nvspcap64.dll

NVIDIA GeForce Experience

NVIDIA Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ShadowPlay’.
Publisher:
NVIDIA Corporation  (signed and verified)

Product:
NVIDIA GeForce Experience

Description:
NVIDIA Capture Server Proxy

Version:
9.3.16.0

MD5:
372fb9c5abc9c28c21cd70b1ef6275a0

SHA-1:
10d5db76e8b8e91c0412555832b8db2d15de8b40

SHA-256:
7ac40cf3794ce7e7d43dd0151d7f28da2620ad3896771d9760cf4e125a805976

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
3/1/2014 5:48:38 AM UTC  (four months ago)

File size:
1 MB (1,063,200 bytes)

Product version:
9.3.16.0

Copyright:
(C) NVIDIA Corporation. All rights reserved.

Original file name:
nvspcap.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Windows\System32\nvspcap64.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/1/2011 7:00:00 PM

Valid to:
9/1/2014 6:59:59 PM

Subject:
CN=NVIDIA Corporation, OU=Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NVIDIA Corporation, L=Santa Clara, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
43BB437D609866286DD839E1D00309F5

File PE Metadata
Compilation timestamp:
10/16/2013 11:27:50 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:3XaL/s2VkFgBx5vuel6tiJGFG4u0nVDZDNEv+RVIQAy9iZztpG:3XaL/sKrx5Ai750nJpNEvoAy9iZztpG

Entry address:
0x8C290

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, A3, 87, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, AB, FE, FF, FF, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 48, 89, 78, 20, 41, 54, 48, 83, EC, 20, 4D, 8B, 51, 38, 48, 8B, F2, 4D, 8B, E0, 41, 8B, 02, 48, 8B, E9, 49, 8B, D1, 48, 03, C0, 48, 8B, CE, 49, 8B, F9, 49, 8D, 5C, C2, 04, 4C, 8B, C3, E8, 32, E0...
 
[+]

Entropy:
5.5929

Code size:
872 KB (892,928 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ShadowPlay

Command:
C:\Windows\System32\rundll32.exe C:\Windows\System32\nvspcap64.dll,shadowplayonsystemstart


There are 14 known versions of nvspcap64.dll by NVIDIA Corporation.

0 / 68
nvspcap64.dll  14.6.22.1  (de915690eab4b9f09ef71f5d425b400b666c0e3a)

0 / 68
nvspcap64.dll  12.4.67.0  (f5124bd0e6553128d5898e296224983c213652d1)

0 / 68
nvspcap64.dll  12.4.55.0  (13c05c4df3b7c80b1133061a81993ea7a96bc2f6)

0 / 68
nvspcap64.dll  12.4.50.0  (2d841c6ae8c453388f5705e0f8d346f52ef0beca)

0 / 68
nvspcap64.dll  12.4.46.1  (70f20d7e2b4a4b1313757ee8d6b9b0dab74ab1a8)

0 / 68
nvspcap64.dll  11.10.13.1  (a0b666de9f50afdadb39ab1d1767bd8b37a68827)

0 / 68
nvspcap64.dll  11.10.11.1  (31d8535f85d6893b1d810f1dff0181d3f8725bfc)

0 / 68
nvspcap64.dll  10.11.15.0  (4234d33c6f89829c147b10357ed1b30eea44813f)

0 / 68
nvspcap64.dll  10.10.5.1  (133a8f25e5483d99a9ba1dee3acbe882e8332438)

0 / 68
nvspcap64.dll  10.10.5.1  (bf285b32f0c4f64de80d11de0a2c1656f61762aa)

0 / 68
nvspcap64.dll  9.3.21.0  (89558b2b328c37411099b4375d1cdd7034ed4039)

0 / 68
nvspcap64.dll  9.3.21.0  (a1ad1fbd23a95b3cdf4e2f9b516b383d806422cf)

0 / 68
nvspcap64.dll  9.3.16.0  (42c170f39ad6d9a096ab1bb3dc1b86972687dd43)

0 / 68
nvspcap64.dll  9.3.11.1  (bdd931dc529f6015632af6d95ec25737539a31f6)

0 / 68
daemonu.exe  (5c3262e5922c3d176bb0efaef85d1bfa723f42ca)

0 / 68
easydaemonapiu64.dll  (58b52ddbaf5ea073bc1de1b545000f5dc4d21ff4)

0 / 68
nvupdt.dll  (82167fb9f1216c1733337b963c36092de438e9bf)

0 / 68
NvUpdtR.dll  (d3efa72a98bbadd67b3c3c23d237febd60582e4b)

0 / 68
NvTmru.exe  (82b662b8f7ef428c57f0aa2d87c351ed4da510ba)

0 / 68
nvspcaps.exe  (0092575041a4693e0ff647875bceb9741df72f9e)

0 / 68
nvspcaps64.exe  (3da28f50d97084082be4dbc7d27042ae89f96b85)

0 / 68
ComUpdatus.exe  (6068ba1ff3516b9ab960a4779f704d3857d581ec)

1 / 68
WLMerger.exe  (465de6a12e3950a62ab9c3a5a5d9c8099c4e3e88)

0 / 68
nvspcap.dll  (e1c647708c256e492c12dec86ca6bd45b245aab1)

0 / 68
ExtensionLoader.dll  (7ebb4697e9c29bbf8e8d83c03fb1e1970a5250d5)

0 / 68
easydaemonapiu32.dll  (d0c94203b724004ca1eebf8152bf61d6b1102343)

0 / 68
nvupdt32.dll  (e7225e11601825e16e81e4227cac9834134c32bf)

0 / 68
nvupdt64.dll  (f0ec7d68307b43260b3fc153c0d749702a66f8a1)

0 / 68
nvupdtr32.dll  (be31d90f5214777f3b130b93601d76835bec857e)

0 / 68
nvupdtr64.dll  (295078521c505c34c6ec321d758013cc1379fb72)

Distribution by Country