Should I block it?

Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization


PE structurePE file structure

Show functions
Import table
RegQueryInfoKeyA, RegQueryInfoKeyW, RegDeleteValueA, RegEnumKeyExA, RegSetValueExA, RegCloseKey, RegDeleteKeyA, RegCreateKeyExA, RegOpenKeyExA
GetStockObject, GetObjectA, CreateSolidBrush, GetDeviceCaps, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, DeleteObject, SetViewportOrgEx, OffsetWindowOrgEx, SetWindowOrgEx, DeleteDC
FindResourceA, LoadLibraryExA, SetThreadLocale, GetThreadLocale, lstrcmpA, MulDiv, GlobalUnlock, GlobalLock, GlobalAlloc, GetEnvironmentVariableA, SetEnvironmentVariableA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, HeapCreate, GetModuleFileNameW, GetStdHandle, WriteFile, ExitProcess, GetCommandLineA, FreeLibrary, GetModuleHandleW, InitializeCriticalSection, CreateMutexA, ReleaseMutex, IsDBCSLeadByte, WaitForSingleObject, FlushFileBuffers, CloseHandle, CreateFileW, WriteConsoleW, SetStdHandle, GetStringTypeW, LCMapStringW, GetConsoleMode, SetLastError, InterlockedDecrement, InterlockedIncrement, GetCurrentThreadId, GetModuleFileNameA, lstrlenW, GetCurrentProcess, FlushInstructionCache, lstrcmpiA, MultiByteToWideChar, lstrlenA, GetModuleHandleA, GetProcAddress, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, GetLastError, RaiseException, WideCharToMultiByte, VirtualQuery, GetSystemInfo, GetConsoleCP, SetFilePointer, LoadLibraryW, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetStartupInfoW, GetFileType, SetHandleCount, Sleep, IsValidCodePage, VirtualProtect, GetSystemTimeAsFileTime, EncodePointer, DecodePointer, RtlUnwind, LocalFree, HeapSize, HeapReAlloc, HeapDestroy, InterlockedPopEntrySList, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, HeapAlloc, GetProcessHeap, HeapFree, InterlockedPushEntrySList, InterlockedCompareExchange, IsDebuggerPresent, GetCPInfo, GetACP, GetOEMCP
CreateItemMoniker, CoTaskMemFree, StringFromCLSID, CoTaskMemAlloc, CoTaskMemRealloc, StringFromGUID2, CoCreateInstance, OleLockRunning, CoGetClassObject, CLSIDFromProgID, CLSIDFromString, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, GetRunningObjectTable, OleRun
ClientToScreen, SendMessageA, GetWindowRect, KillTimer, SetTimer, DestroyWindow, SetWindowLongA, ShowWindow, IsWindow, GetClassInfoExA, LoadCursorA, CharNextA, RegisterClassExA, GetClientRect, CreateWindowExA, CharNextW, DefWindowProcA, GetWindowLongA, RegisterWindowMessageA, GetWindowTextLengthA, GetWindowTextA, SetWindowTextA, CreateAcceleratorTableA, GetDesktopWindow, SetFocus, GetFocus, DestroyAcceleratorTable, FillRect, ReleaseCapture, GetClassNameA, GetDlgItem, IsChild, SetCapture, RedrawWindow, InvalidateRgn, InvalidateRect, ReleaseDC, GetDC, MapWindowPoints, SetWindowPos, MoveWindow, GetSysColor, IsWindowVisible, ScreenToClient, GetCursorPos, BeginPaint, EndPaint, GetParent, GetWindow, UnregisterClassA, DispatchMessageA, TranslateMessage, PeekMessageA, MsgWaitForMultipleObjects, CallWindowProcA
Export table


Funmoods by Volonet Ltd (Signed)

Remove escortlbr.dll
MD5:   5757860dc188218396fe9e5d1d7d0f58
SHA1:   879fcb98518eecb5a1c01402aa00e52ec5fd9c6f
SHA256:   bac85636258261878970e711f8f7dbfd3ad01997bab124a14cf7dcb376152aae
Warning 4 antivirus scanners has detected malware.

What is escortlbr.dll?

FunMoods toolbar installs a Mindspark toolbar in your Web browser that collects and stores information about your web browsing habits and sends this information to Mindspark so they can suggest services or provide ads via the toolbar.

About escortlbr.dll (from Volonet Ltd)

Funmoods is a free add-on for social networks Chat that gives you a huge collection of smileys, winks, text effects and more! Get funmoods smileys for social networks and start sending amazing, fun me


File name:escortlbr.dll
Product name:Funmoods
Typical file path:C:\Program Files\funmoods\\escortlbr.dll
File version:
Size:245.95 KB (251,856 bytes)
Issued to:Volonet Ltd
Digital DNA
PE subsystem:Windows GUI
File packed:No
More details


The following programs will install this file
Conduit Ltd.
  65% remove
Gossiper Toolbar is a Conduit Community toolbar for various web browsers. The toolbar collects information about a user's web browsing habits and sends this information to Conduit so they can suggest services or provide advertising. During installation it may change the web browser's home page and search page and if uninstalled will need to be manually changed back. It may also automatically download and install updates without notifyin...
Mindspark Interactive Network
  72% remove
Installs a Mindspark toolbar in your Web browser that collects and stores information about your web browsing habits and sends this information to Mindspark so they can suggest services or provide ads via the toolbar. FunMoods toolbar gives no or little satisfaction to its users, but a profound desire to get rid of FunMoods browser extension is in place. The toolbar is but a part of the problem as occasional but inevitable redirects in ...
Volonet Ltd
  70% remove
FunMoods toolbar gives no or little satisfaction to its users, but a profound desire to get rid of FunMoods browser extension is in place. The toolbar is but a part of the problem as occasional but inevitable redirects in the course of browser search leading to the toolbar related website burden users even more. Installs a Mindspark toolbar in your Web browser that collects and stores information about your web browsing habits and sends...


Internet Explorer toolbar
Located in the registry at 'SOFTWARE\Microsoft\Internet Explorer\Toolbar'
  • CLSID: {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}

MalwareMalware detections

Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engineEngine versionDetection
Dr.Web Adware.Funmoods.1
eSafe Win32.Trojan
ESET NOD32 7.8197 Win32/Toolbar.Funmoods
Malwarebytes PUP.FunMoods

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate N 65.00%
Windows 7 Ultimate 30.00%
Microsoft Windows XP 5.00%

Distribution by countryDistribution by country

United States installs about 72.73% of Funmoods.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 66.67%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE