Windows Repair Intelligence™ Report

0XC0000428

The hash for image %hs cannot be found in the system catalogs. The image is likely corrupt or the victim of tampering

Home / Error Codes / Applications and processes / 0XC0000428

Microsoft defines 0XC0000428 as STATUS_INVALID_IMAGE_HASH: The hash for image %hs cannot be found in the system catalogs. The image is likely corrupt or the victim of tampering.

SeverityMediumSystemsWindows 10 / 11SymbolSTATUS_INVALID_IMAGE_HASHUpdatedSep 1, 2026

Overview

0XC0000428 is the NTSTATUS representation of STATUS_INVALID_IMAGE_HASH. The code identifies the documented condition, while the calling program, timestamp, logs, and repeatable operation identify the responsible component.

Common causes

  • The affected operation returned the official STATUS_INVALID_IMAGE_HASH condition
  • The calling program encountered the documented result: The hash for image %hs cannot be found in the system catalogs. The image is likely corrupt or the victim of tampering.
  • A configuration, resource, or dependency used by the applications and processes operation did not meet its requirements
  • A recent program, service, installer, or system change altered the context in which 0XC0000428 occurs

Symptoms

  • Confirm which operation returned 0XC0000428
  • Match 0XC0000428 to events from the same timestamp
  • Retest once and preserve any changed result

Prevention

  • Preserve Application and System events that accompany 0XC0000428
  • Use supported installers and configuration methods for the affected applications and processes workflow
  • Document changes so the operating context for STATUS_INVALID_IMAGE_HASH can be reconstructed

0XC0000428 diagnostic evidence

Official-definition grounded

Use the code identity and the affected operation together. The same numeric result can appear in different workflows, so logs and symptoms determine the safest repair branch.

Hexadecimal0XC0000428
Unsigned decimal3221226536
SymbolSTATUS_INVALID_IMAGE_HASH
Error familyApplications and processes
Severity bitFailure
Evidence sourceMicrosoft Open Specifications [MS-ERREF] NTSTATUS Values
1Confirm the operationConfirm which operation returned 0XC0000428
2Collect matching evidenceMatch 0XC0000428 to events from the same timestamp
3Retest the same actionRetest once and preserve any changed result

Definition source: Microsoft Open Specifications [MS-ERREF] NTSTATUS Values. This report preserves the official code identity and does not claim one universal cause.

How to troubleshoot error 0XC0000428

Use these Windows-native steps in order. Stop when Windows Update works again; advanced repair commands are not necessary on every PC.

1

Restart Windows and retry the update

Save your work, restart the PC, then open Settings > Windows Update and select Check for updates. A restart can release pending files without changing Windows configuration.

2

Run the Windows Update troubleshooter

Open Settings > System > Troubleshoot > Other troubleshooters. Locate Windows Update and select Run. Current Windows 11 versions may continue the diagnostic flow in Get Help.

3

Repair Windows components when indicated

If troubleshooting still reports missing or damaged components, open Terminal as administrator, run DISM RestoreHealth, and then run System File Checker. Do not interrupt either scan.

Before advanced repair: Back up important files. Managed work or school PCs may use organization update policies, so contact the administrator before changing services or update components.

Official-source grounding

The error meaning is grounded in Microsoft Open Specifications [MS-ERREF] NTSTATUS Values. The visual sequence also follows Microsoft Support guidance for Windows Update troubleshooting and Microsoft DISM repair guidance. Causes and repair steps vary by system evidence; this report does not claim a universal success rate.

Frequently asked questions

What does 0XC0000428 mean?

Microsoft defines 0XC0000428 as STATUS_INVALID_IMAGE_HASH: The hash for image %hs cannot be found in the system catalogs. The image is likely corrupt or the victim of tampering. 0XC0000428 is the NTSTATUS representation of STATUS_INVALID_IMAGE_HASH. The code identifies the documented condition, while the calling program, timestamp, logs, and repeatable operation identify the responsible component.

Is 0XC0000428 always caused by the same problem?

No. The code identifies a failure condition, but the exact cause depends on the affected operation, Windows build, logs, and recent system changes.

Can Advanced System Repair help with 0XC0000428?

Advanced System Repair can scan for damaged Windows components and related system issues. No tool can guarantee one universal fix; preserve backups and match repair steps to the evidence on the affected PC.