We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

McAfee scan and false-positive guidance checked July 30, 2026

McAfee Scans, Quarantine and Exclusions: A Safe, Practical Guide

Quick, full and custom scans answer different questions. Quarantine buys you time; an exclusion removes a safety check. This guide shows what to inspect before you restore anything.

Choose scans by taskVerify before restoreKeep exclusions narrow

Quick answer: Use a quick or short scan for a routine check, a full scan after a credible compromise or as a first broad baseline, and a custom scan for one file, folder, download or external drive. McAfee's official support material separates real-time, on-demand and scheduled scanning, but the visible labels and menus vary by Windows or macOS build. If McAfee quarantines a file, leave it isolated while you record the detection name, exact path, source, publisher, signature, version and SHA-256 hash. Restore only after the evidence identifies the exact file as clean; a familiar name or one reassuring forum reply isn't enough. If the detection appears wrong, use McAfee's official dispute form, update the product and rescan. An exclusion is the last, narrowest workaround—not the first response—and old McAfee help that describes custom or scheduled-scan exclusions doesn't prove that the same setting bypasses every current real-time check.

Capture the product, build and first detection before changing anything

Open McAfee from the installed application or its trusted system-tray entry, not from a browser warning. Record the product name, version, operating system, signed-in account and whether the subscription came directly from McAfee, a PC maker or an internet provider. Those details matter because current McAfee+, older Total Protection or LiveSafe builds, macOS versions and provider bundles can expose different scan names and menus.

Preserve the first event. Take a screenshot of the detection name, exact path, time, action and process if McAfee shows them, then copy the text into a note. Don't restore, delete or add an exclusion until you know which file triggered the event; a familiar folder name can contain an unfamiliar executable, and a familiar executable can have been replaced.

If the alert appeared only inside a website and McAfee isn't installed, it may be a notification scam rather than a product result. Use our fake McAfee pop-up guide to separate browser permission abuse from a real quarantine record. A genuine product event should also be visible inside the installed app or its protection history.

Real-time, on-demand and scheduled scans answer different questions

McAfee's official scan guidance for Windows and Mac separates three families. Real-time scanning checks files and apps as they're accessed, on-demand scanning begins when you ask for it, and scheduled scanning runs on a timetable. A manual full scan is therefore not a replacement for real-time protection; it's another way to inspect a wider scope at a chosen moment.

McAfee's current Mac antivirus page also lists real-time, on-demand and scheduled scanning. That supports the concepts across platforms, but it doesn't make Windows screenshots valid Mac instructions. Use the labels visible in your installed build and treat a search-result menu path as historical until it matches your screen.

Scheduled scans are useful for repeatable coverage, especially on a family PC that's usually online but rarely checked. Keep the device awake and powered at the scheduled time, and review the result afterward. A schedule that never runs because the laptop sleeps isn't protection merely because a weekly box is selected.

Choose quick, full or custom by the task—not by which sounds strongest

A quick or short scan samples common active locations, a full scan broadens the sweep, and a custom scan targets the path you choose. Current reviews and McAfee's own video show that users can encounter several on-demand choices, but names such as Quick, Full, Custom or Five-Minute Scan can vary with platform and build. The useful distinction is scope, not marketing vocabulary.

QuestionBest starting scanWhyWhat it doesn't prove
Routine check after updatesQuick or shortChecks common active locations without a broad sweepThat every stored file is clean
Credible compromise or first baselineFullExpands the scope across the deviceThat an account, router or browser is safe
One download or known folderCustomPreserves a clear target and resultThat unrelated locations are clean
New USB or external driveCustom on that driveChecks the device before opening filesThat firmware or another computer is safe
File is detected when launchedReal-time event firstThe event has the exact path and detection contextThat restoring it's safe
Scan freezes or overloads PCTroubleshoot the scanA repeated larger scan can hide the failing pathThat more scanning will repair the service

Start with the smallest scan that answers the actual question, then expand only when the evidence warrants it. This preserves time and makes the result interpretable. Repeating every scan type after an unrelated browser pop-up creates activity, not diagnosis.

Decision guide for choosing McAfee real-time, quick, full or custom scanning by task
Update first, save the result and let quarantine isolate uncertain files while you investigate.

Use a quick or short scan for a bounded routine check

A quick scan is a sensible first pass after McAfee updates, when the PC behaves normally and you want to check common active locations. It can also confirm whether a corrected detection is still firing after the vendor updates its protection data. Save the result and time so a later full or custom scan can be compared against the same state.

Don't interpret speed as weakness or a clean result as a guarantee. A quick scan deliberately examines a narrower scope, and it may not read every archive, backup or inactive program on the device. If the original evidence points to a known download folder, USB drive or secondary disk, a custom scan of that location is more direct.

Some current McAfee marketing and reviews refer to a five-minute scan. Treat it as a short on-demand option whose exact scope depends on the build, not a universal promise that every device completes in five minutes. The size, storage speed, file mix and background load all change completion time.

Run a full scan when the security question is genuinely broad

A full scan is appropriate after a credible malicious download was executed, when protection was off for an unknown period, when several unrelated locations show detections, or when you're establishing a first baseline on a newly recovered device. Update McAfee first, connect the laptop to power and close heavy apps so a long scan has a stable chance to finish. Record where it slows or stops rather than restarting immediately.

A broad sweep isn't automatically the first response to every concern. If one signed installer from an official vendor was quarantined, the important task is to verify that exact build and classification. If a browser page claims “18 viruses” but the product history is empty, the browser-notification path matters more than running full scans all night.

A clean full scan is useful evidence, not proof of absence. Malware may be new, inactive, encrypted, already removed or outside the local file scope, and a compromised account or router isn't repaired by scanning the PC. Compare the result with the original symptom and escalate the incident response when the evidence still conflicts.

Use a custom scan when you know the file, folder or drive

A custom scan keeps the question precise: “What does McAfee report for this download folder, external drive or application directory?” Archived McAfee help for custom scan options describes choosing drives, locations, file types and threat categories. The page is useful for scope concepts, but its old interface isn't guaranteed to match a current McAfee+ installation.

Include all file types when investigating an uncertain folder unless you have a documented reason to narrow it. Malware doesn't need to arrive with an obvious `.exe` name, and archives or scripts can carry the active component. If the product offers scanning inside archives, expect compressed developer trees and backups to take longer.

For a single known file, preserve its original path and hash before any repair tool moves it. The exact path connects the scan event to the download source and installed application. A file with the same name in another folder is a different item until the content proves otherwise.

Scan downloads and external drives before opening their contents

Connect an external drive only to a patched device with real-time protection active, then run a custom scan on that drive before browsing unknown files. Don't enable macros, mount unfamiliar images or run installers to “see what happens.” If the drive contains irreplaceable data, make a controlled backup through an approved recovery process rather than copying suspicious executables into trusted folders.

For a download, record the exact official page and final domain, then compare the expected filename, version and published hash when the vendor provides one. Redirect chains, mirror sites and sponsored search results can deliver a different build. The browser's Downloads list and file Properties can help reconstruct the source, but neither makes the file clean by itself.

McAfee's March 2026 research found 443 malicious ZIP files impersonating game mods, AI tools, drivers and trading utilities in January. That is why “everyone in the mod community uses it” isn't a release gate. Get the file from the publisher's official channel and verify the exact content.

Update McAfee and prepare the PC before a meaningful scan

Confirm the subscription and protection status inside the installed app, then check for product and detection updates. Restart if McAfee or Windows requests it, because a pending driver or service update can make scan behavior and results inconsistent. Note the update time so the evidence package shows which detection data made the decision.

Save work, connect portable devices to power and close games, virtual machines, large compilers and backup jobs. Don't disable real-time protection to make an on-demand scan faster. If the scan repeatedly pauses during full-screen apps, run it while those apps are closed and compare the behavior.

Make sure the target is accessible. An unplugged external drive, offline network share or encrypted container that was never mounted can't be covered merely because Full was selected. Record the chosen locations and any skipped or inaccessible items shown in the result.

Read the result in context instead of counting only threats

Record the detection name, file path, action, timestamp and whether McAfee says the item was cleaned, quarantined, deleted, blocked or couldn't be handled. Those verbs aren't interchangeable. A count of “1 issue fixed” without the path can leave you unable to tell whether a browser cache object, required program file or repeated download was involved.

Compare the result with the first symptom. A scan that quarantines a game DLL can explain why the game no longer launches; it doesn't prove that the DLL was safe. A scan with no detections doesn't explain repeated browser push notifications, so that symptom should move to browser permissions and extensions rather than another scan loop.

If several detections share one parent folder or source, group them before acting. An installer can unpack multiple components, and a mail client can recreate temporary message files. Deleting a hundred repeated entries without fixing the source may clear the list while the same pattern returns.

