How To: Detect if McAfee Virus Scanner Exclusions are being applied?

Question: How can I detect if McAfee Virus Scanner Exclusions are being applied?

Answer:

  1. Download ProcMon
  2. Extract the downloaded files to a clean directory using WinZip or other file extraction utility.
  3. Launch ProcMon.exe.
  4. Select Options then Enable Advanced Output.
  5. Create the relevant filter for McShield. For example, to filter for all READ actions by McShield, set Process Name IS McShield.exe and Operation CONTAINS IRP_MJ_READ