Hello Bitdefender team,
I need help with a persistent issue that is preventing me from continuing development on my personal Windows 11 computer using OpenAI Codex.
- What happens
Bitdefender repeatedly displays “Malicious command line detected,” with the feature listed as “Antivirus.” The application is the pwsh.exe bundled with Codex, located under:
C:\Users<user>.cache\codex-runtimes\codex-primary-runtime\dependencies\native\powershell\pwsh.exe
Codex reports:
CreateProcessAsUserW failed: 5 (Access denied)
The blocked command is intended to make a bounded edit to a local Python test file. It checks the original file’s size and SHA-256, verifies the replacement location and protected content, then writes and reads back the result. It includes JSON-escaped source text. The Base64 conversion near the end compares written bytes; it is not an encoded execution payload.
Read-only checks have succeeded, while the editing process has repeatedly failed to start. I suspect a false positive, but I am seeking confirmation rather than assuming the detection is harmless. - Troubleshooting so far
- I contacted live support and submitted the requested bdsyslog.zip through the supplied upload channel
- Support said the technical team had been notified of the upload
- Support suggested an Antivirus exception, but the Antivirus option was greyed out; only the Advanced Threat Defense option was available
- The suggested attempts to resolve the exception issue did not work
- I reinstalled Bitdefender as recommended, but the problem remains unresolved
- Additional scan findings
A subsequent scan reported deleting nine JSON files from Codex Security scan artifacts and .review-hook records. Detection names included:
CMD:Heur.BZC.PZQ.Pantera.175.*
Generic.PY.Stealer.Q.F3FE4D74
Generic.DDE.Exploit.F.*
A later read-only check found the project’s core source files, backups and formal records unchanged. However, this does not establish whether the deleted review records were harmless or whether their removal affects review functionality. - Help requested
Could a moderator or technical specialist please:
- Confirm that the uploaded BDSYS log is accessible and assigned for analysis
- Identify the exact protection component and detection rule responsible for the command-line block
- Determine whether these detections involve malicious execution or command/code text stored in review records
- Explain why Antivirus exclusions are unavailable even after reinstalling
- Provide a targeted, supported remedy that keeps protection enabled, rather than broadly excluding PowerShell or the project directory
- Advise how the deleted JSON artifacts should be handled safely
There are three related support tickets. I can provide the ticket numbers and further diagnostic details privately to a moderator so the investigation can be consolidated.
This has already taken considerable troubleshooting time and is blocking my personal development work. Please advise on the next concrete step rather than another reinstall without further diagnosis.
Thank you.