A stuck or resource-heavy scan is a separate troubleshooting problem

If progress stops at the same path, preserve that path and elapsed time, then let one reasonable attempt finish before forcing it closed. A large archive, virtual-disk image, mail store or damaged file can make the counter appear frozen while work continues. Check CPU, disk and the McAfee service state rather than starting multiple scans in parallel.

Use our McAfee not working, updating or scanning guide when the service won't start, definitions won't update or every scan fails. Use the separate high CPU, memory and disk guide when resource use is the dominant symptom. Those pages preserve the diagnostic boundary instead of treating exclusions as a performance fix.

Don't exclude the troublesome path simply to make the scan complete. First decide whether the path is necessary, corrupt, unreasonably large or actively changing. A performance workaround that creates a permanent blind spot isn't a successful scan repair.

Quarantine isolates a file; it doesn't declare the case closed

McAfee's archived quarantine and trusted-items help says quarantined items are encrypted and isolated so they can't harm the PC. That's the useful mental model: quarantine buys time while you identify the file and choose an action. It's neither the Recycle Bin nor an approval queue.

Leaving an uncertain item isolated is a valid temporary decision. You don't need to restore it merely because an application complains, and you don't need to delete it before recording evidence. If the item is confirmed malicious and no longer needed for incident analysis, delete it through the product's supported quarantine control.

McAfee's current quarantine restoration video says Windows and macOS products quarantine files they can't clean and can restore an item that was quarantined by mistake. The word “mistake” carries the burden: establish that the detection is wrong before returning the file to an executable location.

Inspect a quarantined item without restoring or executing it

Start with the record inside McAfee. Capture the detection name, original path, date, file name and any process or URL context. A path under a browser cache, email temp directory, program folder or user Downloads directory suggests a different source chain, but none of those locations proves whether the content is clean.

Search the detection name through McAfee's official threat information or support route, then check whether the software publisher acknowledges the exact detection and version. Avoid search-result pages that tell you to download a “removal tool” from an unrelated domain. If the only evidence is a forum post about a similarly named file, keep the item isolated.

Don't extract a quarantine container manually or copy its raw files from McAfee's storage. The supported interface preserves isolation and metadata. If a confidential business file is involved, use the organization's security team and approved sample-handling process rather than posting it to a public forum.

Choose among leave isolated, delete, submit and restore

Leave the item isolated when its source or purpose is uncertain, when the publisher signature is missing or invalid, or when different pieces of evidence conflict. This is the safest default because it keeps the file unavailable while preserving a record. Set a reminder to resolve the case rather than accumulating an unexplained quarantine indefinitely.

Delete through McAfee when the file is clearly unwanted, malicious, a disposable duplicate or an installer you can safely obtain again from the official vendor. Preserve logs and hashes first if the incident may require support, workplace reporting or account review. Deleting the sample doesn't undo actions it may have taken before detection.

Submit the file when there's credible evidence of a false positive but McAfee still detects the exact build. Restore only after McAfee or the publisher resolves the classification and your own evidence agrees. A required application failing to launch creates urgency, not proof.

Use a five-stage release gate before restoring a quarantined file

The safe sequence is capture, verify, submit, update and rescan, then restore only if cleared. Each stage should refer to the same exact file, not merely the same filename. If a vendor posts a corrected installer, prefer the fresh signed build to restoring an older disputed copy.

Stop at verification when the source is unknown, the signature is invalid, the hash doesn't match or the publisher can't confirm the build. Leave the file isolated and investigate the source account or download path. Don't use a temporary exclusion to force the process past missing evidence.

Safe release gate for verifying and submitting a McAfee quarantined file before restore
Quarantine, restore, scan exclusions and firewall rules change different controls; never substitute one for another.

Keep private and proprietary files out of public analysis channels unless the owner authorizes the disclosure. A hash can identify an exact file without sharing its contents, although a hash match is only useful when compared with a trustworthy publisher value. Sensitive cases belong in an approved support or incident-response workflow.

Verify the source, publisher signature, version and SHA-256 hash

Return to the publisher's official site through a fresh bookmark or typed domain, not the link that delivered the suspicious file. Confirm the product name, version, release date and supported operating system. A legitimate publisher can still have an old vulnerable build, and a familiar filename can be hosted by an impersonation domain.

On Windows, open the file's Properties and inspect Digital Signatures when the file type supports Authenticode. The signer should be the expected legal publisher and Windows should report a valid signature; an absent signature isn't automatic proof of malware, but it removes an important identity signal. Microsoft explains that digital signatures provide authenticity and integrity assurances only when the signature and certificate are valid and the publisher is trusted.

