The total amount in mb is one factor,they must match exactly.
You can also go to run,type:SigVerif Advanced,then have it run
the diffrent apps.thru it.
If you've installed the Microsoft root certificate, you can check the
signature of the file... this will verify that the file is from Microsoft,
and that it has not been altered since originally signed. To check this,
right-click on the file, select "properties," "digital signature," and click
on "details." And sit back... 'cause it may take a while (as long as 10-20
minutes, depending on CPU speed, available memory, etc.) to verify that the
signature is valid.