As of May 14, 2024, Knowledge Base (KB) articles will only be published and updated in our new Trellix Thrive Knowledge space.
Log in to the Thrive Portal using your OKTA credentials and start searching the new space. Legacy KB IDs are indexed and you will be able to find them easily just by typing the legacy KB ID.
Technical Articles ID:
KB55986
Last Modified: 2022-05-02 09:59:28 Etc/GMT
Environment
V2 DAT Files
Extra.DAT files
McAfee Labs (AVERT)
DAT Reputation
Summary
This article is a consolidated list of common questions and answers. It's intended for users who are new to the product, but can be of use to all users.
Recent updates to this article
Date
Update
May 2, 2022
Minor formatting updates; no content changes.
March 23, 2021
Updated the FAQ "What are the CommonUpdater Repositories?" in the "CommonUpdater" section to include the HTTPS URLs.
January 11, 2021
Added the FAQ "Does McAfee release DAT files on holidays?" in the "General" section.
To receive email notification when this article is updated, click Subscribe on the right side of the page. You must be logged on to subscribe.
Contents
Click to expand the section you want to view:
What are DAT files?
Virus definition or DAT files contain signatures and other information that our antivirus products use to protect your computer against existing and new potential threats. DAT files are released regularly. To make sure that your antivirus software protects your system against the latest threats, always use the most recent DAT files.
What products use DAT files?
The following products use the Scan Engine and DAT files:
Advanced Threat Defense
Endpoint Security for Linux before 10.7.0
Endpoint Security for Mac before 10.7.0
Management for Optimized Virtual Environments
SaaS Endpoint Protection
Security for Lotus Domino
Security for Microsoft Exchange
Security for SharePoint (PortalShield)
SuperDAT Manager
VirusScan Command-Line Scanner
VirusScan Enterprise (VSE)
VirusScan Enterprise for Linux
VirusScan Enterprise for Storage
VirusScan for Mac
Web Gateway
What integrity and validity checks are performed on the DAT files to make sure that they aren't tampered with?
The DAT files are encrypted and then compressed and signed when they're compiled. The Scan Engine performs a signature verification on the DATs as an integrity check during initialization. The Scan Engine doesn't load the files if they've been modified. The products that use the Scan Engine then verify the integrity of the Scan Engine by verifying whether the digital certificate used to sign the Scan Engine is valid.
Does the DAT perform any proactive detection for scanning of malformed archives?
Our products can handle specific types of malformed archives. Malformed archives cause the Scan Engine to be unable to scan within the archive. This ability enables the products to detect the presence of a bad archive without having to open it. The detection is reported as Malformed Archive.
We continue to refine our detection techniques to tackle the many types of malformed archives that can be created. We also continue to focus on making sure that customers receive maximum protection and providing a rapid response to potential vulnerabilities.
Why does McAfee Labs release regular DAT files?
There has been an exponential rise in the number, propagation rate, and prevalence of new threats. The same applies to the number of virus submissions, rate of new malware development, and number of emergency DAT releases. The growing number and variety of threats make it vital that you update your DAT files regularly.
At what time during the day are DAT files made available?
The regular DAT files are generally available on the day of release at19:00 (UTC/GMT). But, DAT files might be released earlier if a new threat warrants it. To receive alerts regarding delays or important notifications, subscribe to the Support Notification Service (SNS). For SNS details, see KB67828 - Support Notification Service Frequently Asked Questions.
Do you release DAT files on holidays?
We release DAT files on holidays, except for January 1 and December 25. If needed, emergency DAT files are issued on these days.
When should I schedule an automatic update of my system with the regular DAT files?
We recommend that you schedule a daily pull task within a 4–6 hour interval from the time the DAT files are made available to the source repository. This schedule allows enough time for the DAT file to replicate on all our servers globally. See the ePolicy Orchestrator (ePO) product guidefor details.
Where can I find the latest DAT files?
The latest DAT files are available from the Security Updates page in XDAT and SDAT format at the Enterprise Product Downloads page. This site also provides access to Beta DAT files.
What's the difference between regular DAT files and Beta DAT files?
DAT files are released regularly and go through a full QA cycle. Beta DAT files are produced hourly and receive only limited false positive testing. We recommend that you use the following:
Regular DAT files for desktop deployment
Beta DAT files for high-risk computers and perimeter products such as GroupShield.
What's the difference between normal DAT files and runtime DAT files?
