
An attempt by developers from Symantec to distribute a diagnostic package of fixing products turned into a panic among users and attempts to use an information vacuum for bad purposes, reports Security Lab .
The troubles began at 16:30 California time on Monday March 9, when Symantec engineers began to spread corrections for the old versions of the NAV (Norton Anti-Virus) package and Norton Internet Security package version 2006 and 2007, which gave rise to all the fuss, called Pisft.exe (Product Information Framework Troud Shooter)? His task was to collect information about the quantity and configuration of computers using NAV/NIS 2006/2007 packages.
As a result of the human error, the Pisft.exe file was without digital signature, so users began to send numerous requests to Symantec demanding to clarify the situation. As expected to respectable users, Symantec customers published their appeals at the official forum.
The attackers instantly reacted to the sharply increased interest of users in the forum dedicated to NAV/NIS 2006/2007? For the first hour after the release of the ill -fated correction, the forum administrators found more than 200 new users who placed more than 600 meaningless, and sometimes offensive records containing the name of the Pisft.exe file.
At the same time, the automatic response system used in Symantec found the PIFTS.exe file with a potential threat, as a result, administrators or automated system began to delete all messages containing the notorious PIFTS.exe name from the official forum.
Users who found that the messages published by them are immediately destroyed, flooded all the leading search engines with requests about this file. The correction of pifts.exe was withdrawn 3 hours after the release, but users never received any official information, so the scandal spiral reached a new round.
Most of the sites that promised to provide information about the pifs.ex.ex. Interestingly, on some sites a special scenario was used, which determined the method of getting a visitor to the site.
If the visitor entered the malicious site through the search engines Google, Yahoo or MSN, then the site tried to introduce the virus in the visitor’s PC. Otherwise, the visitor’s browser issued an error.
Now the official explanations of Symantec representatives can be found on the very site where all users' messages about the unexpected behavior of systems in relation to the Pifts.exe file were deleted.