Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

3,1,8,6032 9.09%
3,1,8,6032 36.36%
3,1,8,5535 9.09%
3,1,8,5535 9.09%
3,1,7,3061 9.09%
3,1,7,3059 9.09%
3,1,6,3511 9.09%
3,1,4,5831 9.09%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteValueW, RegQueryValueExW, RegEnumValueW, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegCloseKey, SetNamedSecurityInfoW, RegDeleteKeyW, RegCreateKeyExW, RegOpenKeyExW, GetNamedSecurityInfoW, BuildExplicitAccessWithNameW, SetEntriesInAclW
crypt32.dll
CertGetNameStringW
gdi32.dll
CreateBitmap, GetBitmapBits, GetTextExtentExPointW, GetGlyphOutlineW, CreateFontW, GetTextExtentExPointA, CreateDIBitmap, DeleteDC, DeleteObject, SelectObject, CreateCompatibleBitmap, CreateCompatibleDC, BitBlt, GetDeviceCaps, CreateSolidBrush, GetObjectW, GetStockObject, CreateDIBSection, GetGlyphOutlineA, SetDIBitsToDevice
kernel32.dll
DllMain
msimg32.dll
AlphaBlend
ole32.dll
CoTaskMemAlloc, CreateStreamOnHGlobal, CLSIDFromString, CLSIDFromProgID, CoGetClassObject, OleLockRunning, StringFromGUID2, CoUninitialize, CoInitialize, OleInitialize, OleUninitialize, CoTaskMemRealloc, CoTaskMemFree, ReleaseStgMedium, StringFromIID, CoCreateInstance
rpcrt4.dll
UuidFromStringW
shell32.dll
SHCreateDirectoryExW, SHGetFolderPathW, DragQueryFileW, SHGetSpecialFolderPathW, ShellExecuteW, ShellExecuteExW
shlwapi.dll
PathFileExistsW, PathRemoveFileSpecW, PathAppendW, UrlUnescapeW
urlmon.dll
URLDownloadToCacheFileA, URLDownloadToCacheFileW
user32.dll
LoadCursorW, GetClassInfoExW, IsWindow, GetFocus, SetFocus, DestroyAcceleratorTable, GetDesktopWindow, BeginPaint, EndPaint, CallWindowProcW, EnableMenuItem, RegisterClassExW, ReleaseCapture, GetClassNameW, GetParent, SetCapture, RedrawWindow, InvalidateRgn, GetWindowTextW, GetWindowTextLengthW, RegisterWindowMessageW, LoadBitmapW, SetMenuItemBitmaps, InsertMenuW, PostMessageW, CreateIconIndirect, DialogBoxIndirectParamW, GetActiveWindow, DispatchMessageW, TranslateMessage, CreateAcceleratorTableW, EnableWindow, LoadImageW, FillRect, UnregisterClassA, GetMessageW, PostQuitMessage, InvalidateRect, ScreenToClient, ClientToScreen, GetClientRect, MoveWindow, CharNextW, GetSysColor, DefWindowProcW, SetWindowContextHelpId, GetWindow, wsprintfW, DestroyWindow, SetWindowPos, CreateWindowExW, GetWindowLongW, SetWindowLongW, MapDialogRect, GetDlgItem, KillTimer, SetTimer, GetWindowRect, GetSystemMenu, SetWindowTextW, EndDialog, SendMessageW, GetDC, ReleaseDC, IsChild, GetSystemMetrics
wininet.dll
DeleteUrlCacheEntryW, InternetOpenW, InternetConnectW, HttpOpenRequestW, HttpSendRequestW, DeleteUrlCacheEntryA, InternetCrackUrlW, InternetCanonicalizeUrlW, InternetCloseHandle, InternetReadFile, HttpQueryInfoA, HttpQueryInfoW
wintrust.dll
WTHelperProvDataFromStateData, WinVerifyTrust, WTHelperGetProvSignerFromChain, WTHelperGetProvCertFromChain
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer

kindling.dll

ShellFire Dynamic Link Library by PPLive Corporation (Signed)

Remove kindling.dll
Version:   3,1,4,5831
MD5:   849016e301fd83161764904f7ff3541d
SHA1:   ccfa038b4981dcad41b11958443672763c298b1d
SHA256:   1398ad5bad121c3c026e8e44dafae1676c39f27633a985bd4bf7c29c42959e30

Overview

kindling.dll is loaded as dynamic link library that runs in the context of a process. The file is digitally signed by PPLive Corporation which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:kindling.dll
Product name:ShellFire Dynamic Link Library
Typical file path:C:\Windows\System32\kindling.dll
Original name:ShellFire.dll
File version:3,1,4,5831
Size:332.85 KB (340,840 bytes)
Certificate
Issued to:PPLive Corporation
Authority (CA):VeriSign
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Context menu handlers
Located in '*\shellex\ContextMenuHandlers'
  • CLSID: {4C5A0DA6-C2DA-422D-89E1-457978AB87B5}
Approved shell extensions
Located in the registry at 'SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved'
  • 'PPTVFile extesnsion' with CLSID {a6cd1e26-02e1-406e-a3a7-2d26c6b2b3ac}
  • 'ShellFire extesnsion' with CLSID {4C5A0DA6-C2DA-422D-89E1-457978AB87B5}

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 36.36%
Windows 7 Home Premium 27.27%
Windows 8 18.18%
Windows 8 Pro 9.09%
Microsoft Windows XP 9.09%

Distribution by countryDistribution by country

Spain installs about 27.27% of ShellFire Dynamic Link Library.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 40.00%
Acer 26.67%
Sony 26.67%
GIGABYTE 6.67%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE