Resource icon

Check a Windows download before you run it

A familiar filename is not proof that a download is safe. Before opening an installer, decide whether you meant to get it and whether it came from the developer's real site or a trusted store. Avoid sponsored search results that imitate a vendor.

Four checks​

  1. Confirm the site's address and the developer's download page. If the file arrived in an unexpected message, do not run it merely because the sender looks familiar.
  2. Right-click the file, open Properties and inspect any Digital Signatures tab. A valid signature helps identify the signer; absence of a signature does not automatically mean malware, and a signature alone does not make software trustworthy.
  3. Let Windows Security scan the file and heed Defender SmartScreen or reputation warnings. Do not bypass a warning until you have independently established why the file is needed and who published it.
  4. If the developer publishes an official checksum, compare it with a hash calculated locally. A match detects a changed file only when you trust the checksum's source.

If something disagrees​

Stop and obtain the download again from the official source. If you already ran an untrusted installer, update your security software, scan the PC and review new apps and browser extensions. Windows app and browser controls describe SmartScreen; Microsoft's Get-FileHash documentation explains hashes. No single check is a guarantee.

If the installer is already open​

Cancel the installer before accepting permissions or disabling protection. If you have already run it, note its exact name and download source, update Windows Security, scan, and review installed apps. For work devices, send the file and its origin to IT rather than testing it yourself.
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack