Slashdot Mirror


Norton Users Worried By PIFTS.exe, Stonewalling By Symantec

An anonymous reader writes that "[Monday] evening, on systems with Norton Internet Protection running, users began to see a popup warning about an executable named PIFTS.exe trying to access the internet. The file was shown to be located in a non-existent folder inside the Symantec LiveUpdate folder. There were several posts about this to the Norton customer forums asking for help or information on this mysterious program. The initial thread received several thousand views and several pages of replies in a few short hours before being deleted. Several subsequent posts to the Norton forum were deleted much more quickly. These actions — whether actively covering up, or simply not well thought through — have spurred people to begin crafting conspiracy theories about the purposes of this PIFTS program. I for one am blocking the program until more information becomes available." The current top link on Google for "PIFTS.exe" links to one of these deleted questions on Norton's support boards, which sounds innocent enough: "I searched this forum but did not see PIFTS.exe. Any idea what this is?"

8 of 685 comments (clear)

  1. Rootkit? by KingSkippus · · Score: 5, Interesting

    The file was shown to be located in a non-existent folder inside the Symantec LiveUpdate folder.

    An application that exists in a folder not accessible by the underlying operating system? Sounds suspiciously like a rootkit to me. If so, then man, am I glad I gave up Norton years ago! I mean seriously, what is so hard to understand about the concept that hiding things like directories is a security risk? Have we learned nothing from Sony's stupidity?

    Oh yeah, it's Norton (aka Symantec) we're talking about here. I guess not.

  2. Auto-update sent out a virus? by ukyoCE · · Score: 5, Interesting

    Reading TFA, the author noted a lot of padding in the suspect executable, presumably to have it match the filesize of something it's pretending to be.

    The author then suggests with the rapid proliferation and Norton's screwy coverup in their forums, that the auto-updater may have sent out a virus/rootkit.

    Perhaps Norton thought they could send out a patch to clean it up before anyone found out?

  3. They would not answer my (a customer) question. by odeean · · Score: 5, Interesting

    I posted the following question on symantec's forum and it was deleted within 2 minutes: This afternoon for no apparent reason my computer launched a file under C:\documents and settings\all users\application data\symantec\liveupdate\downloads\Updt56\pifts.exe this exe then tried to connect to do a dns lookup. It seemed suspicious because if it was really part of my symantec product then why was it not recommended to allow this connection. I blocked the request then tried to delete the file but access was denied, I couldn't even open it in notepad to see what's inside. I restarted my computer and checked the location again but the directory was gone. Is this file a part of norton internet security or am I being attacked? Does symantec have any advice on this file as it seems to belong to symantec's product? That was not offensive and I have a official product, not some pirated copy. I deserve an answer because it's my pc their program is running on.

  4. Strings in PIFTS.exe by Elphin · · Score: 5, Interesting

    Here's a dump of strings found in the pifts.exe on pastebin:

    http://pastebin.com/m1e207a78

    Interesting padding buffer right at the end? Spoofed length or just room to grow some internal resource?

  5. An effort underway by Zexarious · · Score: 5, Interesting

    There is an effort underway here http://chrysler5thavenue.blogspot.com/ to figure out exactly what the purpose of this villainous little program is.. You can download it here http://www.mediafire.com/?mnmh35b9d0k (BUT DON'T RUN IT). Right now all the theroes are tentative but we are leaning towards this being either symantec's cooperation with government on cyber spying, or a virus which was accidentally released after symantec themselves was infiltrated by middle eastern hackers (it calls home to north africa).

  6. Windows Users Beware... by capnkr · · Score: 5, Interesting

    As of this writing, if you do a Google search for "PIFTS.exe" (like was noted in the above summary), the first several links will take you to compromised/attack vector sites.

    Did /. just get social engineered?

    (Yes, Offtopic to the posts above, but maybe this will have kept someone from getting a nasty surprise...)

    --
    "...there are some things that can beat smartness and foresight. Awkwardness and stupidity can." ~ Mark Twain
    1. Re:Windows Users Beware... by capnkr · · Score: 5, Interesting

      That does seem to be the case.

      Maybe not just Slashdot, but the whole intertubes is getting socially engineered... ;)

      1) Crack the NAV update process, inject a timed release 'pifts.exe'.
      2) At the appointed time, firewall alerts get users to start massive concurrent searches on 'pifts.exe', and while Norton tries to figure out WTF is going on, they make the deadly mistake of censoring their forums to disguise their bafflement, which creates huge internets buzz on various security and tech related sites like here and Digg and ZA.
      3) Have your malware sites primed and ready to go, optimized for the expected Google results, creating a nice giant influx of "new users" for your botnets.
      4) Profit!!!

      Okay, just joking... Possible, but highly unlikely. It will be interesting to see what this story turns out to be all about. :)

      --
      "...there are some things that can beat smartness and foresight. Awkwardness and stupidity can." ~ Mark Twain
    2. Re:Windows Users Beware... by daenris · · Score: 5, Interesting

      And after a quick check, it is indeed a side effect of some compilation, so nothing about the file really appears virusy anymore. The only suspicious points remaining are why the Norton mods were so eager to remove mention of it from their forums last night.