A pirated .iso already modifies the data from the official release because it has to break the activation code somehow. Thus, you can't check it against any official hash. From there, the best you can hope for is to find a "canonical" hacked version and check against that, but since most people aren't really capable of breaking protections, they'll trust whatever shows up on the pirate bay.
Most pirated ISOs I've seen aren't activation-cracked. I've had to download a few legitimately for systems that only came with a 'recovery partition', and whose hard drive failed or needed upgrading. I try to only download 'legit' ISOs (OEM or regular), or at least ISOs that look legit. It would be nice if I had some way of verifying them against each other to see if they've been modified.
Then it is your decision whether to buy a license or download an activator (which you can download after installing all the antivirus programs in the world)
Not always. The most common and reliable piracy channel for Windows 7 right now is by updating your BIOS with a SLIC signature, and then installing Windows as a valid OEM copy. The installation ISOs can be SHA1 and MD5 hash checked against the same versions given out on Microsoft's TechNet site, because it's the same disk required to install any version of Windows 7.
Granted, flashing your BIOS with random binaries floating around the internets is just as bad, if not worse, than installing random pirated binaries, but it's a lot easier* to check whether or not a 512KB dump is exactly the same as the version given out by the manufacturer's site with the exception of a section of non-executable address space than it is to check to see if the only modifications to a 4.2GB ISO are on activation-related components.