I began getting this threat warning after using driver updater. Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network. Status: Repaired. Startup Item: Yes Hundred thousands of users in the Norton Community have used this file. C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated C:\Windows\System32\conhost.exe | Process | Terminated. I worked with the support chat and tried everything it recommended except using the Norton Power Eraser. When I went to download it this is what I found “Norton Power Eraser was discontinued on April 30, 2026. The tool is no longer supported and functional. Review the FAQs below for more details about this change.” So much for Norton support having a clue about their products. Every time I start/reboot the computer I get the threat. Have been using Norton/Symantec products for more than 30 years. Guess it is time to cancel the subscription and find another product.
Issue abstract:
Detailed description:
Product & version number:
OS details:
What is the error message you are seeing?
If you have any supporting screenshots, please add them:
Regarding Driver Updater. First, across the forums users report DU not giving accurate results and in some cases installing drivers that bricked their devices. Requiring a clean reinstall of Windows and other software that were being used. We recommend NOT using it and/or using it “with extreme caution” for those reasons.
Your Norton detection: It depends on what the software or file was that was detected, was it already installed or something you were installing at the time of the detection? Below is the AI generated information I can gather for you.
AI Overview
IDP.HELU.PSE79%s_cmd is a behavioral detection triggered by Norton/Avast that flags suspicious command-line activity run via Windows PowerShell (powershell.exe). In most cases, it is a false positive triggered by legitimate developer tools, software updaters, or system scripts. [1, 2, 3, 4, 5]
Why is this happening?
Machine Learning Heuristics: The IDP prefix stands for Identity Protection. The string indicates Norton’s AI/Behavioral engine suspects a file or script exhibits behaviors common to fileless malware or unauthorized system manipulation. [1, 2, 3, 4]
Legitimate Triggers: This specific alert frequently pops up when legitimate software (like IDEs, game launchers, or graphics drivers) uses background scripts for automatic updates or installations. [1, 2, 3, 4]
What you should do:
**1. Identify the Triggering Program > Check your Norton “History” or Quarantine logs to see which program was actively running when the notification popped up. If you were running an IDE (like Cursor or JetBrains), a game update, or a trusted developer tool at the exact time of the alert, it is likely a false positive. [1, 2, 3, 4, 5]
2. Verify the File
If you know exactly which file was flagged, you can scan it independently using VirusTotal. If 0 or only 1-2 obscure vendors flag it, it is safe to ignore. [1, 2]
3. Create an Exception (If Safe)
If you are 100% sure the file is safe, you can add it to Norton’s Exclusion list. Follow the steps in Norton Support to exclude the specific folder or file from future scans. [1, 2, 3]
4. Run a Secondary Scan (If Unsure)
If you do not know why the script ran, perform a secondary scan using a reputable, standalone anti-malware tool like Malwarebytes to ensure no hidden malicious scripts are running on your machine
Conversely Windows has a built in tool you can use for a second opinion.
AI Overview
MRT.exe is the Microsoft Malicious Software Removal Tool (MSRT) built into Windows. It is a free, on-demand scanner designed to detect and remove specific, prevalent malware. It runs automatically once a month via Windows Update, but you can also run it manually as a “second-opinion” scanner. [1, 2]
How to Run MRT Manually
Press the Windows Key + R to open the Run dialog box. [1, 2]
I’ve also been getting this identical warning for several days now. I’ve never used the driver updater (my trust in Norton software is low and getting lower), but I did use the Nvidia app to update my graphics card driver around the time this warning started popping up. I’ve been using the Nvidia driver updater for years with no issues. I just ran a manual MRT full scan as suggested, and it showed no threats. Guess I’ll have to exclude the powershell.exe file from the Norton scanner.
@rocketscientist If you downloaded your new drivers from you OEM or the Nvidia site exclude the application in Norton settings. Norton is most likely over zealous with its detections and the AI its using.
Thanks. The MRT didn’t find anything. I have been running Malware for many years and it doesn’t report any issue. I wonder if the whole thing is just another false positive. Went through every service and app that starts with computer start and nothing appears to be remotely related. I can run powershell and a number of commands/apps and no problem or warning. One thing that has made me think about looking for another product is that the last few times I have had a problem with Norton 360 is the first thing they recommend is removing and reinstalling their software. Reminds me of what used to be a typical thing on Windows 2 and 3. I refused to put Windows on any of my machines until I began working on my Masters degree in CompSci and it was required for some of the classes/projects. Before that I used different versions of OS/2 through WARP 4 which was far more robust and actually ran some of the Windows apps faster and without the “blue screen of death”. This is the only machine I run windows on. The others run a version of Linux. Funny, I still have the Red Hat version 2.0 workstation and 3.2 server versions among all the old disks stored away. Thanks for the info. Guess I will just have Norton ignore powershell during startup.
Thanks Dale for the post-back. This is indeed most likely a false positive issue on the part of you both. One last thing of note is, IF, you both have the installers still around, try having VirusTotal review it for you, see what those results are. MetaDefender is also another useful tool to use and is highly regarded.
VirusTotal
MetaDefender can also check the file for you as well.
I just started getting this error today on boot. But I don’t know how to identify the program and when I click on “See Details” it just shows me another screen with ZERO information of what was trying to execute PowerShell script. And yes, I’m a software engineer and use JetBrains tools.
Path | Type | Status
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\USERS\ROBAI\APPDATA\LOCAL\TEMP__PSSCRIPTPOLICYTEST_HRBGTWTH.G4N.PS1 | File | Deleted
C:\USERS\ROBAI\APPDATA\LOCAL\TEMP__PSSCRIPTPOLICYTEST_5EUN1XFL.OEK.PS1 | File | Deleted
C:\USERS\ROBAI\APPDATA\LOCAL\TEMP__PSSCRIPTPOLICYTEST_RBD2N25A.BPS.PS1 | File | Deleted
645A917389B470269DF99A4A0BF978F0 | File | Deleted
This message is pointless and doesn’t help me at all? What the heck does Norton expect me to do about this to determine if it’s valid or not and setup and exclusion? I already have exclusions for Visual Studio and JetBrains folders.
So a google AI search reveals these files are standard temp files Windows creates and are benign … so the question is why is Norton flagging them … I thought Norton used AI also to determine false positives … I mean heck, if Google can, why can’t Norton?
Norton support the past few years has not been helpful. Spend hundreds of dollars each year for Norton 360, driver manager tool and other options. Am seriously considering not renewing any of the Norton products and looking at something else like Bitdefender or TotalAV. It has gotten to be a joke when the first thing support suggests is to run the uninstaller and reinstall.
@robains When you bring up the name JetBrains I cringe. This software is listed in the weekly CISA reports almost every week. In your case what you are using and its version my be the telling story on your side. I have to wonder if Norton is detecting a vulnerability that hasn’t been patched? Here is some information for you to review:
AI Overview
Major vulnerabilities impacting JetBrains products—primarily IntelliJ IDEA, TeamCity, YouTrack, and JetBrains Hub—require attention to avoid unauthorized code execution, data exposure, and authentication bypasses. [1, 2, 3]
Recently Patched Flaws (Mid-2026)
JetBrains released significant security patches in May and June 2026. The major vulnerabilities include: [1, 2]
JetBrains Hub (CVE-2026-56141 & CVE-2026-50242): Multiple critical authentication bypass flaws that allowed account takeovers without interaction and administrative access via direct database access. [1, 2]
IntelliJ IDEA & GoLand (CVE-2026-49366 & CVE-2026-53915): Remote Code Execution (RCE) vulnerabilities. Attackers could execute commands within the IDE host context via untrusted project configurations or malicious guest user accounts. [1, 2, 3]
JetBrains TeamCity (CVE-2026-49373 & CVE-2026-49372): An RCE flaw in the Perforce VCS root configurations and a Server-Side Request Forgery (SSRF) vulnerability in the build status component. [1, 2]
JetBrains YouTrack (CVE-2026-49370 & CVE-2026-49368): Unauthenticated information disclosure flaws through fetchApp requests and Cross-Site Scripting (XSS) via template injections. [1, 2]
IntelliJ Copyright Plugin (CVE-2026-49382) & UI Designer (CVE-2026-49383): Remote code execution and local information disclosure via maliciously crafted XML or template engine files. [1, 2]
IntelliJ Built-in Web Server (CVE-2026-41882): A flaw allowing attackers to read arbitrary local files. [1]
Ecosystem Alerts
Malicious AI Plugins: JetBrains removed 15 third-party AI extensions from the Marketplace that were secretly masquerading to harvest developer-configured API keys. [1]
Official Fixes and Resources
JetBrains has released updated versions addressing these issues across all maintained release lines (including 2024.x, 2025.x, and 2026.x). [1, 2]
To ensure your environment is secure, it is highly recommended to upgrade your products and view the specific patched build versions on the official JetBrains Issues Fixed advisory page. [1, 2]
Additionally your screenshot of the detection references powershell v1.0 which is seriously antiquated. Windows keeps that folder naming intact for backward compatibility, but I have to ask what PS version are you using?
