dlmgn.exe

III|I|L

CAROSENTE PROJECT, S.L.

This is the Solimba installer program that will bundle additional offers mostly including adware and various unwanted PC utilities. The application dlmgn.exe by CAROSENTE PROJECT, S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Solimba DownloadMR installer. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Installer Setup  (signed by CAROSENTE PROJECT, S.L.)

Product:
III|I|L

Description:
Installer Setup

Version:
3.1.50

MD5:
a34b24cbac28f8c95bd636f936274676

SHA-1:
9116a30cd6654d645a17a5e5fba0b52760adc3d4

SHA-256:
e93ff6ebdda5f7a5a6c725b64c2693cc9eaeed2907ef00c05495ba3153686d01

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/13/2025 9:22:30 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Solimba (M)
16.10.16.12

File size:
368.7 KB (377,560 bytes)

Product version:
3.1.50

Copyright:
2015 © All Rights Reserved

Trademarks:
Installer Setup

Original file name:
imgr.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\dlmgn.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/6/2015 2:10:02 PM

Valid to:
2/6/2017 2:10:02 PM

Subject:
CN="CAROSENTE PROJECT, S.L.", O="CAROSENTE PROJECT, S.L.", S=BARCELONA, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219194A2E7EDD02B7DFBEA99132A3C4275

File PE Metadata
Compilation timestamp:
9/9/2015 7:11:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:pPvCV994J8pvSMpIvKyC+Z032UqzYblgGOaqOqziRJhn6IYw:1Uz4J8cuTOqlqUb1OaCiAIYw

Entry address:
0x57DCA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 70, 05, 00, 0C, 00, 00, 00, CC, 3D, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
343.5 KB (351,744 bytes)

Remove dlmgn.exe - Powered by Reason Core Security