For the examiners who wish to locate malware in EnCase 6 based on virus signature, I have downloaded the latest VirusTotal database and compiled to an EnCase 6 Hash Set. Note that hashes are MD5 you need to hash your files first. Acknowledgments go to the [VirusTotal](https://www.virustotal.com/) for making available the files. Use this [link for download](https://docs.google.com/file/d/0B4_fd9ATmJuOLUhVTnM5V3A4TFk/). Hash Set contains more than 18 millions of hashes.