cancel
Showing results for 
Search instead for 
Did you mean: 

Monitoring mcshield.exe write actions

Acording to https://kc.mcafee.com/corporate/index?page=content&id=KB50981 I am able to monitor all read actions of the on access scanner. How can I monitor the write actions?

3 Replies

Re: Monitoring mcshield.exe write actions

Moved to VirusScan for better attention.

Re: Monitoring mcshield.exe write actions

spongetron wrote:

Acording to https://kc.mcafee.com/corporate/index?page=content&id=KB50981 I am able to monitor all read actions of the on access scanner. How can I monitor the write actions?

When you set the filter as in KB50981,

KB50981 wrote:

  1. Click Options, Enable Advanced Output.
  2. Create the filter for McShield.
           
            Example: Filter for all READ actions by McShield:
           
            Process Name: IS McShield.exe
           
    Operation: CONTAINS IRP_MJ_READ

Change the filter to:

   Operation: CONTAINS IRP_MJ_

which would catch both reads and writes, or:

        Operation: CONTAINS IRP_MJ_WRITE

should catch only write operations.

What is it you are looking for? As I understand things, McShield.exe may not write much, sometimes delegating resposibility to other modules. You may also want to include several other processes, such as mfeann.exe.

Hope this is helpful.

Ron Metzger

wwarren
Level 15
Report Inappropriate Content
Message 4 of 4

Re: Monitoring mcshield.exe write actions

This article is a bit outdated too.

If you're using current VSE software, Procmon may not be able to see everything our product is doing.

The tool you should be using now is McAfee Profiler.

William W. Warren | S.I.R.R. | Customer Success Group | McAfee