Feeds

Conspiracy theories fly around Norton forum 'Pifts' purge

EXE phones home?

Beginner's guide to SSL certificates

Conspiracy theories are running rampant in the absence of a clear explanation of why Symantec deleted threads expressing concern about a file called pifts.exe from its Norton support forums.

Many users running Norton Internet Protection began seeing a popup warning on Monday that a file called PIFTS.exe on their systems was trying to access the internet. The location of the file was given as a non-existent folder buried inside the Symantec LiveUpdate folder.

The appearance of a file in a non-existent folder suggests rootkit-like behaviour. PIFTS.exe attempts to contact a server in Africa, which has been traced to Symantec.

Concerned punters started posting on Norton's support forums, asking what was going on. That's all normal enough, but then discussions on the subject were deleted without explanation from Norton's community pages. Follow-up threads mentioning the issue were deleted even more quickly.

Users unable to comment about the issue on Norton's community pages moved onto ZoneAlarm's forums instead. Meanwhile, numerous blog postings (example here) referred to the issue, some touting conflicting conspiracy theories.

4chan's bulletin board had a field day, and talk of the issue even prompted a popular urban myths site to set up a holding page. Theories about law enforcement backdoors ran rampant pending a response from Symantec clearing up the issue.

Some solid evidence also emerged.

The PIFTS.exe file has been submitted to VirusTotal numerous times, from which we only learn no vendor has defined it as malign. Submission to ThreatExpert suggests that the file phones home to Symantec (specifically stats.norton.com).

Symantec UK told us it was looking into the issue. The reliable Internet Storm Centre reports that Symantec told it the program is part of the Norton update process and is benign.

This fails to explain why support forum postings were deleted, a type of behaviour that might be cited as evidence that Symantec has something to hide. It also doesn't explain why the file reportedly appears in a non-existent folder. ®

How to simplify SSL certificate management

More from The Register

next story
Nothing illegal to see here: Tribunal says TEMPORA spying is OK
Rules mass surveillance is legal, in principle at least
Google kills CAPTCHAs: Are we human or are we spammer?
Do you make up these questions, Mr Wonka?
Author fined $500k in first US spyware conviction
100,000 creeps buy mobe-watching wares
Sony Pictures struggles as staff details, salaries and films leaked
Fury and Annie now doing the rounds - along with staff's privates
Stupid humans and their EXPENSIVE DATA BREACHES
Non-human cockups only account for 7% of leaks
Australian Government funds effort to secure wearable data pulses
Skipping hand-in-hand with government and insurance company databases
prev story

Whitepapers

Virtual desktop cost analysis
The downward trend in desktop virtualization costs and how this trend is prompting organizations to evaluate their own physical PC costs.
Manage security in real time
How security information and event management (SIEM) can work, but also shows how SIEM will become an essential feature of your security environment.
The Escalating Threat of DDoS Attacks
With increasing frequency and scale, some of the world’s largest data center and network operators are suffering from crippling Distributed Denial of Service (DDoS) attacks.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Everything a site builder wants to know
The major changes in Drupal 8 for end users, site builders, designers and front-end developers, and for back-end developers - part 2.