Usually, no. dxgiadaptercache.exe is normally a Microsoft Windows/DirectX component at C:WindowsSystem32dxgiadaptercache.exe, commonly launched by MicrosoftWindowsDirectXDXGIAdapterCache. The filename alone is not proof of safety: malware can copy the name or forge the task. Verify the exact path, Microsoft signature, task action and file hash before deciding whether to remove anything.
What DXGIAdapterCache is
DXGI (DirectX Graphics Infrastructure) manages parts of Windows graphics hardware and software. DXGIAdapterCache is a background Windows component, not a program you normally open yourself. File metadata for one Windows 11-era sample identifies the product as “DXGI Adapter Cache,” company “Microsoft Corporation,” internal name DXGIAdapterCache.exe, version 10.0.22621.608; versions vary by Windows release, language edition and servicing updates. See the sample metadata at Hybrid Analysis.
Windows malware-removal logs repeatedly show the expected executable under System32, including examples identifying Microsoft attribution (BleepingComputer log).
Expected file and scheduled-task locations
| Item | Normal-looking value | Why it matters |
|---|---|---|
| Executable | C:WindowsSystem32dxgiadaptercache.exe |
The Windows system directory is the expected location; a copy elsewhere requires investigation. |
| Task | MicrosoftWindowsDirectXDXGIAdapterCache |
This is the commonly documented DirectX task path (example log). |
| Task action | The same System32 executable, without obfuscated scripts or unrelated arguments |
A familiar task name can be forged; its action is decisive. |
Related DirectX tasks, such as DirectXDatabaseUpdater, may appear nearby in FRST or Autoruns output (recent example).
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
- WHAT YOU GET: FixMeStick Virus Removal Tool for Windows PCs (Windows XP, Vista, 7, 8, 8.1, 10, and 11. 512 MB RAM required), Getting Started Guide, our virus removal guarantee backed by our friendly Canadian based Customer Support Team.
Why it appears in FRST, Malwarebytes or HijackThis logs
Farbar Recovery Scan Tool (FRST), HijackThis, Autoruns and similar utilities enumerate scheduled tasks, files, signatures and registry entries for an analyst. A line showing DXGIAdapterCache therefore means the artifact was reported; it does not by itself mean malware was detected. FRST logs can list this task alongside ordinary Microsoft tasks (example).
Verify your copy safely
1. Confirm the path
- Press Windows key + E and open
C:WindowsSystem32. - Locate
dxgiadaptercache.exe, right-click it, choose Properties, and note the full location. - Open Digital Signatures. A normal copy should have a valid Microsoft signature.
A matching filename in C:Users<name>AppData, C:WindowsTemp, Downloads or another user-writable folder is not the Windows copy.
2. Check Authenticode and metadata in PowerShell
Open PowerShell as administrator:
Get-AuthenticodeSignature "$env:windirSystem32dxgiadaptercache.exe" |
Format-List Status,SignerCertificate
The key result is Status : Valid, with a Microsoft signer. A missing or invalid result is a warning, not conclusive proof: verify the file directly because a log’s “not signed” notation can be misleading.
(Get-Item "$env:windirSystem32dxgiadaptercache.exe").VersionInfo |
Format-List FileDescription,ProductName,CompanyName,FileVersion,OriginalFilename
Expected metadata generally names Microsoft Windows and DXGI Adapter Cache. Do not demand one universal version, size or timestamp; servicing changes them.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →3. Inspect the scheduled-task action
$task = Get-ScheduledTask `
-TaskPath "MicrosoftWindowsDirectX" `
-TaskName "DXGIAdapterCache"
$task.Actions | Format-List *
The action should point to the expected Windows executable. Look for PowerShell or cmd.exe wrappers, encoded commands, scripts, temporary paths, unexpected DLLs or unrelated arguments. To view the complete task from Command Prompt:
Rank #2
- Emergency Boot USB compatible with Windows 98, 2000, XP, Vista, 7, and 10. It has never ben so easy to repair a hard drive or recover lost files
- Plug and Play type usb - Just boot up the usb and then follow the onscreen instructions for ease of use
- Boots up any PC or Laptop model and brand.
- Virus and Malware Removal made easy for you
- This is your one stop shop for PC Repair of any need!
schtasks /query /tn "MicrosoftWindowsDirectXDXGIAdapterCache" /fo LIST /v
To list task information from PowerShell:
Get-ScheduledTask -TaskPath "MicrosoftWindowsDirectX" |
Where-Object TaskName -eq "DXGIAdapterCache" |
Get-ScheduledTaskInfo
4. Calculate a SHA-256 hash and scan the exact file
Get-FileHash "$env:windirSystem32dxgiadaptercache.exe" -Algorithm SHA256
Compare the hash only with a trusted reference for the same Windows build. A hash alone does not establish legitimacy. Scan the exact file with Microsoft Defender or another reputable security product. Public upload services can expose private or proprietary files, and their results are sample-specific.
