nvspcap64.dll

NVIDIA GeForce Experience

NVIDIA Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ShadowPlay’. The file has been seen being downloaded from www.telecharger-dll.fr.
Publisher:
NVIDIA Corporation  (signed and verified)

Product:
NVIDIA GeForce Experience

Description:
NVIDIA Capture Server Proxy

Version:
9.3.21.0

MD5:
4c376b5d5221eff4255e1696bc0ab76a

SHA-1:
89558b2b328c37411099b4375d1cdd7034ed4039

SHA-256:
2b7eeb27a495f5af7ba5c19eacfb125421171b1c1bb56908d301f2613dac05db

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 1:34:10 PM UTC  (today)

File size:
1 MB (1,064,224 bytes)

Product version:
9.3.21.0

Copyright:
(C) NVIDIA Corporation. All rights reserved.

Original file name:
nvspcap.dll

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Windows\System32\nvspcap64.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/2/2011 6:00:00 AM

Valid to:
9/2/2014 5:59:59 AM

Subject:
CN=NVIDIA Corporation, OU=Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NVIDIA Corporation, L=Santa Clara, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
43BB437D609866286DD839E1D00309F5

File PE Metadata
Compilation timestamp:
11/9/2013 2:37:51 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:nK0BXmZ5VQZ3Bi/vyMFjfgHTAy9iZztpy:nK0B2RQUFjfgzAy9iZztpy

Entry address:
0x8C610

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, A3, 87, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, AB, FE, FF, FF, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 48, 89, 78, 20, 41, 54, 48, 83, EC, 20, 4D, 8B, 51, 38, 48, 8B, F2, 4D, 8B, E0, 41, 8B, 02, 48, 8B, E9, 49, 8B, D1, 48, 03, C0, 48, 8B, CE, 49, 8B, F9, 49, 8D, 5C, C2, 04, 4C, 8B, C3, E8, 32, E0...
 
[+]

Code size:
873 KB (893,952 bytes)

2 Startup Files (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ShadowPlay

Command:
C:\Windows\System32\rundll32.exe C:\Windows\System32\nvspcap64.dll,shadowplayonsystemstart

Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ShadowPlay (1)

Command:
C:\Windows\System32\rundll32.exe C:\Windows\System32\nvspcap64.dll,shadowplayonsystemstart


The file nvspcap64.dll has been seen being distributed by the following URL.

http://www.telecharger-dll.fr/download.php?dll=nvspcap64.dll