Something fishy is going on.
Lots of users suddenly get a PIFTS.EXE popup warning on their AV's
It tries to connect to a Norton website, and also to an african IP.
Now the really strange things here is, Symantec has been deleting all threads made on their forums about this exe, people just asking what it is and the thread gets deleted.
I don't know much about it yet but i'm trying to gather all the info i can get.
Oh does anyone actually have this file?
Source: Tech-linkblog
Also lots of stuff on google.
Edit:
QUOTE
At zonealarm.org, one person reports talking with various representatives of Symantec for two hours without receiving any answer as to why inquiries posted on the Symantec forums were being deleted. The caller was told that PIFTS.exe is part of Symantec's update installation process, was denied any further information regarding the purpose of the file and was repeatedly transferred to a new representative when asking why inquiries about PIFTS.exe were being deleted from Symantec's forums.
Source
Edit #2:
Think i found the links to the file.
They seem legit but still be careful with what you download.
http://www.hacktrack.org/2009/03/10/now-
what-is-symantec-up-too/