escortshld.dll

Volonet Ltd

The module escortshld.dll by Volonet has been detected as adware by 40 anti-malware scanners. This file is typically installed with the program Funmoods on IE and Chrome by Volonet Ltd which is a potentially unwanted software program. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Volonet Ltd  (signed and verified)

MD5:
c9203382e3e7b20cb23fc4de70ce7ad5

SHA-1:
e19b9a6d8652de14a42899d0ad35ea07372d110e

Scanner detections:
40 / 68

Status:
Adware

Explanation:
escortshld.dll is infected by a worm that might download, install and run additional malware as well as may spread to other executable files.

Analysis date:
4/24/2024 5:24:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.N
877

Agnitum Outpost
Win32.Nimnul.Gen.2
7.1.1

AhnLab V3 Security
Win32/Ramnit.G
2014.08.29

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

avast!
Win32:RmnDrp
2014.9-140911

AVG
Win32/Zbot.F
2015.0.3355

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.14911

Bitdefender
Win32.Ramnit.N
1.0.20.1270

Bkav FE
W32.InjectAdwaredDwnA1.PE
1.3.0.4959

Clam AntiVirus
W32.Ramnit-1
0.98/19312

Comodo Security
Virus.Win32.Ramnit.K
19347

Dr.Web
Adware.Funmoods.1
9.0.1.0221

Emsisoft Anti-Malware
Win32.Ramnit.N
8.14.09.11.11

ESET NOD32
Win32/Ramnit.H virus
8.7.0.302.0

Fortinet FortiGate
W32/Ramnit.C
9/11/2014

F-Prot
W32/Ramnit.E
v6.4.6.5.141

F-Secure
Win32.Ramnit.N
11.2014-11-09_5

G Data
Win32.Ramnit
14.9.24

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.7.5.0

K7 AntiVirus
Virus
13.183.13198

Kaspersky
Virus.Win32.Nimnul
14.0.0.3268

McAfee
W32/Ramnit.a
5600.7011

Microsoft Security Essentials
Threat.Undefined
1.183.771.0

MicroWorld eScan
Win32.Ramnit.N
15.0.0.762

NANO AntiVirus
Virus.Win32.Nimnul.bqjjnb
0.28.2.61861

Norman
Ramnit.AS
11.20140911

nProtect
Win32.Ramnit.N
14.08.28.01

Panda Antivirus
W32/Cosmu.E
14.09.11.11

Qihoo 360 Security
Virus.Win32.Ramnit.A
1.0.0.1015

Quick Heal
W32.Ramnit.A
9.14.14.00

Reason Heuristics
PUP.Volonet.K
14.8.9.9

Rising Antivirus
PE:Win32.Mgr.b!1594784
23.00.65.14909

Sophos
W32/Ramnit-A
4.98

Total Defense
Win32/Ramnit.C
37.0.11149

Trend Micro House Call
PE_RAMNIT.DEN
7.2.254

Trend Micro
PE_RAMNIT.DEN
10.465.11

Vba32 AntiVirus
Virus.Win32.Nimnul.b
3.12.26.3

VIPRE Antivirus
Threat.4732184
32210

ViRobot
Win32.Nimnul.A
2011.4.7.4223

Zillya! Antivirus
Virus.Nimnul.Win32.2
2.0.0.1905

File size:
63 KB (64,464 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\funmoods\funmoods\1.5.12.2\escortshld.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/11/2012 3:30:00 AM

Valid to:
11/26/2013 3:29:59 AM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9EB879A7F4ADB713BB56F5D9EA449DA

File PE Metadata
Compilation timestamp:
2/6/2012 1:37:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:K7NHVr2DuHKclNfLdNxI+UTUzto5uuAv3/hTp7k5rqnTEDN5l7QLzttNe/hN+:K7NHr71S3UzcNuZThkKW5OttA/hw

Entry address:
0x1AF4

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 55, 28, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 48, DF, 00, 10, 89, 0D, 44, DF, 00, 10, 89, 15, 40, DF, 00, 10, 89, 1D, 3C, DF, 00, 10, 89, 35, 38, DF, 00, 10, 89, 3D, 34, DF, 00, 10, 66, 8C, 15, 60, DF, 00, 10, 66, 8C, 0D, 54, DF, 00, 10, 66, 8C, 1D, 30, DF, 00, 10, 66, 8C, 05, 2C, DF, 00, 10, 66, 8C, 25, 28, DF, 00, 10, 66, 8C, 2D, 24, DF, 00, 10, 9C, 8F, 05, 58, DF...
 
[+]

Entropy:
5.8524

Code size:
30 KB (30,720 bytes)

The file escortshld.dll has been discovered within the following program.

Funmoods on IE and Chrome  by Volonet Ltd
FunMoods toolbar gives no or little satisfaction to its users, but a profound desire to get rid of FunMoods browser extension is in place.
www.funmoods.com
65% remove it
 
Powered by Should I Remove It?

Remove escortshld.dll - Powered by Reason Core Security