Each file has its own advantage:
Normal DAT files: Normal DAT files are simple in format with optimization designed for downloads of regular incremental files (signatures). A priority for downloading the normal DAT updates is to use as little bandwidth as possible. But, it's not well optimized for local performance. Advantage: Faster download
Runtime DAT files: The runtime DAT file is optimized for high local performance. It's a rebuild of the normal DAT files, so that the memory and CPU resources needed to operate are balanced for best performance. Advantage: Faster system
Under what circumstances do emergency DAT releases happen?
Outbreaks sometimes require emergency releases. Emergency DAT releases generally ship around 19:00 GMT. But, they might be released earlier or later in the day if a new threat warrants it. When a DAT is released early to preempt a potential outbreak, there's generally no second DAT release that day, unless another emergency situation occurs.
Where can I find the regular DAT Release Notes?
The regular DAT Release Notes are available at the Threat Centre.
In what format are the regular DAT Release Notes provided?
The DAT Release Notes are web-based and offer the option to be emailed as a link or printed.
When are the regular DAT Release Notes published?
The Release Notes are available about two hours after the release of the regular DAT posting.
What's DAT Reputation?
DAT Reputation is an endpoint technology that contacts the GTI Cloud before an endpoint DAT update. The call-back component checks the reputation of a DAT package before it installs the update. Also, an endpoint safety pulse component runs periodically on a Microsoft Windows endpoint. The safety pulse checks for potential product or operating system issues that have occurred since the installation of a DAT update package. Data collected from the endpoint safety pulse tests are transferred back to McAfee Labs and monitored for anomalies. If a significant problem is found with a DAT package after it has been released, it's tagged as Blocked in the GTI Cloud so that endpoints don't install the DAT.
Will I be contacted using SNS if there's a problem found with the current DAT?
Yes. Our Incident Response procedures are invoked if we find a significant problem with a DAT. We recommend that all corporate customers register for SNS.
Which products can use DAT Reputation?
DAT Reputation is available for all supported products on Microsoft Windows that update using a DAT. The minimum supported McAfee Agent (MA) version for DAT Reputation is MA 4.6.
What happens if my endpoints update using ePO?
The endpoints call the GTI Cloud individually in case a problematic DAT is already downloaded to a local repository.
What are the system requirements for DAT Reputation?
DAT Reputation has been tested with Windows Vista and later. The recommended system requirements are as follows:
Processor
Minimum: Pentium class processor
Recommended: Pentium IV class processor or higher
Physical RAM
Minimum: 512 MB
Recommended: 1 GB or greater
Where are the DAT Reputation files installed?
DAT Reputation files are installed to the following locations:
Where do I download DAT Reputation?
DAT Reputation is installed as part of a standard DAT update. Customers can elect to download DATs that contain DAT Reputation for about six months. After six months, a full AutoUpdate is downloaded.
New health check content might be added later if further diagnostic tests are needed. Health check content is also delivered as part of a standard DAT update. Customers are notified through SNS as to when new health check content is going to be deployed.
What's the increase in download size when DAT Reputation is installed?
The update size is about 1 MB, in addition to the size of the standard DAT content.
Do updates fail if my endpoints can't connect to the GTI Cloud?
DAT Reputation doesn't block updates if the endpoint can't make a connection to the GTI Cloud.
Does DAT Reputation work in an environment using proxy servers?
Yes. DAT Reputation works if the endpoint can communicate on port 443 using SSL over TCP. DAT Reputation supports the following proxy servers:
Basic proxy
NTLM
LDAP
Proxy without authentication (Transparent Proxy)
NOTE: Kerberos authentication isn't currently supported.
What type of data is collected when checking the DAT Reputation?
The DAT version number and the DAT type (V2, V3, or MED) are securely transmitted to verify the reputation of the DAT file. No additional information about the endpoint is uploaded.
What type of data is collected during the endpoint safety pulse health check?
The only data collected are the results of a few tests being run on the endpoint following a DAT download. These results contain data such as the following:
Whether a test passes or fails.
Metadata about the endpoint. For example, the operating system name and version, DAT and engine versions, and product versions that are installed.
IMPORTANT: No personally identifiable information is collected or transmitted.
Why is this data collected?
This data helps us determine whether the recently downloaded DAT behaves as expected. It also provides value to the security of your endpoint.
How frequently does the health check component run on an endpoint?
The health check component runs between 6–8 times per day.
What size are the data packets sent for the DAT Reputation check and health check data?
About 200 bytes of data for a reputation check. Also, between 1–2 kilobytes of data are transferred per instance of health check data.
How is the health check data encrypted and transferred?
The data is encrypted using SSL and transferred using SSL over TCP, which uses port 443.
