Guide

How to Verify SHA-256 on Windows

A SHA-256 hash is a unique fingerprint of a file. If even one byte differs, the hash changes completely. Verifying the hash is the only reliable way to confirm that the file you downloaded matches the one that was published.

Why This Matters

Download mirrors, malicious ads, and network tampering can all serve a modified version of a file. The published SHA-256 hash is the reference point. If your file's hash matches, the file is byte-for-byte identical to the version that was scanned and verified. If it does not match, the file is not what we published — delete it and re-download.

Method 1: PowerShell (Recommended)

This is the fastest method on Windows 10 and Windows 11.

1

Open PowerShell or Windows Terminal

Press Win + X and select Terminal or Windows PowerShell. You do not need administrator rights for this command.

2

Run the Get-FileHash Command

Paste this command, replacing the path with the actual location of your downloaded file:

Get-FileHash "C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe" -Algorithm SHA256

Tip: type Get-FileHash " then drag the file from File Explorer into the PowerShell window. Windows will insert the full path automatically.

3

Read the Output

You will see output like this:

Algorithm       Hash                                                                   Path
---------       ----                                                                   ----
SHA256          A3F5C8E91B2D4F7A6C8E0B3D5F7A9C1E2B4D6F8A0C2E4B6D8F0A2C4E6B8D0F2A   C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe

The hash is the long string in the middle. It is 64 characters long.

4

Compare Character by Character

Compare the output hash to the hash published on the download page. PowerShell output is uppercase; our published hash may be uppercase or lowercase. Case does not matter — the letters and digits must match.

If they match: the file is intact. If they do not match: delete the file and download it again from the CDN link.

Method 2: CertUtil (Built Into Windows)

If PowerShell is unavailable, use CertUtil from Command Prompt.

  1. Press Win + R, type cmd, press Enter.
  2. Run this command, replacing the path with your file's location:
certutil -hashfile "C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe" SHA256

CertUtil prints the hash on the second line of output. Ignore the spaces — the hash is the same 64-character string with spaces inserted for readability.

Example output:

SHA256 hash of C:\Users\YourName\Downloads\wave-executor-NEW-1.5.5.exe:
a3 f5 c8 e9 1b 2d 4f 7a 6c 8e 0b 3d 5f 7a 9c 1e 2b 4d 6f 8a 0c 2e 4b 6d 8f 0a 2c 4e 6b 8d 0f 2a
CertUtil: -hashfile command completed successfully.

Remove the spaces and compare.

Method 3: 7-Zip (Optional)

If you have 7-Zip installed:

  1. Right-click the downloaded file
  2. Select CRC SHA → SHA-256
  3. The hash appears in a small dialog — you can copy it and compare

7-Zip is not required and you do not need to install it just for hash verification.

Common Problems

"The term 'Get-FileHash' is not recognized"

You are running an older version of PowerShell or a non-Windows PowerShell (for example, PowerShell 2.0). Get-FileHash was added in PowerShell 4.0. Update Windows, or use CertUtil instead.

The hash does not match

This means the file is not what we published. Possible reasons:

  • The download was incomplete or corrupted. Re-download the file.
  • You downloaded from a different source. Only use the CDN link on our download page.
  • The file was modified by something on your system (rare, but possible with certain antivirus products).

Do not run the file if the hash does not match. Report it via our contact page.

The file is locked or in use

Close any application that might have the file open, then run the command again.

Long path issues

If the file path contains spaces or special characters, wrap the path in double quotes as shown in the examples above.

What SHA-256 Does Not Tell You

A matching SHA-256 proves the file is identical to the one whose hash we published. It does not prove that the file is safe, that it does what it claims, or that it is free of bugs. It only confirms integrity and source identity.

To understand what the file does and what risks it carries, read our Safety Center.

Related Pages

Download Page

Where the published SHA-256 hash lives.

Download →

Safety Center

Scan results and antivirus flags explained.

Safety Center →

Installation Guide

What to do after the hash matches.

Installation →

Troubleshooting

If something goes wrong after install.

Troubleshooting →