x2000C: the upgrade fails applying the image or migrating data Free Fix 0xC1800118: WSUS is holding feature update content it has no key to decrypt Free Fix 0x80240034 and 0x80240438: the download fails, or an update endpoint is unreachable
โ† Back to Knowledge Base