I am also getting this same message. Multiple times a day. It tells me it has handled the issue….etc. But it keeps popping up on my screen, again and again.
I use JetBrains ReSharper and have been for over a decade without any security issues. I’ll be clear, if I have to drop Norton or JetBrains, I’ll drop Norton. To be even more direct, Norton’s constant and annoying “advertising” for additional Norton product sales and providing FALSE information about my registry slowing me down (no it’s not and I’ve run performance tests) along with other false information … that DOES make me cringe.
Anyway, the items flagged have NOTHING to do with JetBrains, they are standard Windows temporary scripts as outlined by Microsoft. But Norton does NOTHING to show me what’s in the PS scripts that they deem a threat? If Norton is unable to determine a real threat vs. standard processing, then what sort of AI processing are they using … it’s clearly not working.
And finally Windows has PowerShell natively part of the OS installed and it’s version 5.1. And the folder name is NOT the version of PowerShell being executed, it’s simply a compatibility reference, if you actually look at the PowerShell.exe located in the SysWOW64\WindowsPowerShell\v1.0 you’ll see it is NOT version 1.0.
And how is deleting the PS1 file helpful to an end user, by all means isolate if deemed a threat but deleting without looking into the contents in an isolation is NOT helpful.
Rob please read my post again. Windows retains the folder NAMED1.0 for backward compatibility. My statement was NOT, that version 1.0 is the current installed version. I am astutely aware of how the Windows OS and what its native components are and how they function.
Windows keeps that folder naming intact for backward compatibility
Using Jet Brains is of course, a person decision, my reference was/is that there are severe vulnerabilities with that software. I also linked the “Fixed Issues” site as a reference for you to review what you are using and whether it has been updated. That is standard for the way I personally try to assist. A cautious approach that doesn’t make assumptions that cannot be validated.
Regarding Norton detection. I all the other posts prior to yours I have suggested these were false positives. The AI info suggest that posted suggest you can ignore them.
> If you are confident that is the case add the directories being detected to Norton exclusions
. Norton is designed to first and foremost protect the OS. Even native Windows files are being used to gain access into systems. That alone is where I am suggesting caution whether you have used this software 40 minutes or 40 years. Things change what we are not aware of.
Using JetBrains (specifically ReSharper, dotMemory, dotPeak, dotTrace) is actually a company decision of which I happen to agree with as it’s a huge productivity saver. The issues you listed for JetBrains aren’t part of the development toolset I use.
Caution is fine and expected for this type of software. However, what is NOT fine:
Pointing to a file, deleting it and not giving anyone the ability to see what’s in the file via an editor, notepad, or anything else at our disposal. PS1 files are plain text files not binaries so one can easily open them in an editor to discover if there is anything malicious so we can make an informed decision. But if Norton expects that we’ll exclude the …AppData\Local as “safe” in order to stop this situation, that is a BAD idea. Because bad actors can indeed put malicious file in that hidden folder.
Using my paid for service called Norton 360 as an advertising platform is definitely NOT fine.
Using my paid for service called Norton 360 and providing false information (again part of the advertising campaign) such as “46683 issues are slowing your PC” suggesting I have “57.26 GB of junk” without actually knowing if it’s “junk” and to suggest it has some sort of performance penalty is even more FALSE.
I hope Norton understands how and why they lost market share and reputation and trust.
I agree 100% with protecting the OS, but that needs to be done in a way so as to not prevent the OS and other applications from working as expected. Stop the in product advertising and provide more intelligent detection and reduce false positives will go a long way in improving Norton tools.