Windows file
dwm.exe (Desktop Window Manager): genuine Windows process, or a copy using its name?
dwm.exe is the Desktop Window Manager, the Windows component that composes every window into the image shown on screen. It runs on every Windows 10 and 11 PC and is safe in C:\Windows\System32. A dwm.exe in any other folder is not Windows.
Prefer to check it yourself? The manual checks follow.
dwm.exe in C:\Windows\System32, signed by Microsoft, is safe. It is needed to draw the desktop, so do not delete it or end the process. Memory use in the tens or low hundreds of megabytes is part of how it works.
The name is copied by malware, and the genuine process can be a target for code injection. Check the folder and the signature, not the name. Malware often arrives through email attachments, links in pop-ups and unofficial downloads, so open attachments only from senders you know and install programs from the publisher's own site, and keep Windows and your programs updated.
- Task Manager name
- Desktop Window Manager (dwm.exe)
- Description in the file
- Desktop Window Manager
- Genuine folder
- C:\Windows\System32\dwm.exe
- Signed by
- Microsoft; of the 69 known builds, Winbindex lists both signed and unsigned entries, so use the hash check below as well as the signature
- Windows releases
- Windows 10 1507 to Windows 11 26H1
- Introduced in
- Windows Vista, with desktop composition
- Copies
- Normally one for each signed-in desktop session
What the Desktop Window Manager does
Since Windows Vista, windows no longer draw straight to the screen. Each window draws to an off-screen surface in video memory, and the Desktop Window Manager (DWM) renders these surfaces into one desktop image and presents it. That is how Windows shows glass window frames, window animations, live previews and high-resolution scaling. In Windows Vista and 7 this was the Aero theme; Windows 10 and 11 still use DWM for composition.
Microsoft Learn describes DWM as a Windows service, listed in Services as Desktop Window Manager Session Manager. The file is dwm.exe in the System32 folder and ships with every Windows 10 and Windows 11 release.
It holds a surface for every open window, so its memory use grows with the number of windows, their size and the number of displays. This is the reason many people mistake it for a virus: the legitimate file is one of the larger entries in the process list. Normal Windows files are installed with the operating system, and a dwm.exe that arrived any other way did not come from Windows.
About .exe files. An .exe file is a program. It runs as a process you can see in Task Manager, so its name, folder and publisher are what to check.
How to check a dwm.exe
Three checks need nothing installed.
- Where the file is. In Task Manager, Details tab, right-click dwm.exe and choose Open file location. The genuine file is in C:\Windows\System32. A copy in a user folder, AppData, Temp, ProgramData or the Downloads folder is not Windows.
- Who signed it. Right-click the file, choose Properties, then Digital Signatures: the signer must be Microsoft Windows and the signature valid. From PowerShell the status and path of every running copy are printed with:
Get-Process dwm | Select-Object Id, SessionId, Path | ForEach-Object { $_; Get-AuthenticodeSignature $_.Path | Select-Object Status, @{n='Signer';e={$_.SignerCertificate.Subject}} } - How many copies there are. One dwm.exe per desktop session is normal, so a PC with one signed-in user has one. Several copies with different paths mean at least one is not Windows. The command lists them with their folders:
Get-CimInstance Win32_Process -Filter "Name='dwm.exe'" | Select-Object ProcessId, SessionId, ExecutablePath - Compare the file with Microsoft's builds. Use the checker on this page: it computes the SHA-256 in your browser and compares it with the known Microsoft builds.
These checks show whether the file is the Windows one. They cannot show that code was injected into the running genuine process, which is a documented technique; for that run Microsoft Defender's full scan and, if the signs below apply, the offline scan.
Check your dwm.exe
Choose the dwm.exe you are unsure about. Its SHA-256 checksum is calculated in your browser and compared with the 69 Microsoft builds indexed from Windows releases and updates.
The file stays on your computer. Nothing is uploaded: the checksum is computed locally.
Warning signs and what they mean
| What you see | What it means |
|---|---|
| dwm.exe outside C:\Windows\System32 | Not the Windows file. A program is borrowing the name. |
| Two or more dwm.exe running from different folders in the same session | The genuine file is at most one of them. The rest are copies. |
| Signature missing, invalid or not Microsoft's, and the hash is not in the checker's list | The file was replaced or is not from Microsoft. |
| Lookalike names such as dwn.exe, dwm32.exe or dvm.exe | Names close to dwm.exe are used to pass a quick look at the process list. |
| High CPU or GPU use that does not fall when you close windows, with fans running | May be mining or other hidden work by a fake or injected process. If the file passes the checks, a graphics driver or a program drawing heavily is far more likely; see the problems section. |
| dwm.exe started from a script, a browser or an Office program | Windows does not start the Desktop Window Manager that way. Treat it as malicious. |
Documented abuse of dwm.exe
What public reports record about dwm.exe. Each row links to the source. MITRE ATT&CK does not list dwm.exe as a masquerade target in its own entries; these are vendor and incident reports.
