VirusTotal + HerdProtect - Check Files with Simultaneously

Page 3 of 3 FirstFirst 123

  1. Posts : 57
    Primary OS: Archlinux with Kde-Plasma5 x86-64. Secondary OS: Windows 8.1 x64. UEFI Setup.
       #20

    Tiny code update to my own script on 'Post 6' to be able to process paths like 'Program Files (x86)' by using also 'EnableDelayedExpansion' in the main part.
    Script will not be able to read files or paths using '!', but that is less important than every special character breaking the script.

    Have a good day ^^.
      My Computer


  2. Posts : 76
    Windows 7 64bit
       #21

    Has something changed or is my PC having a hissy fit of some description. Tried to check a couple of files this morning only to be greeted with the following:

    Code:
    ***** VIRUSTOTAL *****
    e:\users\butters\desktop\f5 stuff\cfgwkst.pdf:
            Verified:       Unsigned
            File date:      12:16 30/08/2016
            Publisher:      n/a
            Company:        n/a
            Description:    n/a
            Product:        n/a
            Prod version:   n/a
            File version:   n/a
            MachineType:    n/a
            VT detection:   0/53
            VT link:        https://www.virustotal.com/file/ce3cf51eef902276ab6e0e05
    583a5945d0aa7ad54abb3042270a45e5c6afa2a4/analysis/
    ***** HERDPROTECT *****
            Unknown file
    
    Press any key to continue . . .
    Tried it with another pdf file and a couple of other random files as well with similar results.
      My Computer


  3. Posts : 57
    Primary OS: Archlinux with Kde-Plasma5 x86-64. Secondary OS: Windows 8.1 x64. UEFI Setup.
       #22

    The scripts in this thread do not send/scan files.
    What these scripts do, is lookup the database of Virustotal and Herdprotect (AKA Check Files).

    For Virustotal, the program 'sigcheck.exe' is used to lookup.
    For Herdprotect, the SHA1 hash is used to download the HTML page. After downloading, the page is read and used.
    If the HTML page does not contain a line containing the text 'Scanner detections:', the file was never identified before.

    PDF's, Images, etc usually do not contain alot of metadata info. That is why you see alot of N/A on these tags, this does not affect the lookup though.

    If the script were to send every file to the server, the checks might take long time and unless their server rejects already scanned files, they might be spammed from repeated continuous file uploads.
    Else I could have make it 'optionally' send unknown files through my script, if i know how to. That way It can contribute to increasing the database of Herdprotect :3.


    If in doubt still, I recommend try my script in post #6. Mine is more functional and you might have more luck with it.

    Unrelated: Hey Tookeri, after more than a year of leaving alone, my script still works .
    Last edited by Midori; 29 Sep 2016 at 15:35.
      My Computer


 
Page 3 of 3 FirstFirst 123

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:03.
Find Us