Compute a SHA-256 hash without executing the file. Microsoft's Get-FileHash documentation says the cmdlet identifies file content rather than relying on a filename and uses SHA-256 by default. In PowerShell, use the exact literal path:

Get-FileHash -Algorithm SHA256 -LiteralPath "C:\Path\To\File.exe"

Compare that value only with a hash published or confirmed by the vendor or an authorized support channel. A random forum hash proves nothing, and a clean multi-engine score isn't a guarantee for a new or targeted file. Record the hash because a rebuilt executable with the same name will have different content and may need a new review.

A restored file can be quarantined again because the detection didn't change

Restoring returns the file; it doesn't rewrite McAfee's classification. When real-time protection sees the same content again, it can quarantine it immediately, especially if protection data hasn't been updated or the publisher released no corrected build. Repeated restoration can also destroy the clean timeline of when the file was accessed.

Don't try to outrun the scanner by turning protection off, launching the file and adding a broad exclusion. That sequence gives an unverified executable the exact opportunity quarantine was designed to prevent. Submit the dispute, update McAfee, obtain a corrected signed build and rescan before restore.

If a generated developer binary changes on each build, its hash also changes. One community developer described repeated detections after rebuilding an executable. That single report is directional, not proof of a McAfee defect; it illustrates why stable release signing and vendor review scale better than trusting each new file by name.

Submit a suspected false positive through McAfee's official route

Use McAfee's current Detection Dispute and Allowlisting form, not a support-looking upload page from a search ad. McAfee says the form accepts authorized ZIP, RAR or extracted contents and that proprietary image formats aren't supported. For an installer, McAfee asks for extracted components as well so the relevant files can be reviewed.

Include the detection name, McAfee product and version, operating system, original path, official source URL, publisher, file version, valid-signature status and SHA-256 hash. Explain why the file is expected to be clean and whether the publisher can reproduce the detection. A concise evidence package is more useful than “my game says this DLL is safe.”

McAfee says submissions are generally processed within two business days but may take longer. Treat that as a target, not a guarantee or automatic allowlist. Keep the file isolated until the result arrives, update the product and scan the exact build again before deciding to restore.

Submit only content you're legally authorized to share. Don't upload customer data, internal tools, tax files, private documents or archives containing credentials through a public consumer form. For proprietary software, the vendor or security owner should control the submission.

A trusted item, scan exclusion, firewall rule and site override aren't the same

Quarantine isolates a detected item, while restore returns it. A scan exclusion tells a particular scan scope to skip content; a trusted item can suppress later detection; a firewall rule changes network access; and a WebAdvisor decision concerns site or download reputation. Using one control to solve another problem creates an exception without removing the cause.

If an app launches but can't connect, use the diagnostic flow in our McAfee firewall and connection-block guide. If a website displays a McAfee reputation warning, use the WebAdvisor guide. Don't add the executable to an antivirus exclusion because a server is offline, and don't open a firewall port because the file was quarantined.

Archived McAfee help warns that an item placed on its trusted list isn't detected in later scans regardless of what threats it might contain. That's a much broader consequence than clicking Restore once. Record exactly which control you change and how to reverse it.

Old McAfee exclusion pages describe legacy or provider-specific menus

Search results still rank archived McAfee help that says an excluded file or folder is omitted from custom or scheduled scans. The archived exclusion page is valuable because it warns that excluding critical files can create a serious security problem. It isn't evidence that every current McAfee+ build offers the same drawer or that the setting bypasses real-time protection.

If the old path matches an ISP-bundled, OEM or older installation, confirm the page's product family and visible labels before applying it. If it doesn't match, use the installed app's help or current McAfee Support rather than editing the registry or installing a legacy component. Our LiveSafe guide explains why retired and current product names often coexist on older devices.

Don't copy Trellix ePO, VirusScan Enterprise or Endpoint Security policy steps into a consumer PC. Managed products use administrative policy and can enforce exclusions centrally. A menu that looks similar doesn't make the control owner or risk boundary the same.

If an exception is justified, make it the smallest reversible one

Prefer the exact verified file over a folder, and a dedicated application folder over a shared library. Record the full path, SHA-256 hash, publisher, business reason, date, responsible person and planned removal date. If the file is replaced during an update, verify the new build instead of assuming the old decision transfers.

Never exclude the system drive, Windows directory, ProgramData as a whole, Downloads, browser cache, temporary directories, an email store or a broad game/mod library. These locations receive changing content from many processes and users. A broad exclusion can hide both the intended program and an unrelated malicious file placed beside it.

