What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Windows 11 can warn about a download for several reasons: the file may be unsigned, new, from an unfamiliar site, marked as coming from the Internet, or blocked by an administrator. A warning is not proof that a file is malicious, but it is a reason to stop and verify it before opening it.
To assess a download, verify its source and file type, scan it, and check its signature and download-origin status. Keep SmartScreen enabled, and do not bypass a warning unless you have independently verified the file.
What “trusting a download” actually means
There is no single Windows 11 command that declares a file safe. A sensible trust decision combines several checks:
| Check | What it tells you | What it does not tell you |
|---|---|---|
| Download source | Whether the file came from the vendor or an expected contact | Whether the source itself has been compromised |
| Microsoft Defender scan | Whether the antivirus engine detects known or suspicious content | That a clean result guarantees safety |
| File type | Whether the file is what you expected to download | Whether an executable is safe to run |
| Digital signature | Who signed the file and whether it changed after signing | Whether the signer is reputable or the file has good SmartScreen reputation |
| SmartScreen | Whether Microsoft has enough reputation information about the website, publisher, or file hash | That every warning means malware |
| Mark of the Web | Whether Windows recorded that the file came from the Internet or another untrusted location | That removing the marker makes the file safe |
SmartScreen considers both publisher reputation and the specific file hash. A new, legitimately signed application can therefore display an “unrecognized app” warning until it builds enough clean download history. Conversely, a file without a warning still deserves normal security checks.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
Step 1: Confirm where the file came from
- Identify the publisher or person who supplied the file.
- Navigate to the publisher’s website by typing the address yourself or using a known bookmark. Do not rely solely on an advertisement, a pop-up, or a search result that resembles the official site.
- Compare the product name, version, file name, and file type with the vendor’s instructions.
- Be especially cautious with unexpected email attachments, files sent through messaging apps, cracked software, key generators, and “urgent” updates.
Microsoft recommends verifying the source, scanning the file, confirming that its type matches what you expected, and avoiding files from unknown senders.
Step 2: Keep SmartScreen enabled
Microsoft Defender SmartScreen checks websites and downloads in Microsoft Edge and contributes to Windows’ reputation-based protection. Do not turn it off merely to make an installer run.
Check SmartScreen in Edge
- Open Microsoft Edge.
- Select Settings and more (…) in the upper-right corner.
- Choose Settings.
- Open Privacy, search, and services.
- Under Security, verify that Microsoft Defender SmartScreen is turned on.
Check Windows’ central protection settings
- Open Windows Security from the Start menu.
- Select App & browser control.
- Open Reputation-based protection.
- Check the status of Check apps and files. This controls SmartScreen evaluation of apps and files downloaded from the web.
- Also check SmartScreen for Microsoft Edge, which controls Edge-specific website and download checks.
If SmartScreen displays a warning, read it and investigate the file rather than immediately selecting a bypass option.
Step 3: Scan the download before opening it
- Locate the downloaded file in File Explorer, normally in Downloads.
- Right-click it and choose Show more options if necessary.
- Select Scan with Microsoft Defender or the equivalent Microsoft Defender scan option.
- Wait for the scan result before opening the file.
A scan is particularly important for executable files such as .exe, .msi, and .scr files, and command or script files such as .bat, .cmd, .js, .vbs, and .ps1 files. Treat archives such as .zip and .7z carefully because they can contain another file that Windows evaluates only after extraction.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →If Defender detects a threat, do not use an “Unblock” action or disable protection to force the file to run. Quarantine or remove the file and obtain a clean copy from the verified publisher.
Step 4: Check the file’s type and name
Malware sometimes relies on misleading names such as invoice.pdf.exe. In File Explorer, enable extensions so the final extension is visible:
Rank #2
- Open File Explorer.
- Select View > Show > File name extensions.
- Inspect the complete name, not just the text before the final dot.
