What I meant was, get the hash of the trusted file yourself (i.e. by downloading from a trusted source), then programatically compare the hash of the downloaded file to the file you checked earlier to see if they match.