Keep real-time protection active and use the supported consumer control visible in your build. Retest only the required workflow, then confirm that unrelated test files and normal protection remain covered. If the exception doesn't solve the problem, remove it before trying another change.

Developer builds, games and mods need a repeatable trust process

Locally compiled tools often change hash on every build and may lack a public reputation or code signature. The durable fix is a controlled build pipeline, stable release signing, reproducible source and a vendor dispute process—not excluding the entire source, build and artifact trees. Keep experimental output separate from production releases so any narrow exception has a defined boundary.

For games, verify files through the official launcher and obtain mods only from the original project or publisher channel. Cracks, cheats and repacked installers are especially poor candidates for exceptions because their expected behavior often resembles malware and their distribution chain is hard to verify. McAfee's 2026 fake-download research shows why a popular game or tool category isn't a trust signal.

If an anti-cheat or signed game component is detected, preserve its exact version and use both the game publisher's support and McAfee's dispute form. Don't restore a DLL based on a post about a different game version. The publisher can issue a corrected signed build, while a permanent folder exclusion follows every future file dropped into that location.

Repeated email-store, cache or temporary detections need a source fix

A mail client or browser can recreate a temporary file after McAfee quarantines it, producing many events with similar names. One April 2026 community report described repeated Thunderbird temporary-file detections. That individual case doesn't prove a false positive; it shows why the parent message, attachment and application behavior matter more than deleting the same path repeatedly.

Record the parent application, account, sender, message time, URL and attachment, then update the client and inspect its security settings. Remove the malicious message or cached source through the application's supported controls when it's clearly identified. Don't exclude an entire mail profile, browser cache or temporary directory, because future unrelated content would share that blind spot.

If McAfee and the mail or browser vendor disagree about a clean file, submit the smallest authorized sample and preserve the event details. A path that disappears and returns is evidence of a process recreating content, not evidence that quarantine failed. Fix the source process and then clear stale isolated copies.

Audit exclusions you don't recognize and remove stale ones

Review the exclusion or trusted-item list after an incident, software migration and major developer project. For each entry, identify who added it, which program owns the path, whether the file still exists and whether the business reason still applies. An exception without an owner or expiry is technical debt in a security control.

An April 2026 user asked whether an unfamiliar security-product-related exclusion was legitimate. The thread is directional only; the right response isn't to bless or condemn a path by name. Capture it, check the file's signature and installation source, remove it if the owning product is gone, then update and rescan.

Unexpected exclusions can be left by old software, a repair tool, another administrator or malware. If the entry points to a system, temporary or user-writable location and no trusted owner explains it, preserve evidence before removal and broaden the incident review. Don't execute the target to discover what it does.

Remove an exception when the clean build or corrected detection arrives

Record the current file hash and working state, then remove the narrow exception through the same supported control that created it. Update McAfee and run a custom scan on the file or dedicated folder. Restart if the product or application update changed services, then repeat the required workflow with real-time protection active.

If detection returns, compare the new hash and signature with the reviewed sample. A vendor update may have replaced the file, so the old review no longer covers it. Return the new evidence to the publisher and McAfee rather than expanding the exception.

If the scan stays clean and the app works, document the correction and close the temporary exception record. Keep no broader folder rule “just in case.” Security exceptions should disappear when their stated reason disappears.

Windows, Mac, ISP bundles and managed devices have different owners

Windows and macOS can share the real-time, on-demand and scheduled concepts while exposing different permissions, quarantine views and file-signature tools. Use the installed product's current help and platform controls. Don't translate a Windows PowerShell or file-Properties step into a Mac command by guesswork.

An ISP or PC-maker bundle may use older branding and menus while still receiving provider support. Confirm the account owner and entitlement before reinstalling retail McAfee; our installation and setup guide explains why the correct account and installer matter. If removal becomes necessary, use the separate McAfee uninstall guide rather than deleting quarantine folders manually.

A work or school device may be managed by Trellix, ePO or another endpoint platform. Don't add local exclusions, restore samples or upload business files without approval. Send the security team the detection, path, hash, signature, source and business impact so they can inspect central telemetry and create a scoped policy decision.

Build an evidence package that McAfee or the publisher can act on

Include the McAfee product and version, Windows or macOS version, detection-data update time, detection name, original path, quarantine time, scan type and result. Add the official source URL, file version, publisher, signature status and SHA-256 hash. State whether the issue occurs during download, install, launch, update or a scheduled scan.

