Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 10th March 2009   #1
Geek Member
 
Profile:
Join Date: Jul 2002
Location: Peterborough, UK
Posts: 822
Computer Experience:
SC/MP
Hugh Jarss Reputation Level


what is pifts.exe please, and should it be blocked at firewall?

Hi all

I've noticed a lot of internet confusion about a file called "pifts.exe" trying to connect out

It seems there's a bit of a fuss on about all the posts at a Norton forum concerning this file getting deleted - wonderful fodder for conspiracy theorists...

What is this file "pifts.exe" pls? (I've seen mention that it's a kind of keylogger, but am unsure how accurate this information is)

Does it have any legitimate purpose (i.e. should it be allowed through a firewall)

best wishes, HJ.

Hugh Jarss is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 10th March 2009   #2
SuperGeek
 
Profile:
Join Date: Sep 2006
Location: Walnut Creek, California, United States
Posts: 2,065
Computer Experience:
Intermediate
Evan Omo Reputation LevelEvan Omo Reputation LevelEvan Omo Reputation LevelEvan Omo Reputation Level

My System

Hi Hugh Jarss. Read this, What is Pifts.exe.

It seems that its linked to Norton. I would try blocking it through the firewall and see if something doesn't work after denying it for example. Then you will know if its necessary or not. Do you have Norton installed and what Operating System are you using?

Evan Omo is offline   Reply With Quote
Old 10th March 2009   #3
Staff
 
PeteC's Avatar
 
Profile:
Join Date: May 2002
Location: Staffordshire, UK
Posts: 22,752
Computer Experience:
Usually not enough
PeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation LevelPeteC Reputation Level

My System

He's already been there Evan ....
Quote:
[...] Hugh Jarss. Read this, What is Pifts.exe. It seems that its linked to Norton. I would try blocking it through the firewall and see if [...]

PeteC is online now   Reply With Quote
Old 10th March 2009   #4
Geek Member
 
Profile:
Join Date: Jul 2002
Location: Peterborough, UK
Posts: 822
Computer Experience:
SC/MP
Hugh Jarss Reputation Level


Hi Evan

read your link but it asks more questions than it answers...

(linux at present BTW, Win98 sometimes (but with Firefox or Opera, not IE; behind router w. NAT and a good firewall!) - I don't use Norton)

I heard about the PIFTS scramble at SANS, and became curious.

(AFAIK) It seems that it's ?not limited to Norton, it's just that Norton's attracting attention because they are currently deleting all posts on this topic (plus it seems banning users who post??). There's plently of stuff about PIFTS on the Zone Labs forums, for example.

The furore seems to be mainly because *at least some folks* are linking PIFTS (?= Public Internet and File Tracking System) to Magic Lantern.

for Magic Lantern, see here:
http://en.wikipedia.org/wiki/Magic_Lantern_(software).

Whatever the truth of the matter, your advice to "block it and see if anything breaks" seems good

The only conclusion that I've drawn thus far is that Norton are doing a really good job of destroying their credibility by deleting all the posts without some informed response as to why they are doing this

best wishes, HJ


Last edited by Hugh Jarss; 10th March 2009 at 17:39. Reason: made Wikipedia link work (corrected missing bracket)
Hugh Jarss is offline   Reply With Quote
Old 10th March 2009   #5
Geek Member
 
Profile:
Join Date: Jul 2002
Location: Peterborough, UK
Posts: 822
Computer Experience:
SC/MP
Hugh Jarss Reputation Level


nice one Pete yes I saw that too

yup, news sure travels fast on the internet...

Hugh Jarss is offline   Reply With Quote
Old 10th March 2009   #6
Geek Member
 
Profile:
Join Date: Jul 2002
Location: Peterborough, UK
Posts: 822
Computer Experience:
SC/MP
Hugh Jarss Reputation Level


SANS now clarify the issue

Hi

According to SANS, it seems that Symantec are now saying that it's merely part of the Norton update process; but still, no ideas yet as to why the posts were getting deleted so avidly (which is what really caused the fuss/interest in the first place).

Also from SANS:
Quote:
We've been sent an example of a web page targeting the term "PIFTS.exe" along with other popular search terms that lead to obfuscated javascript that leads in turn to actual malware.

Take care if you search for this: you might find the bad guys out there taking advantage of our interest in PIFTS.exe already
best wishes, HJ.

Hugh Jarss is offline   Reply With Quote
Old 11th March 2009   #7
SuperGeek
 
Profile:
Join Date: Sep 2006
Location: Walnut Creek, California, United States
Posts: 2,065
Computer Experience:
Intermediate
Evan Omo Reputation LevelEvan Omo Reputation LevelEvan Omo Reputation LevelEvan Omo Reputation Level

My System

Quote:
Originally Posted by PeteC View Post
He's already been there Evan ....
It was the best article I could find on that process.

Hugh, I guess your question has been answered?

Evan Omo is offline   Reply With Quote
Old 11th March 2009   #8
WindowsBBS Team Member
 
wildfire's Avatar
 
Profile:
Join Date: Apr 2008
Location: Scotland, UK
Posts: 2,337
Computer Experience:
for(i=-1; i<0; i--)
wildfire Reputation Levelwildfire Reputation Levelwildfire Reputation Levelwildfire Reputation Levelwildfire Reputation Levelwildfire Reputation Level

My System

Quote:
Originally Posted by Evan Omo View Post
It was the best article I could find on that process.

Hugh, I guess your question has been answered?
Evan,

Walk away friend

wildfire is online now   Reply With Quote
Old 11th March 2009   #9
SuperGeek
 
Profile:
Join Date: Sep 2006
Location: Walnut Creek, California, United States
Posts: 2,065
Computer Experience:
Intermediate
Evan Omo Reputation LevelEvan Omo Reputation LevelEvan Omo Reputation LevelEvan Omo Reputation Level

My System

Ok then.
Evan Omo is offline   Reply With Quote
Old 11th March 2009   #10
Administrator
Microsoft MVP
 
Arie's Avatar
 
Profile:
Join Date: Dec 2001
Location: Birkirkara, Malta
Posts: 10,275
Computer Experience:
***
Arie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation Level

My System

Have a read here: Debunking the Norton pifts.exe conspiracies
Arie is offline   Reply With Quote



Reply

Thread Tools



All times are GMT +1. The time now is 19:27.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]