Quote:
"[Monday] evening, on systems with Norton Internet Protection running, users began to see a popup warning about an executable named PIFTS.exe trying to access the internet. The file was shown to be located in a non-existent folder inside the Symantec LiveUpdate folder. There were several posts about this to the Norton customer forums asking for help or information on this mysterious program. The initial thread received several thousand views and several pages of replies in a few short hours before being deleted. Several subsequent posts to the Norton forum were deleted much more quickly. These actions — whether actively covering up, or simply not well thought through — have spurred people to begin crafting conspiracy theories about the purposes of this PIFTS program. I for one am blocking the program until more information becomes available."
In the Norton forums the proletariats and admins are erasing and banning people for talking about PIFTS.EXE
Quote:
I just read (and checked myself) GOOGLE IS FUCKING DELETING PAGES WITH PIFTS! Dammit this has to be something big. I actually trusted Google. I think Norton was going to do this without nobody noticing but somebody made a mistake and now everyone knows.
http://www.facepunch.com/showthread.php?t=706256http://pastebin.com/m1e207a78PIFTS.EXE STRINGS
Quote:
Something fishy is going on.
Lots of users suddenly get a PIFTS.EXE popup warning on their AV's
It tries to connect to a Norton website, and also to an african IP.
Now the really strange things here is, Symantec has been deleting all threads made on their forums about this exe, people just asking what it is and the thread gets deleted.
I don't know much about it yet but i'm trying to gather all the info i can get.
Oh does anyone actually have this file?
Source: Tech-linkblog
Also lots of stuff on google.
Edit:
QUOTE
At zonealarm.org, one person reports talking with various representatives of Symantec for two hours without receiving any answer as to why inquiries posted on the Symantec forums were being deleted. The caller was told that PIFTS.exe is part of Symantec's update installation process, was denied any further information regarding the purpose of the file and was repeatedly transferred to a new representative when asking why inquiries about PIFTS.exe were being deleted from Symantec's forums.
http://www.hacktrack.org/2009/03/10/now ... ec-up-too/
Crazy Shit