Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryInfoKeyA, RegQueryInfoKeyW, RegDeleteValueA, RegEnumKeyExA, RegSetValueExA, RegCloseKey, RegDeleteKeyA, RegCreateKeyExA, RegOpenKeyExA
gdi32.dll
GetStockObject, GetObjectA, CreateSolidBrush, GetDeviceCaps, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, DeleteObject, SetViewportOrgEx, OffsetWindowOrgEx, SetWindowOrgEx, DeleteDC
kernel32.dll
FindResourceA, LoadLibraryExA, SetThreadLocale, GetThreadLocale, lstrcmpA, MulDiv, GlobalUnlock, GlobalLock, GlobalAlloc, GetEnvironmentVariableA, SetEnvironmentVariableA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, HeapCreate, GetModuleFileNameW, GetStdHandle, WriteFile, ExitProcess, GetCommandLineA, FreeLibrary, GetModuleHandleW, InitializeCriticalSection, CreateMutexA, ReleaseMutex, IsDBCSLeadByte, WaitForSingleObject, FlushFileBuffers, CloseHandle, CreateFileW, WriteConsoleW, SetStdHandle, GetStringTypeW, LCMapStringW, GetConsoleMode, SetLastError, InterlockedDecrement, InterlockedIncrement, GetCurrentThreadId, GetModuleFileNameA, lstrlenW, GetCurrentProcess, FlushInstructionCache, lstrcmpiA, MultiByteToWideChar, lstrlenA, GetModuleHandleA, GetProcAddress, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, GetLastError, RaiseException, WideCharToMultiByte, VirtualQuery, GetSystemInfo, GetConsoleCP, SetFilePointer, LoadLibraryW, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetStartupInfoW, GetFileType, SetHandleCount, Sleep, IsValidCodePage, VirtualProtect, GetSystemTimeAsFileTime, EncodePointer, DecodePointer, RtlUnwind, LocalFree, HeapSize, HeapReAlloc, HeapDestroy, InterlockedPopEntrySList, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, HeapAlloc, GetProcessHeap, HeapFree, InterlockedPushEntrySList, InterlockedCompareExchange, IsDebuggerPresent, GetCPInfo, GetACP, GetOEMCP
ole32.dll
CreateItemMoniker, CoTaskMemFree, StringFromCLSID, CoTaskMemAlloc, CoTaskMemRealloc, StringFromGUID2, CoCreateInstance, OleLockRunning, CoGetClassObject, CLSIDFromProgID, CLSIDFromString, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, GetRunningObjectTable, OleRun
shell32.dll
SHGetFileInfoA
user32.dll
ClientToScreen, SendMessageA, GetWindowRect, KillTimer, SetTimer, DestroyWindow, SetWindowLongA, ShowWindow, IsWindow, GetClassInfoExA, LoadCursorA, CharNextA, RegisterClassExA, GetClientRect, CreateWindowExA, CharNextW, DefWindowProcA, GetWindowLongA, RegisterWindowMessageA, GetWindowTextLengthA, GetWindowTextA, SetWindowTextA, CreateAcceleratorTableA, GetDesktopWindow, SetFocus, GetFocus, DestroyAcceleratorTable, FillRect, ReleaseCapture, GetClassNameA, GetDlgItem, IsChild, SetCapture, RedrawWindow, InvalidateRgn, InvalidateRect, ReleaseDC, GetDC, MapWindowPoints, SetWindowPos, MoveWindow, GetSysColor, IsWindowVisible, ScreenToClient, GetCursorPos, BeginPaint, EndPaint, GetParent, GetWindow, UnregisterClassA, DispatchMessageA, TranslateMessage, PeekMessageA, MsgWaitForMultipleObjects, CallWindowProcA
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer

escortlbr.dll

Funmoods by Volonet Ltd (Signed)

Remove escortlbr.dll
Version:   1.5.23.0
MD5:   5757860dc188218396fe9e5d1d7d0f58
SHA1:   879fcb98518eecb5a1c01402aa00e52ec5fd9c6f
SHA256:   bac85636258261878970e711f8f7dbfd3ad01997bab124a14cf7dcb376152aae
Warning 4 antivirus scanners has detected malware.

What is escortlbr.dll?

FunMoods toolbar installs a Mindspark toolbar in your Web browser that collects and stores information about your web browsing habits and sends this information to Mindspark so they can suggest services or provide ads via the toolbar.

About escortlbr.dll (from Volonet Ltd)

Funmoods is a free add-on for social networks Chat that gives you a huge collection of smileys, winks, text effects and more! Get funmoods smileys for social networks and start sending amazing, fun me

DetailsDetails

File name:escortlbr.dll
Publisher:Funmoods
Product name:Funmoods
Typical file path:C:\Program Files\funmoods\1.5.23.22\escortlbr.dll
File version:1.5.23.0
Size:245.95 KB (251,856 bytes)
Certificate
Issued to:Volonet Ltd
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Conduit Ltd.
  65% remove
Gossiper Toolbar is a Conduit Community toolbar for various web browsers. The toolbar collects information about a user's web browsing habits and sends this information to Conduit so they can suggest services or provide advertising. During installation it may change the web browser's home page and search page and if uninstalled will need to be manually changed back. It may also automatically download and install updates without notifyin...
Mindspark Interactive Network
  72% remove
Installs a Mindspark toolbar in your Web browser that collects and stores information about your web browsing habits and sends this information to Mindspark so they can suggest services or provide ads via the toolbar. FunMoods toolbar gives no or little satisfaction to its users, but a profound desire to get rid of FunMoods browser extension is in place. The toolbar is but a part of the problem as occasional but inevitable redirects in ...
Volonet Ltd
  70% remove
FunMoods toolbar gives no or little satisfaction to its users, but a profound desire to get rid of FunMoods browser extension is in place. The toolbar is but a part of the problem as occasional but inevitable redirects in the course of browser search leading to the toolbar related website burden users even more. Installs a Mindspark toolbar in your Web browser that collects and stores information about your web browsing habits and sends...

BehaviorsBehaviors

Internet Explorer toolbar
Located in the registry at 'SOFTWARE\Microsoft\Internet Explorer\Toolbar'
  • CLSID: {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}

MalwareMalware detections

Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engineEngine versionDetection
Dr.Web 8.13.4.7 Adware.Funmoods.1
eSafe 7.0.17.0 Win32.Trojan
ESET NOD32 7.8197 Win32/Toolbar.Funmoods
Malwarebytes 1.70.0.9 PUP.FunMoods

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate N 65.00%
Windows 7 Ultimate 30.00%
Microsoft Windows XP 5.00%

Distribution by countryDistribution by country

United States installs about 72.73% of Funmoods.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 66.67%
Hewlett-Packard 33.33%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE