Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Usually, no. dxgiadaptercache.exe is normally a Microsoft Windows/DirectX component at C:WindowsSystem32dxgiadaptercache.exe, commonly launched by MicrosoftWindowsDirectXDXGIAdapterCache. The filename alone is not proof of safety: malware can copy the name or forge the task. Verify the exact path, Microsoft signature, task action and file hash before deciding whether to remove anything.

What DXGIAdapterCache is

DXGI (DirectX Graphics Infrastructure) manages parts of Windows graphics hardware and software. DXGIAdapterCache is a background Windows component, not a program you normally open yourself. File metadata for one Windows 11-era sample identifies the product as “DXGI Adapter Cache,” company “Microsoft Corporation,” internal name DXGIAdapterCache.exe, version 10.0.22621.608; versions vary by Windows release, language edition and servicing updates. See the sample metadata at Hybrid Analysis.

Windows malware-removal logs repeatedly show the expected executable under System32, including examples identifying Microsoft attribution (BleepingComputer log).

Expected file and scheduled-task locations

Item Normal-looking value Why it matters
Executable C:WindowsSystem32dxgiadaptercache.exe The Windows system directory is the expected location; a copy elsewhere requires investigation.
Task MicrosoftWindowsDirectXDXGIAdapterCache This is the commonly documented DirectX task path (example log).
Task action The same System32 executable, without obfuscated scripts or unrelated arguments A familiar task name can be forged; its action is decisive.

Related DirectX tasks, such as DirectXDatabaseUpdater, may appear nearby in FRST or Autoruns output (recent example).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FixMeStick Gold Computer Virus Removal Stick for Windows PCs - Unlimited Use on Up to 5 Laptops or Desktops for 2 Years - Works with Your Antivirus
  • WHAT YOU GET: FixMeStick Virus Removal Tool for Windows PCs (Windows XP, Vista, 7, 8, 8.1, 10, and 11. 512 MB RAM required), Getting Started Guide, our virus removal guarantee backed by our friendly Canadian based Customer Support Team.

Why it appears in FRST, Malwarebytes or HijackThis logs

Farbar Recovery Scan Tool (FRST), HijackThis, Autoruns and similar utilities enumerate scheduled tasks, files, signatures and registry entries for an analyst. A line showing DXGIAdapterCache therefore means the artifact was reported; it does not by itself mean malware was detected. FRST logs can list this task alongside ordinary Microsoft tasks (example).

Verify your copy safely

1. Confirm the path

  1. Press Windows key + E and open C:WindowsSystem32.
  2. Locate dxgiadaptercache.exe, right-click it, choose Properties, and note the full location.
  3. Open Digital Signatures. A normal copy should have a valid Microsoft signature.

A matching filename in C:Users<name>AppData, C:WindowsTemp, Downloads or another user-writable folder is not the Windows copy.

2. Check Authenticode and metadata in PowerShell

Open PowerShell as administrator:

Get-AuthenticodeSignature "$env:windirSystem32dxgiadaptercache.exe" |
    Format-List Status,SignerCertificate

The key result is Status : Valid, with a Microsoft signer. A missing or invalid result is a warning, not conclusive proof: verify the file directly because a log’s “not signed” notation can be misleading.

(Get-Item "$env:windirSystem32dxgiadaptercache.exe").VersionInfo |
    Format-List FileDescription,ProductName,CompanyName,FileVersion,OriginalFilename

Expected metadata generally names Microsoft Windows and DXGI Adapter Cache. Do not demand one universal version, size or timestamp; servicing changes them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Inspect the scheduled-task action

$task = Get-ScheduledTask `
  -TaskPath "MicrosoftWindowsDirectX" `
  -TaskName "DXGIAdapterCache"
$task.Actions | Format-List *

The action should point to the expected Windows executable. Look for PowerShell or cmd.exe wrappers, encoded commands, scripts, temporary paths, unexpected DLLs or unrelated arguments. To view the complete task from Command Prompt:

Rank #2
Ralix Compatible with Windows Emergency Boot USB - for Windows 98, 2000, XP, Vista, 7, 10 PC Repair USB All in One Tool (Latest Version)
  • Emergency Boot USB compatible with Windows 98, 2000, XP, Vista, 7, and 10. It has never ben so easy to repair a hard drive or recover lost files
  • Plug and Play type usb - Just boot up the usb and then follow the onscreen instructions for ease of use
  • Boots up any PC or Laptop model and brand.
  • Virus and Malware Removal made easy for you
  • This is your one stop shop for PC Repair of any need!
schtasks /query /tn "MicrosoftWindowsDirectXDXGIAdapterCache" /fo LIST /v

To list task information from PowerShell:

Get-ScheduledTask -TaskPath "MicrosoftWindowsDirectX" |
  Where-Object TaskName -eq "DXGIAdapterCache" |
  Get-ScheduledTaskInfo

4. Calculate a SHA-256 hash and scan the exact file

Get-FileHash "$env:windirSystem32dxgiadaptercache.exe" -Algorithm SHA256

Compare the hash only with a trusted reference for the same Windows build. A hash alone does not establish legitimacy. Scan the exact file with Microsoft Defender or another reputable security product. Public upload services can expose private or proprietary files, and their results are sample-specific.

