Norton blocking Android Studio from running powershell command

Norton is blocking android studio from running a powershell command. Norton claims IDP.HELU.PSE79 is the infection. I have disabled Norton Auto protect and smart firewall, added powershell to the exception list but it is still blocked. Thoughts from anyone how to allow this?

2 Likes

Hello @Waukman
Disable Auto-Protect | Smart Firewall does not disable:

  1. Behavioral Protection
  2. Email Protection
  3. Block Malicious Scripts
  4. Exploit Prevention
  5. Ransomware Protection
  6. Sandbox
  7. WiFi Security
  8. Intrusion Prevention
  9. Safe Web
  10. Download Intelligence

======

======

======

AI sourced content may make mistakes


Details

Threat name: IDP.HELU.PSE79%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
On PC from: 12/22/25, 5:41 PM
Last Used: 6/7/26, 9:34 AM
Startup Item: Yes

Many users
Millions of users in the Norton Community have used this file.

Mature
This file was released 10 months ago.

High
The file risk is high.


Activity

Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C173F4FE10D098AAA3EFFA4456991BBA | File | Deleted


Details

Threat name: IDP.HELU.PSE79%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
On PC from: 12/22/25, 5:41 PM
Last Used: 6/7/26, 9:34 AM
Startup Item: Yes

Many users
Millions of users in the Norton Community have used this file.

Mature
This file was released 10 months ago.

High
The file risk is high.


Activity

Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C173F4FE10D098AAA3EFFA4456991BBA | File | Deleted

1 Like

Note: v26 is less verbose vs v22

AI sourced content may make mistakes

AI sourced content may make mistakes

AI sourced content may make mistakes

Based on the Security History details posted, this appears to be a Behavioral Protection “Repaired” event (process termination + cleanup) rather than a file quarantine event.

AI sourced content may make mistakes

So what do developers who are developing Android applications do in these cases? Do I dump Norton and go to a different Antivrius so that I can do Android development?

Hello @Waukman

If the issue is reproducible (e.g., during build, Gradle sync, SDK update, etc.), mention that to Support as it may help them identify the trigger.

We’ve reached the limit of what can be determined from the Security History entry. The next step requires Norton to collect logs from the affected system.

AI sourced content may make mistakes
Caveat: I’m not a developer – not familiar with Android Studio

Hello @Waukman
Care to share your progress

I am still having issues but I am ignoring them for now. What ever is being blocked doesn’t appear to have an impact on the development of the program.

1 Like

@Waukman Have you attempted using your program in the Norton sandbox environment as a test?

SA

No, I have not tried this. I will take a deeper look. On the surface, it seems like this wouldn’t help me since powershell is a process spawned by AndroidStudio in a temp folder.

Here is some AI generated info for you to review:

AI Overview

To run a PowerShell script inside Norton 360’s Data Protector or Auto-Protect sandbox, you must bypass restrictions by adjusting local execution policies. Because PowerShell is a core Windows component, Norton heavily restricts it from running directly from the desktop to prevent malicious activities. [1, 2, 3, 4]

How to Execute Your Script

  1. Move your script: Place your .ps1 file on your main drive (e.g., C:\Scripts).
  2. Open PowerShell as Administrator: Search for PowerShell in the Start menu, right-click, and select Run as Administrator.
  3. Change the Execution Policy: Since sandboxes reset script permissions by default, you need to allow it to run. Run the following command:

powershell

Set-ExecutionPolicy -ExecutionPolicy Unrestricted -Scope Process

Use code with caution.

  1. Execute the script: Navigate to the folder and run your script:

powershell

& "C:\Path\To\Your\Script.ps1"

Use code with caution.

[1, 2, 3, 4, 5]

Overriding Norton’s Auto-Block

If Norton flags the script or forces it into its internal sandbox environment:

  1. Open Norton 360.
  2. Go to Settings > Antivirus > Scans and Risks.
  3. Scroll down to Exclusions / Low Risks and click Configure [Items to Exclude from Auto-Protect, SONAR, and Download Intelligence].
  4. Add the folder where your PowerShell script is located to the exclusion list.