How is the health check data stored?
The data is stored and secured on our back-end databases.
Which domain does DAT Reputation connect to?
It connects to datreputation.gti.mcafee.com and datreputation.mcafee.com.
Do endpoints that can't connect to the internet try to use DAT Reputation?
You can configure endpoints on closed or limited networks to disable the DAT Reputation check and endpoint safety pulse. But, in the unlikely case of a bad DAT update, these computers must have their update tasks disabled by an administrator. An ePO extension is provided for policy management and reporting. Customers with unmanaged endpoints can contact Technical Support for more information about how to configure DAT Reputation settings. For details, see the "Related Information" section below.
NOTE:McAfee does not recommend that you disable DAT Reputation unless needed.
Who can I contact if I have more questions or ideas for a future release of DAT Reputation?
Contact your Technical Support representative. For details, see the "Related Information" section below.
What's an XDAT?
XDAT is an application that you can double-click to start from Windows. It shuts down any active antivirus scans, services, and other memory-resident software components that might interfere with your updates. It then copies the new files to the needed location and enables your antivirus software to use the update immediately. XDAT files contain virus definitions without the Scan Engine.
How do I recognize an XDAT file?
The file has a name in the formatnnnnXDAT.EXE, where nnnn is the DAT version number. The regular XDAT file includes the DAT files plus an executable that installs the files. We don't support running an XDAT with non-Administrative permissions. For more information about XDAT files, see these Release Notes.
What's an Extra.DAT file?
An Extra.DAT file is a temporary definition file in response to malware that's not yet covered in the regular DAT files. The Extra.DAT file provides emergency coverage until detection for the new malware is added to the regular DAT files. You must apply an Extra.DAT file to the infected system and any systems that can potentially be compromised.
What's a custom DAT package?
A custom DAT package is a temporary detection file created by McAfee Labs. It contains the full production DATs and other detections. It contains cleaning for a new threat that's too complex to be addressed in an Extra.DAT. See KB76657 - How to use custom DATs.
Is an Extra.DAT file still available when emergency releases happen?
Yes. Extra.DAT files are still available from McAfee Labs. They're made available for download for threats that reach a medium-risk assessment or higher. Also, you still receive an Extra.DAT file for any new samples submitted to McAfee Labs.
How safe are Extra.DAT files?
Extra.DAT files are released after limited testing and are provided to address only a specific threat. When you have to deploy an Extra.DAT file to more than a few nodes, we recommend that you test the Extra.DAT on a subset of these nodes before you deploy to all systems. After you verify that there's no problem with the Extra.DAT file, you can deploy it to the remaining nodes.
How long can I use my Extra.DAT file?
The standard expiration for an Extra.DAT file is 30 days, but the expiration varies. Detection in an Extra.DAT file automatically expires when the date embedded in the regular DAT files is the same as or later than the expiration date of the detection in the Extra.DAT file.
How many Extra.DAT files can I use?
You can have only one Extra.DAT file active on a computer at any time. You can combine multiple Extra.DAT files to provide protection for multiple new threats. For instructions, see KB68061 - How to combine multiple Extra.DAT files.
How do I apply an Extra.DAT file?
To apply an Extra.DAT file locally, see the following:
How does an Extra.DAT file relate to the DAT file?
Detection in an Extra.DAT file takes precedence over detection in the standard DAT files. If the remediation method of an Extra.DAT file differs from the method of the standard DAT file, the method specified by the Extra.DAT file is used.
Why are Extra.DAT files removed from a system, and what determines when an Extra.DAT file is removed?
The removal of an expired Extra.DAT file is determined by comparing the expiration date of the detection in the Extra.DAT file to the date embedded in the applied DATs. The Extra.DAT file is removed when the Scan Engine loads the DAT. If the embedded date of the DATs is equal to or greater than the expiration date of the detection in the Extra.DAT file, the Scan Engine sees the detection in the Extra.DAT file as expired.
Example: On May 11, 2020, you run a DAT from May 8, 2020, and your Extra.DAT file expires on May 9, 2020. The Scan Engine continues to use the Extra.DAT file until the DATs are updated to the DAT from May 9, 2020, even though the date is May 11, 2020.
What's the difference between the CommonUpdater and CommonUpdater2 sites?
The CommonUpdater2 download site doesn't have a copy of the DAT files in its root folder.
What are the benefits of the CommonUpdater2 download site?
If you have no products installed that look for DAT content in the root directory of the site, you can select the CommonUpdater2 site for bandwidth benefits because fewer files need to be replicated.