查看: 1911|回复: 5
收起左侧

[分享] VT Hash Check v0.8 - 有右键的VirusTotal Uploader

[复制链接]
andylau
发表于 2010-8-9 10:52:42 | 显示全部楼层 |阅读模式
http://boredomsoft.org/index.bs?page=VT+Hash+Check

VT Hash Check adds a Windows Explorer context menu item to compute the MD5 hash checksum of any file and to then send that checksum to http://www.virustotal.com for checking against their Virus database.
Download|GPG Sig (?)





Current VersionThe most current version of VT Hash Check is 0.81 Beta (Last update: 7/30/10).

Files Included in the Download
  • setup.exe - Program Installer
  • ReadMe.txt - ReadMe File
  • License.txt - License

InstallationExecute the included setup.exe file to install.

IssuesNone Reported.

Command Line Parameters
  • !about
    • Show the "About" Window
  • !SHA1
    • Use the SHA1 algorithm (see Further Notes, below)

Further NotesBy default, only the MD5 hash is computed. The MD5 hash algorithm is vulnerable to theoretical collisions and has been recommended to be avoided for cryptographic functions requiring a high level of security1. While this theoretical vulnerability may represent a deficiency in the operation of this particular program, I don't feel that it should cast any doubt onto the results returned by the program via Virus Total. Nevertheless, for those of you interested in using a theoretically superior hash function, I have included the option to use the SHA12 hash function instead.
To invoke the SHA1 option, you may pass the program the !SHA1 argument before the file path like this:
        VTHash.exe !SHA1 C:\somefile.exe
If you prefer for SHA1 to be the default, create a file called "usesha1" (sans quotes) in the installation directory (by default: C:\Program Files\Boredom Software\VT Hash Check):

When attempting check the hashes of executable files obtained from the Internet, users are likely to see a warning similar to this one:

This warning is generated by Windows whenever an executable file launched if the executable was downloaded from an untrusted network source (i.e. the Internet) and saved on a drive formatted in NTFS. Windows uses a special alternate data stream to mark the file as "untrusted" and prompts the user any time the file is about to be opened, even if the act of opening it is only to read the data therein.
VT Hash Check does not actually launch or execute any file processed through it. It reads the data from the file, computes the hash based on the data, and then closes it. The data is treated the same way whether the file being hashed is an executable or and image or a text file.
However, I am not a computer security expert. I cannot guarantee that the program is immune to attack, error, etc.

                        
好处是可以直接在档案右键,方便很多呢,而且还有命令行参数可用呢
P.S. 如有错区,麻烦版大移一下
zhangxujian11
发表于 2010-8-9 11:10:37 | 显示全部楼层
这个是用来上传到virustotal的?
andylau
 楼主| 发表于 2010-8-9 11:12:53 | 显示全部楼层
这个是用来上传到virustotal的?
zhangxujian11 发表于 2010.8.9 11:10



當然是啦
oyd2008
发表于 2010-8-9 12:59:47 | 显示全部楼层
希望能翻译成中文,我看了半天还没看懂啊
lz能好好介绍下吗
悠柚
发表于 2010-8-9 13:59:14 | 显示全部楼层
回复 4楼 oyd2008  的帖子


    很简单的,只要有可疑文件就右键check file hash,程序就会比对服务器里德hash信息,如果别人已经扫描过了,就直接显示结果,如果别人没有用vt扫描过就上传到vt的网站进行扫描
CiX
发表于 2010-8-9 14:30:54 | 显示全部楼层
这个很像VirusTotal Uploader。。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-4 03:01 , Processed in 0.127082 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表