A familiar filename is not proof that a download is safe. Before opening an installer, decide whether you meant to get it and whether it came from the developer's real site or a trusted store. Avoid sponsored search results that imitate a vendor.
Four checks
- Confirm the site's address and the developer's download page. If the file arrived in an unexpected message, do not run it merely because the sender looks familiar.
- Right-click the file, open Properties and inspect any Digital Signatures tab. A valid signature helps identify the signer; absence of a signature does not automatically mean malware, and a signature alone does not make software trustworthy.
- Let Windows Security scan the file and heed Defender SmartScreen or reputation warnings. Do not bypass a warning until you have independently established why the file is needed and who published it.
- If the developer publishes an official checksum, compare it with a hash calculated locally. A match detects a changed file only when you trust the checksum's source.