| Malware | How it used the file | Source |
|---|---|---|
| CVE-2021-28310 (BITTER APT) | In 2021 Kaspersky reported an out-of-bounds write in dwmcore.dll, a component of dwm.exe, used in the wild as a privilege escalation exploit, attributed to the BITTER APT group and possibly other actors. Microsoft patched it in April 2021. | Exploit in a genuine Windows component (Securelist) |
| Process injection, general | Picus Security lists dwm.exe among the legitimate Windows processes that attackers inject code into, because a malicious module running inside it looks like Windows. | T1055 process injection (Picus) |
| Manufacturing workstation incident, April 2026 | A security investigation recorded blocked injection attempts by iexplore.exe and an injection detected in dwm.exe on the same workstation, and treated the dwm.exe injection as significant. | T1055 process injection (Command Zero) |
Two patterns: a flaw in the genuine component, fixed by installing Windows updates, and code injected into the genuine process, where the file passes every check. A copy named dwm.exe in another folder gives itself away by its path.
Everyday problems that are not malware
Why does dwm.exe use so much memory?
It keeps an off-screen surface in video memory for each open window and composes them all, so the number of windows, the resolution and the number of monitors raise its use. This is necessary for how it works, not a sign of infection.
If it keeps growing while the number of windows stays the same, update the graphics driver and restart the PC. Ending dwm.exe in Task Manager is not a fix; Windows restarts it and open windows can flicker or reset.
Why is dwm.exe using high CPU or GPU?
Usually a program that animates or redraws constantly, a video or game in a window, or a faulty graphics driver. Close programs one by one and watch whether the use falls, then update or roll back the display driver.
If nothing changes and the file failed the folder or signature check, run a full Microsoft Defender scan.
Why does the screen flicker or turn black when dwm.exe restarts?
Windows restarts the Desktop Window Manager after it crashes, and for a moment the screen redraws. Repeated crashes point to the graphics driver or a program that hooks into window drawing; installing Windows updates and the latest driver is the first step.
dwm.exe versions by Windows release
The newest build indexed for each release, and the update that delivered it. 69 Microsoft builds in total are known.
| Windows release | File version | Delivered by | Size, 64-bit |
|---|---|---|---|
| Windows 11 26H1 | 10.0.28000.2804 | KB5124006, Sep 22, 2026 | 135,168 bytes |
| Windows 11 25H2 | 10.0.26100.3624 | original release | 131,072 bytes |
| Windows 11 24H2 | 10.0.26100.9549 | KB5124010, Sep 22, 2026 | 135,168 bytes |
| Windows 11 23H2 | 10.0.22621.7219 | KB5129242, Sep 14, 2026 | 118,784 bytes |
| Windows 11 22H2 | 10.0.22621.5415 | KB5066793, Oct 14, 2025 | 118,784 bytes |
| Windows 11 21H2 | 10.0.22000.1 | original release | 122,880 bytes |
| Windows 10 22H2 | 10.0.19041.4355 | KB5066198, Sep 25, 2025 | 94,720 bytes |
| Windows 10 21H2 | 10.0.19041.7417 | KB5129236, Sep 14, 2026 | 111,104 bytes |
| Windows 10 21H1 | 10.0.19041.746 | original release | 94,720 bytes |
| Windows 10 20H2 | 10.0.19041.746 | KB5026361, May 9, 2023 | 94,720 bytes |
Questions people ask
Is dwm.exe a virus?
No. It is the Windows Desktop Window Manager. Malware can copy the name or run inside it, so the folder, the signature and the number of copies matter more than the name. A genuine file is in C:\Windows\System32, signed by Microsoft, and found among the known Microsoft builds.
Can I disable or delete dwm.exe?
No. Windows needs it to compose and show windows. Deleting or ending the genuine file makes the screen redraw or fail, and Windows restarts the process. Remove only a copy that failed the folder or signature check, using Microsoft Defender's full scan and, if needed, the offline scan.
Does seeing dwm.exe in Task Manager mean something is wrong?
No. Seeing one dwm.exe in Task Manager is expected on a healthy PC. It becomes suspicious when the file is outside System32, when several copies run from different folders in one session, or when the signature is not Microsoft's.
Why does dwm.exe use so much memory?
It stores a surface for each window and renders them together, so memory use rises with open windows, resolution and monitors. The memory use alone is not evidence of malware. A path outside System32 or a missing signature is.
What should I do if a scan says dwm.exe is malware?
First check the folder and the signature. If the file is in System32 and passes the hash check, the detection is probably wrong or a legitimate process was flagged for injected code; run the offline Microsoft Defender scan. If it is a copy elsewhere, let Defender remove it and do not touch the genuine file.
Can two dwm.exe processes run at the same time?
Yes, one for each desktop session, for example when two users are signed in or a Remote Desktop session is open. Two from the same session or from different folders are not normal. Check each one's path with the command above.
Sources
- Microsoft Learn: Desktop Window Manager
- Securelist: Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310)
- MITRE ATT&CK T1055: Process Injection
- Picus Security: T1055 Process Injection
- Command Zero: Manufacturing workstation compromised
- Winbindex, the Windows binaries index (m417z)
Version data read on Oct 5, 2026.
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
…