PhysXExtensions.dll

PhysXExtensions Dynamic Link Library

Epic Games Inc.

This is installed with multiple programs including FallenAngelsLair and Paranormal. The file has been seen being downloaded from de.fix4dll.com and multiple other hosts.
Publisher:
NVIDIA Corporation  (signed by Epic Games Inc.)

Product:
PhysXExtensions Dynamic Link Library

Description:
PhysXExtensions Dynamic Link Library (EG)

Version:
2, 8, 4, 1

MD5:
89485544c13a96e9579fedd8c2a82612

SHA-1:
35d78cf614585526407f3c51d84ddc2bd9d80d58

SHA-256:
7799e6f30fddd94a355558a21788d68e3a344e2a88adb02f89a3773bf75b72eb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/25/2025 10:47:22 PM UTC  (today)

File size:
150.8 KB (154,432 bytes)

Product version:
2, 8, 4, 1

Copyright:
Copyright (C) 2010 NVIDIA Corporation

Original file name:
PhysXExtensions.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\steam\steamapps\common\orion dino beatdown\binaries\win32\physxextensions.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/21/2011 7:00:00 PM

Valid to:
1/27/2015 6:59:59 PM

Subject:
CN=Epic Games Inc., OU=Engine Team, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Epic Games Inc., L=Raleigh, S=North Carolina, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3E1338505D2C3D34E2DF71AE64C5C24F

File PE Metadata
Compilation timestamp:
1/30/2013 7:49:54 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
3072:ZIeqA1tfs3OM6Ci9N+53FwpKY/2PMIBNdJ5fL2zPL5:Z4Y1/+jY/0Df8

Entry address:
0xD1BB

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, A9, 6D, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 0F, 33, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 48, 24, 02, 10, 74, 12, 8B, 0D, 64, 23, 02, 10, 85, 48, 70, 75, 07, E8, B1, 77, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 68, 22, 02, 10, 74, 16, 8B, 46, 08, 8B, 0D, 64, 23, 02, 10, 85, 48, 70, 75, 08, E8, 25...
 
[+]

Entropy:
6.6180

Code size:
99.5 KB (101,888 bytes)

The file PhysXExtensions.dll has been discovered within the following programs.

Astralium  by Epic Games, Inc.
About 9% of users remove it
Betrayer  by Blackpowder Games
www.BlackpowderGames.com
About 2% of users remove it
Chime_UDK  by Epic Games, Inc.
About 8% of users remove it
Countless Rooms of Death  by Epic Games, Inc.
steamcommunity.com/sharedfiles/filedetails/?id=204659946
About 6% of users remove it
Desura: Perilous Peak  by docjoe23
Perilous Peak is distributed through Desura, a digital distribution platform for games and provides automated game updates via a client that allows users to create game mods as well as the online interface. Desura does not utilize digital rights management.
www.desura.com/games/perilous-peak
About 5% of users remove it
Dream  by HyperSloth
dreamthegame.co.uk
About 7% of users remove it
Driving Range Cart Simulator  by Epic Games, Inc.
About 5% of users remove it
Epigenesis  by Dead Shark Triplepunch
deadsharktriplepunch.com/epigenesis
About 2% of users remove it
FallenAngelsLair  by Epic Games, Inc.
About 7% of users remove it
My Game Long Name  by Epic Games, Inc.
If you directly run an Epic game installed with a custom installer, the user needs Administrator access to run the game for the first time. If this occurs, an uninstall entry gets created in Windows Add/Remove Programs with the name 'My Game Long Name'.
About 9% of users remove it
 
Latest 20 of 20 programs
Powered by Should I Remove It?

The file PhysXExtensions.dll has been seen being distributed by the following 4 URLs.

http://de.fix4dll.com/.../?file=PhysXExtensions.dll&md5=89485544C13A96E9579FEDD8C2A82612

http://pt.fix4dll.com/.../?file=PhysXExtensions.dll&md5=89485544C13A96E9579FEDD8C2A82612

Scan PhysXExtensions.dll - Powered by Reason Core Security