Normal indicators versus red flags

Evidence Generally reassuring Needs investigation
Path Exactly under %WINDIR%System32 AppData, Temp, Downloads or another user-writable directory
Signature Valid Authenticode signature naming Microsoft Missing, invalid or unexpected publisher
Task action Launches the System32 binary directly Encoded PowerShell, scripts, command shells or unrelated arguments
Timing and context Version plausible for the installed Windows build Recent unexplained creation, odd triggers or neighboring persistence entries
Security alert Task merely listed for review Alert names this exact file or its hash as malicious

If the file or task looks suspicious

  1. Record the complete file path, task path, signer result, Windows version, detection name and task action.
  2. Export or photograph the task details and calculate the SHA-256 hash before changing anything.
  3. Run an offline or second-opinion scan. Prefer quarantine through security software because it preserves recovery information.
  4. Do not download a replacement from an unofficial site, use a random DLL fixer, or delete only the executable while leaving persistence behind.
  5. If there are signs of credential theft, ransomware, unauthorized remote access or repeated reinfection, disconnect the computer from the network and use a trusted incident-response process.

Disable a clearly malicious task only when you have recorded its configuration and have a recovery plan. On a business or high-value system, involve an incident-response professional.

Repairing a legitimate file that Windows reports as corrupted

Use system repair tools for corruption of a genuine Windows component, not as a substitute for malware analysis. In an elevated Command Prompt, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
DISM.exe /Online /Cleanup-Image /RestoreHealth
sfc /scannow
  • DISM repairs the Windows component store that SFC may rely on.
  • SFC checks and repairs protected system files.
  • Neither command proves that an identically named file outside System32 is safe, and neither is a complete malware-removal procedure.

Repair can replace the original file, so preserve forensic details first if compromise is suspected.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why online scan results can disagree

Public sandbox pages may describe different files that share the same name, different Windows builds, or incomplete runtime behavior. One Hybrid Analysis page presents Microsoft product metadata, while another sample named dxgiadaptercache.exe reports suspicious indicators such as an unusual future timestamp and a DLL loaded from a Windows temporary directory (sample-specific result; the metadata sample is here). A “clean” label is not a guarantee, and one suspicious API or registry operation is not proof by itself. Judge the individual file, path, signature, hash and behavior.

Rank #3
64GB Bootable USB Installer for Windows 11, 10 & 7 Home/Pro with WinPE Repair Tools
  • [Win OS Install or reinstall] — Boot from the USB to install or reinstall Win 11, 10, or 7 Home & Pro editions. Includes OS installations and reinstallations media plus WinPE Utility Suite.
  • [WinPE Repair & Recovery Tools] — Boot into the included WinPE utility suite to backup system and important files, troubleshoot startup problems, repair boot issues, recover data, recover Win User accounts password, and diagnose common PC problems.
  • [All-in-One PC Rescue USB] — Combines Win 11, 10, and 7 installation media with PC repair, recovery, and diagnostic tools on one bootable 64GB USB drive, helping you troubleshoot and restore a computer without needing multiple discs or downloads.
  • [Support] — Full instructions are included in packaging plus a printable copy of the instructions with troubleshooting information on the device. Also, a video “How to boot from a bootable USB drive.mp4” to help guide you through starting a PC from a USB drive. If you need help using the USB please contact us for assistance, we are here to help.
  • [Video] - If you are new to booting from a USB drive or need a refresher see our video "How to boot from USB drive" both in description and on USB device.

How antivirus detections involving the task should be read

Malware databases sometimes mention DXGIAdapterCache in entries for particular trojans or file-deleting malware (Dr.Web entry; another entry). Such references can mean malware creates, modifies, invokes or removes a task with that name; they do not show that the standard Microsoft task is inherently malicious. Ask which exact object was quarantined, its full path, hash and detection name.

Should you delete or disable it?

Do not delete a properly signed Microsoft file in the expected System32 location merely because it appears in Task Scheduler, Autoruns or a malware-removal log. The task’s existence alone is not decisive, and malware can abuse a legitimate task while leaving the genuine binary untouched. Investigate first; quarantine a confirmed malicious copy through security software rather than manually deleting evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can malware use the exact dxgiadaptercache.exe name?

Yes. A malicious copy can sit outside System32, or malware can create a forged DirectX task. Path, signature, action and hash identify the sample—not the spelling alone.

What if the file is unsigned?

Treat an invalid or missing direct Authenticode result as a warning and investigate the build, path and hash. It is not conclusive proof by itself, especially when the only evidence is a log notation rather than a direct signature check.

Does SFC remove malware?

No. SFC and DISM repair protected Windows files and the component store; they do not analyze persistence, credentials, injected code or unrelated copies in user folders.

What information should I provide when asking for help?

Provide the full path, Windows version/build, Authenticode status and signer, SHA-256 hash, complete scheduled-task action and the security product’s exact detection name.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.