Home > Threat descriptions >

Application:W32/InstallBrain

Classification

Category:  Spyware

Type:  Application

Platform:  -

Aliases:  Application:W32/InstallBrain.[variant], Trojan:W32/InstallBrain.[variant]

Summary


InstallBrain is an updater service that runs in the background and periodically updates associates browser plug-ins and add-ons.

Removal


Automatic action

Based on the settings of your F-Secure security product, it will either prompt you for a desired action, allow the program to run, block access to the program but leave it in place, or move it to the quarantine where it cannot harm your device.

Allow blocked files and exclude files from scanning

If you are confident that you are aware of the risks involved in using the program and consent to its use, you may choose to allow the program to run. You can also change the settings of the F-Secure security product to exclude it from further scanning. Note: you need administrative rights to change the settings.

Knowledge Base

Find the latest advice in our Community Knowledge Base.

About the product

See the manual for your F-Secure product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details


InstallBrain is part of a software bundler program associated with various browser plug-ins and add-ons from the Perion Network software company. When installed, the application is essentially an updater service that will run in the background as 'ibsvc.exe' and periodically download and install updates for the associated browser components.

The add-ons maintained by InstallBrain vary in function, but have reportedly silently reset the browser homepage and modified the search engine settings and/or search results. If the user elects to remove the components, the related InstallBrain program should also be uninstalled.

As of early October 2013, some InstallBrain installers have shown code similarity to Trojan-Downloader:W32/Mevade; these installers are identified with the detection name Trojan:W32/Installbrain.[variant].