Normal indicators versus red flags
| Evidence | Generally reassuring | Needs investigation |
|---|---|---|
| Path | Exactly under %WINDIR%System32 |
AppData, Temp, Downloads or another user-writable directory |
| Signature | Valid Authenticode signature naming Microsoft | Missing, invalid or unexpected publisher |
| Task action | Launches the System32 binary directly | Encoded PowerShell, scripts, command shells or unrelated arguments |
| Timing and context | Version plausible for the installed Windows build | Recent unexplained creation, odd triggers or neighboring persistence entries |
| Security alert | Task merely listed for review | Alert names this exact file or its hash as malicious |
If the file or task looks suspicious
- Record the complete file path, task path, signer result, Windows version, detection name and task action.
- Export or photograph the task details and calculate the SHA-256 hash before changing anything.
- Run an offline or second-opinion scan. Prefer quarantine through security software because it preserves recovery information.
- Do not download a replacement from an unofficial site, use a random DLL fixer, or delete only the executable while leaving persistence behind.
- If there are signs of credential theft, ransomware, unauthorized remote access or repeated reinfection, disconnect the computer from the network and use a trusted incident-response process.
Disable a clearly malicious task only when you have recorded its configuration and have a recovery plan. On a business or high-value system, involve an incident-response professional.
Repairing a legitimate file that Windows reports as corrupted
Use system repair tools for corruption of a genuine Windows component, not as a substitute for malware analysis. In an elevated Command Prompt, run:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →DISM.exe /Online /Cleanup-Image /RestoreHealth
sfc /scannow
- DISM repairs the Windows component store that SFC may rely on.
- SFC checks and repairs protected system files.
- Neither command proves that an identically named file outside
System32is safe, and neither is a complete malware-removal procedure.
Repair can replace the original file, so preserve forensic details first if compromise is suspected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why online scan results can disagree
Public sandbox pages may describe different files that share the same name, different Windows builds, or incomplete runtime behavior. One Hybrid Analysis page presents Microsoft product metadata, while another sample named dxgiadaptercache.exe reports suspicious indicators such as an unusual future timestamp and a DLL loaded from a Windows temporary directory (sample-specific result; the metadata sample is here). A “clean” label is not a guarantee, and one suspicious API or registry operation is not proof by itself. Judge the individual file, path, signature, hash and behavior.
Rank #3
- [Win OS Install or reinstall] — Boot from the USB to install or reinstall Win 11, 10, or 7 Home & Pro editions. Includes OS installations and reinstallations media plus WinPE Utility Suite.
- [WinPE Repair & Recovery Tools] — Boot into the included WinPE utility suite to backup system and important files, troubleshoot startup problems, repair boot issues, recover data, recover Win User accounts password, and diagnose common PC problems.
- [All-in-One PC Rescue USB] — Combines Win 11, 10, and 7 installation media with PC repair, recovery, and diagnostic tools on one bootable 64GB USB drive, helping you troubleshoot and restore a computer without needing multiple discs or downloads.
- [Support] — Full instructions are included in packaging plus a printable copy of the instructions with troubleshooting information on the device. Also, a video “How to boot from a bootable USB drive.mp4” to help guide you through starting a PC from a USB drive. If you need help using the USB please contact us for assistance, we are here to help.
- [Video] - If you are new to booting from a USB drive or need a refresher see our video "How to boot from USB drive" both in description and on USB device.
How antivirus detections involving the task should be read
Malware databases sometimes mention DXGIAdapterCache in entries for particular trojans or file-deleting malware (Dr.Web entry; another entry). Such references can mean malware creates, modifies, invokes or removes a task with that name; they do not show that the standard Microsoft task is inherently malicious. Ask which exact object was quarantined, its full path, hash and detection name.
Should you delete or disable it?
Do not delete a properly signed Microsoft file in the expected System32 location merely because it appears in Task Scheduler, Autoruns or a malware-removal log. The task’s existence alone is not decisive, and malware can abuse a legitimate task while leaving the genuine binary untouched. Investigate first; quarantine a confirmed malicious copy through security software rather than manually deleting evidence.
Frequently Asked Questions
Can malware use the exact dxgiadaptercache.exe name?
Yes. A malicious copy can sit outside System32, or malware can create a forged DirectX task. Path, signature, action and hash identify the sample—not the spelling alone.
What if the file is unsigned?
Treat an invalid or missing direct Authenticode result as a warning and investigate the build, path and hash. It is not conclusive proof by itself, especially when the only evidence is a log notation rather than a direct signature check.
Does SFC remove malware?
No. SFC and DISM repair protected Windows files and the component store; they do not analyze persistence, credentials, injected code or unrelated copies in user folders.
What information should I provide when asking for help?
Provide the full path, Windows version/build, Authenticode status and signer, SHA-256 hash, complete scheduled-task action and the security product’s exact detection name.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

