SCI: Tech Fears Arise Over Norton and Pifts.exe, page 3
Pages: <<  1    2    3    4    5    6  >>
ATS Members have flagged this thread 267 times


reply posted on 10-3-2009 @ 04:52 AM by fooffstarr
reply to post by nikmti



Would have to be a hell of a hacker to break an Antivirus company's link to it's software.

They'd go away for years if they were caught.


reply posted on 10-3-2009 @ 04:54 AM by Ian McLean
Wow, it's rather amusing to watch the Norton forums:
community.norton.com...

and see new threads there getting immediately deleted. Someone's pulling an all-nighter.


reply posted on 10-3-2009 @ 04:57 AM by fooffstarr
Originally posted by Ian McLean
Wow, it's rather amusing to watch the Norton forums:
community.norton.com...

and see new threads there getting immediately deleted. Someone's pulling an all-nighter.


I'd say, if they are that panicked by all this interest in the file, that they would have noticed this thread now too.

Nortons have no power over ATS, so it would be amusing to see if they tried to find a way to take down this topic too.

ATS is a dishonest company's worst nightmare.


reply posted on 10-3-2009 @ 05:18 AM by Ian McLean
Interesting string from PIFTS.EXE:

d:\perforce\entiredepot\consumer_crt\patchtools\patch021809db\release\PIFTS.pdb

A PDB, or "Program Database" file, is a separate file that is created when a C/C++ program is compiled by Microsoft Visual C++. It contains debugging information, and is usually not distributed with the EXE file.

This fully-qualified path to the PDB seems to indicate that PIFTS.EXE belongs to a set of 'patch' tools. It's unknown whether the Perforce depot (a source code version control system) that's referred to in the path is Symantic's.

Looking further at the EXE, this is a C++ STL program, console mode, compiled with Microsoft C++. Of interest is the 'imports' section, which allows the program to connect to operating system functions. It seems fairly simple, there's find/load/lock resource, which allows information in the resource segment of the EXE file to be accessed by the program, various file functions such as getting timestamps, creating and writing to files, registry access functions, some OLE automation, and interestingly, access to InternetOpen APIs provided by wininet.dll.

At first, and very brief glance, this would appear to be a program that connects to the internet and downloads files, writing them on the local machine. That's consistent with the depot naming of this as some kind of 'patch' tool. (That's just speculation, without a controlled analysis in a virtual machine.)

Of course, what is downloaded, why, and what that does, is a mystery - and Symantic's response (or lack thereof) to questions in this situation is quite suspicious.




[edit on March 10th 2009 by Ian McLean]


reply posted on 10-3-2009 @ 05:18 AM by allsop
reply to post by -Jaguar-




Rofl, this is no joke mate... this is serious stuff :| have you bothered to check pifts.exe?


reply posted on 10-3-2009 @ 05:34 AM by -Jaguar-
reply to post by allsop



Just because the file exists doesn't mean this is all couldn't be a joke. That file could have always been there. Somebody just decided to make everyone paranoid and make a post about it. Because the board this story orginated from allows anonymous posting, it could easily be one person making most of the comments.

The people now examining the file, I suspect, have no real idea what they are looking at or looking for. Try to decompile any program or open it in a hex editor and you will find wierd stuff.

People are spamming the Norton forums, that's why posts keep getting deleted. If I were them I would just lock the boards for a couple hours.


reply posted on 10-3-2009 @ 05:34 AM by Gemwolf
ATTENTION: PLEASE DO NOT SPAM OTHER SITES!

We don't advocate spamming of other sites, nor do we "boast" about it. I doubt if spamming/upsetting the Norton mods will get any answers (sooner). Should you decide to spam Norton in any case, please don’t bring it over to ATS as board wars are forbidden in the
Terms & Conditions Of Use


2g.) Board Wars: You will not use these boards to organize "attacks" on other boards, blogs, or discussion groups, and similarly, you will not organize such attacks against this board. Doing so will result in removal of your post(s) and immediate termination of your account.


Edit: Clarity

[edit on 10-3-2009 by Gemwolf]
Pages: <<  1    2    3    4    5    6  >>    ^^TOP^^