Question: How can I detect if McAfee Virus Scanner Exclusions are being applied?
Answer:
- Download ProcMon
- Extract the downloaded files to a clean directory using WinZip or other file extraction utility.
- Launch ProcMon.exe.
- Select Options then Enable Advanced Output.
- Create the relevant filter for McShield. For example, to filter for all READ actions by McShield, set Process Name IS McShield.exe and Operation CONTAINS IRP_MJ_READ