PIFTS.EXE

How do I made forum
User avatar
Fluffdick
fluffduck
Posts: 4544
Joined: Wed May 14, 2008 8:52 pm
Location: not where you are
Contact:

PIFTS.EXE

Post by Fluffdick »

"[Monday] evening, on systems with Norton Internet Protection running, users began to see a popup warning about an executable named PIFTS.exe trying to access the internet. The file was shown to be located in a non-existent folder inside the Symantec LiveUpdate folder. There were several posts about this to the Norton customer forums asking for help or information on this mysterious program. The initial thread received several thousand views and several pages of replies in a few short hours before being deleted. Several subsequent posts to the Norton forum were deleted much more quickly. These actions — whether actively covering up, or simply not well thought through — have spurred people to begin crafting conspiracy theories about the purposes of this PIFTS program. I for one am blocking the program until more information becomes available."
In the Norton forums the proletariats and admins are erasing and banning people for talking about PIFTS.EXE
I just read (and checked myself) GOOGLE IS FUCKING DELETING PAGES WITH PIFTS! Dammit this has to be something big. I actually trusted Google. I think Norton was going to do this without nobody noticing but somebody made a mistake and now everyone knows.
http://www.facepunch.com/showthread.php?t=706256

http://pastebin.com/m1e207a78
PIFTS.EXE STRINGS

Something fishy is going on.

Lots of users suddenly get a PIFTS.EXE popup warning on their AV's
It tries to connect to a Norton website, and also to an african IP.

Now the really strange things here is, Symantec has been deleting all threads made on their forums about this exe, people just asking what it is and the thread gets deleted.

I don't know much about it yet but i'm trying to gather all the info i can get.

Oh does anyone actually have this file?

Source: Tech-linkblog
Also lots of stuff on google.


Edit:
QUOTE
At zonealarm.org, one person reports talking with various representatives of Symantec for two hours without receiving any answer as to why inquiries posted on the Symantec forums were being deleted. The caller was told that PIFTS.exe is part of Symantec's update installation process, was denied any further information regarding the purpose of the file and was repeatedly transferred to a new representative when asking why inquiries about PIFTS.exe were being deleted from Symantec's forums.
http://www.hacktrack.org/2009/03/10/now ... ec-up-too/
Crazy Shit
Last edited by Fluffdick on Tue Mar 10, 2009 7:47 pm, edited 2 times in total.

meatloaf of darkness
Posts: 383
Joined: Mon Sep 15, 2008 9:04 pm

Post by meatloaf of darkness »

*Polishes AVG*

RabidNintendoFanboy
Posts: 870
Joined: Tue Oct 09, 2007 7:52 pm

Post by RabidNintendoFanboy »

An anti-virus software company delivering the most devastating virus EVER would be the epitome of irony.

Lets make up acronyms for the program!

Program Integrity Failure Trojan System

Yoshi
Posts: 953
Joined: Sat Jul 26, 2008 11:56 am

Post by Yoshi »

Norton sucks.
racist gay-beating monster [img]http://i30.tinypic.com/2rfzlhl.jpg[/img]
[quote="Tall-Hatted Yanimae"]I love old people[/quote]

Zink
Posts: 4706
Joined: Tue Feb 17, 2009 9:04 pm
Location: Here
Contact:

Post by Zink »

I think it is either one of these two things.

1. Just a huge prank.
2. Dinosaurs.


Also, this topic has reminded me that the computer I usually use for web-surfing has no anti-virus. Anyone know a good one I can use?

Yoshi
Posts: 953
Joined: Sat Jul 26, 2008 11:56 am

Post by Yoshi »

Zink wrote:I think it is either one of these two things.

1. Just a huge prank.
2. Dinosaurs.


Also, this topic has reminded me that the computer I usually use for web-surfing has no anti-virus. Anyone know a good one I can use?
AVG
racist gay-beating monster [img]http://i30.tinypic.com/2rfzlhl.jpg[/img]
[quote="Tall-Hatted Yanimae"]I love old people[/quote]

User avatar
Fluffdick
fluffduck
Posts: 4544
Joined: Wed May 14, 2008 8:52 pm
Location: not where you are
Contact:

Post by Fluffdick »

Man; am I ever glad I hopped off of the Norton bandwagon AGES ago.



I want to first send a (I won't lie) half-hearted apology to the admins on these forums for my contribution to the spam. However, you guys brought it on yourself. A simple "Here's what's going on, stop spamming thanks" post would have stopped all of this QUICKLY.



Now, on another note, your extremely haphazard way of handling this has prompted many to disassemble your .exe file and we have noticed a few key problems with it:



1) The file itself is designed specifically to send usage history (In the form of Internet Explorer history files, Temporary Internet Files, and Google Desktop information) to 2 private servers: One owned by Microsoft and the other owned by a Washington-based corporation known as "SwapDrive". This in and of itself is a breach of our privacy and should be explained immediately.



2) An inconsistency I noticed with the .exe in question was the fact that it has a very curious amount of padding. Padding is often used in cracking and hacking to force an .exe file to match the expected size of the program. However, why would you need any kind of padding in an official .exe from Symantec? Also, there's a lot of nonsense strings in the file; anything from the days of the week to the alphabet. Which tells me you're using even MORE padding.



What's really going on, guys?
http://community.norton.com/norton/boar ... ing&page=3

What the balls

Zink
Posts: 4706
Joined: Tue Feb 17, 2009 9:04 pm
Location: Here
Contact:

Post by Zink »

This may be one of the best examples of "ironic" I have seen in a long time.

epona4
Posts: 2507
Joined: Mon Nov 10, 2008 11:22 pm

Post by epona4 »

Can't wait to see this on Fox

Image

Zink
Posts: 4706
Joined: Tue Feb 17, 2009 9:04 pm
Location: Here
Contact:

Post by Zink »

epona4 wrote:Can't wait to see this on Fox
Dumb theroy
Oh my god. I know Fox News is bad (well, terrible), but that might just be the stupidest thing I have ever heard from any news source ever.

Please tell me that is fake.

epona4
Posts: 2507
Joined: Mon Nov 10, 2008 11:22 pm

Post by epona4 »

I don't think so :(

User avatar
Unbalanced
Posts: 5285
Joined: Thu Nov 20, 2008 3:54 am

Post by Unbalanced »

I'm pretty sure that's what I thought the first time I heard his name.j
You are now manually breathing.

User avatar
Fluffdick
fluffduck
Posts: 4544
Joined: Wed May 14, 2008 8:52 pm
Location: not where you are
Contact:

Post by Fluffdick »


Water
Posts: 4242
Joined: Fri Jun 15, 2007 6:16 am
Location: Under the radar.

Post by Water »

I have Norton. I don't know how to find the EXE. I don't really care, for that matter.

Perfect customer.
[img]http://img219.imageshack.us/img219/3664/legendaryrh6.png[/img]
[size=84]Last edited by Powers Which You Cannot Comprehend on Fri Dec 21, 2012 8:36 pm; edited 1 time in total[/size]

Yoshi
Posts: 953
Joined: Sat Jul 26, 2008 11:56 am

Post by Yoshi »

Water wrote:I have Norton.
Stop that.
racist gay-beating monster [img]http://i30.tinypic.com/2rfzlhl.jpg[/img]
[quote="Tall-Hatted Yanimae"]I love old people[/quote]

Post Reply