Describe one clean reproduction. “Version 4.2.1 downloaded from the publisher's HTTPS release page; valid Contoso signature; SHA-256 …; quarantined at launch after the July 30 update” is actionable. “McAfee deleted my safe game” doesn't identify the build, event or evidence.

Redact account email, license key, personal folder names, private server addresses and unrelated filenames from screenshots. Never paste a quarantined executable into a forum or send it to an unsolicited support account. Use McAfee's official form and the publisher's verified support channel.

Verify protection, repeat the original task and roll back failed changes

Confirm real-time protection is on, the product is updated and the exclusion list contains only entries you intentionally kept. Repeat the same download, install, launch or scan that produced the event, using the verified clean build. Then restart once and repeat because services and protection policies can change after boot.

If a change didn't solve the problem, undo it before moving on. Remove an ineffective exclusion, return a test firewall rule to its previous state and restore the original scan schedule. This prevents a pile of unexplained exceptions from outliving the incident.

Check the result inside McAfee rather than relying only on the application opening. A file can launch while another component is still quarantined, and a game can start while network protection blocks a child service. Save the final evidence and the reason the case was closed.

Bottom line: quarantine buys time; an exclusion spends protection

Choose a scan that answers the actual question, update before you run it and preserve the result. When McAfee isolates a file, use that pause to verify the exact source, publisher, signature, version and hash. Restore only after the evidence clears the same build.

If the detection appears wrong, submit it through McAfee's official dispute route and wait for the correction or a clean signed release. Keep any temporary exception narrow, documented and short-lived. The fastest safe outcome isn't the one with the fewest clicks; it's the one that restores the required software without creating a permanent blind spot.

For the broader product decision, read our current McAfee review and plans and renewal guide. Those pages cover protection, value and subscription choices; this page remains the operational record for scan scope and file-release decisions.

McAfee scan, quarantine and exclusion FAQ

Should I run a McAfee quick scan or full scan?

Use a quick or short scan for routine checks of common active locations. Use a full scan after a credible compromise, when establishing a first baseline, or when evidence points beyond one known path. A custom scan is usually better for a single download, folder or external drive. Update McAfee first and save the result rather than choosing solely by which label sounds strongest.

What happens when McAfee quarantines a file?

McAfee's archived help describes quarantine as encrypted isolation that prevents the item from harming the PC while you decide what to do. Quarantine isn't the same as permanent deletion, and it isn't proof that the detection was wrong. Leave an uncertain file isolated while you record its detection, path, source, publisher, signature and hash.

Is it safe to restore a file from McAfee quarantine?

Only when independent evidence identifies that exact file as clean. Verify the official source, expected version, valid publisher signature and a SHA-256 hash that the publisher or trusted support channel can confirm. If the source is unknown, the signature is invalid or the evidence conflicts, leave the file isolated and submit the disputed detection instead of running it.

Why does McAfee quarantine a file again after I restore it?

Restoring changes the file's location, not the detection logic. Real-time protection can inspect it again and make the same decision, especially if the file hasn't changed and McAfee's detection data hasn't been corrected. Submit the exact build through McAfee's dispute route, update and rescan; don't race the scanner by repeatedly restoring or disabling protection.

How do I add a file or folder exclusion in McAfee?

First confirm that your current consumer build actually exposes a supported exclusion control and identify which scan scope it affects. Archived McAfee help describes exclusions for custom or scheduled scans, but that wording isn't proof of current real-time behavior. Add only the smallest verified file or dedicated folder, record why it exists and remove it when the vendor supplies a clean or correctly signed build.

Can I exclude Downloads, a game library or my whole drive?

No broad location is a safe default. Downloads, temporary folders, browser caches, email stores, Windows directories and large game or mod libraries receive changing content from many sources, so excluding them creates an attractive blind spot. Fix the source, signature or false-positive classification, or use one narrowly scoped file only when the evidence supports it.

How do I report a McAfee false positive?

Use McAfee's official Detection Dispute and Allowlisting form. McAfee says authorized submitters can send ZIP, RAR or extracted contents and that reviews are generally processed within two business days, although they can take longer. Include the detection name, product version, exact source, publisher, file version and SHA-256 hash, and don't upload private or proprietary data without authorization.

Does a clean full scan prove my computer is safe?

No scan provides that proof by itself. A clean result is useful evidence, but it can miss a new, inactive, encrypted, removed or out-of-scope item and it doesn't explain a browser scam or account compromise. Combine the result with the original symptom, protection history, updates, account and browser checks, and a second trusted opinion when the incident warrants it.