A warning on a downloaded installer is information to investigate, not a cue to click Run anyway or to assume every unfamiliar file is malicious. Microsoft Defender SmartScreen checks app and file reputation; Edge also checks sites and downloads. A new legitimate release may have little reputation, while a fake installer can imitate a trusted name. The right response checks source, publisher, signature and threat history before deciding whether to report a false positive or discard the file.
Before you start
Keep the warning visible and do not execute the file. Note the exact URL, filename, size, claimed publisher and download time. Confirm you reached the vendor's domain directly, not through an ad or search-result mirror. If the file came through work, ask the software owner or IT for the approved package.Do it step by step
- Read whether the warning is from the browser, Windows SmartScreen, Smart App Control or antivirus. These mechanisms have different reasons and different safe remediation paths.
- Check Windows Security > Protection history for a malware or potentially unwanted app detection. A named threat requires a more cautious response than a simple low-reputation notice.
- Open file Properties > Digital Signatures where present and compare publisher details with the vendor's site. A missing or valid signature alone does not settle safety.
- Look for the installer and checksum on the vendor's official download page. If the page offers a hash, calculate and compare the downloaded file's hash using a trusted local method.
- If the vendor confirms a legitimate false positive, use Microsoft's reporting route or ask the vendor to submit the file. Avoid turning off reputation protection for the whole PC.
- Delete the file if provenance remains unclear. If you already ran it, disconnect sensitive sessions, update protection, scan and review accounts from a clean device.