Hacker News new | ask | show | jobs
by skuzins 6410 days ago
Hi, this is Sascha from BaseShield.

Sorry about this confusion, such messages can be worrying, but let me assure you that BaseShield is not doing anything malicious here. Symantec Endpoint Security is reporting some activity that is in fact happening but is not malicious. To achieve its high level of sandbox security, BaseShield in some cases loads dlls into other processes. This is a common technique that is natively supported by the Windows API and is in itself perfectly safe. We will investigate how this can be avoided and try to make sure BaseShield does not trigger these warnings with this product.

Again, apologies for the inconvenience. Please contact me directly at sascha (at) baseshield.com if you have any questions about this.

UPDATE: Symantec Endpoint Protection appears to be prone to showing false alerts. This not only affects BaseShield but also other products, including Microsoft Virtual PC.

https://forums.symantec.com/syment/board/message?board.id=en...

https://forums.symantec.com/syment/board/message?board.id=en...

https://forums.symantec.com/syment/board/message?board.id=en...