Note: If you are simply testing the script safely, built-in Windows alternatives like the native Windows Sandbox often provide a cleaner testing environment without third-party antivirus overrides. [1, 2]

SA

Thanks for this information. However, I can’t control where Android studio runs the script. It seems to generate a new temp folder with every run along with new script files with a random name. I will dig deeper but this is really good information. Thank you.

Windows sandbox may also be something to have a look at as well.

SA

@Waukman Interesting story! I’m having a similar problem. When I try to use the local “Microsoft Scout” app, some kind of script gets blocked during authentication. I’m not exactly a tech whiz. I then moved the “Microsoft Scout” app and powershell.exe to the permanent sandbox, but that didn’t work. Before that, I (of course) disabled as much of Norton 360 as possible, but that didn’t help either.

The name of “my threat” has since changed from IDP.HELU.PSE79 to IDP.HELU.PSE80 and now to IDP.HELU.PSE81. If you’ve found out anything, I’d really appreciate your response.
Best regards,
Andreas

1 Like

Hello @mande

===

AI sourced content may make mistakes
Caveat: I’m not familiar with Microsoft Scout

Edit: content points to v22

1 Like

@bjm Thank you very much for your suggestions; I really appreciate them. Unfortunately, the suggestions didn’t work. In addition to the exclusions, I also disabled behavior-based protection. The login still doesn’t work. However, the message did not appear. After I re-enabled behavior-based protection (without attempting to log in again), the message reappeared immediately.

1 Like

Hello @mande

May be best – to document/report “issue” directly via Norton support.
Note: for an official Norton response – open a support case:
Norton Support Help Center → Contact us (bottom of page)
Contact Norton Support → Let’s get started.

===

Hello @mande
Is this your Microsoft Scout →
MicrosoftScout-Windows-0.23.331-x64-Setup.exe – Version: 0.23.331?
https://www.microsoft.com/en-us/download/details.aspx

And is your Microsoft Scout install available to all users or just yourself?

File: MicrosoftScout-Windows-0.23.331-x64-Setup.exe
File size: 303 MB (317,769,056 bytes)
MD5 checksum: 0E69FD155BF1DCC1BECFF30D5EE6232B
SHA1 checksum: 0CE0724666C1BB0EEE7EEFE4699E2F8577B60411
SHA256 checksum: 1BC8676C898D044B3765B1B8A6F4CE5F6932CF2AA01EC6D814387F266E0087BB
Date/Time: 7/17/2026

==========================

fwiw ~ as test:


096125c5455e/2026-07-17T16:41:29.150Z

Threat name: IDP.HELU.PSE81%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
On PC from: 12/2/25,
Last Used: 7/17/26,
Startup Item: Yes

Many users
Millions of users in the Norton Community have used this file.

Mature
This file was released a year ago.

High
The file risk is high.

Activity
Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\USERS\USER\APPDATA\LOCAL\TEMP__PSSCRIPTPOLICYTEST_BGMSYKMV.IBX.PS1 | File | Deleted
CF0110D7801E8D87A76495F070A50197 | File | Deleted

===


===

096125c5455e/2026-07-17T16:41:29.150Z

Threat name: IDP.HELU.PSE81%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
On PC from: 12/2/25,
Last Used: 7/17/26,
Startup Item: Yes

Many users
Millions of users in the Norton Community have used this file.

Mature
This file was released a year ago.

High
The file risk is high.

Activity
Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\USERS\USER\APPDATA\LOCAL\TEMP__PSSCRIPTPOLICYTEST_CU422PZ0.J2G.PS1 | File | Deleted
CF0110D7801E8D87A76495F070A50197 | File | Deleted

===

1 Like