Do not assume that a PDF, image, or document is harmless. A file that claims to be a document but ends in an executable extension deserves additional scrutiny.
Step 5: Check whether Windows marked the file as downloaded
Windows commonly adds a Mark of the Web (MOTW) to files obtained from websites, email, messaging applications, another computer, or restricted locations. This origin information can trigger warnings or additional protection in Edge, Windows, and Microsoft Office.
Use the Properties dialog
- Open File Explorer and locate the file.
- Right-click the file and select Properties.
- Stay on the General tab.
- Look at the bottom for a security message stating that the file came from another computer and might be blocked.
- Only if you have independently verified the source, select Unblock.
- Select Apply, then OK.
Important: Unblock removes the download-origin block; it does not scan, authenticate, or certify the file. Use it only for a file from a source you trust. Removing MOTW can also change how Microsoft Office handles active content and macros.
Inspect MOTW with PowerShell
To display a file’s Zone.Identifier stream in Notepad, open PowerShell and run notepad “C:\Path\file.exe:Zone.Identifier”, replacing the example path with the file’s actual path. Notepad displays the file’s [ZoneTransfer] section and its ZoneId, when the alternate data stream exists. The relevant mappings are:
| ZoneId | Meaning |
|---|---|
| 0 | My Computer |
| 1 | Local intranet |
| 2 | Trusted sites |
| 3 | Internet |
| 4 | Restricted sites |
The PowerShell equivalent of selecting Unblock in Properties is Unblock-File -LiteralPath “C:\Path\file.exe”. This removes the ZoneId value; it does not prove that the file is safe. Use it only after checking the source, type, and antivirus result.
Step 6: Verify the digital signature
A digital signature can identify the signer and show whether the file was altered after signing. It is useful evidence, but it is not the same thing as SmartScreen reputation. A signed file can still be new and unrecognized; an unsigned file is not automatically malware.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesCheck a signature in File Explorer
- Right-click the file and select Properties.
- Open the Digital Signatures tab.
- Select a signature in the list and choose Details.
- Confirm that Windows reports the signature as valid and inspect the signer name.
If there is no Digital Signatures tab, the file may be unsigned. Some file types do not expose signatures in the same way, so use PowerShell when appropriate.
Check Authenticode with PowerShell
Run this command with the full path to the file: Get-AuthenticodeSignature -FilePath “C:\Test\NewScript.ps1”.
Review the Status and SignerCertificate fields. For an unsigned file, PowerShell returns a signature object but its signature fields are blank. Use -LiteralPath when the path must be interpreted exactly as typed, for example: Get-AuthenticodeSignature -LiteralPath “C:\Downloads\release[1].exe”.
-FilePath allows wildcards only when they resolve to a single file. If a file has both an embedded signature and a Windows catalog signature, Windows uses the catalog signature.
Recommended Free Tools
Why a signed file can still show a SmartScreen warning
SmartScreen reputation is separate from signature validation. Microsoft’s current behavior means a valid OV or EV code-signing certificate may still produce a warning until reputation accumulates, although the verified publisher name can be displayed. An unsigned or self-signed file generally starts with little or no useful reputation for each new version.
The old advice that an EV certificate automatically bypasses SmartScreen is outdated. Microsoft states that EV certificates no longer bypass SmartScreen. A publisher should not purchase an EV certificate solely to eliminate these warnings.
Rank #4
- Windows 11's new user experience, from reworked Start menu and Settings app to voice input
- The brand-new Windows 365 option for running Windows 11 as a Cloud PC, accessible from anywhere
- Major security and privacy enhancements that leverage the latest PC hardware
- Expert insight and options for installation, configuration, deployment, and management – from the individual to the enterprise
- Getting more productivity out of Windows 11's built-in apps and advanced Microsoft Edge browser
There is no published reputation threshold. Microsoft says clean download history can eventually reduce warnings, and that accumulation may take several weeks and hundreds of clean installations across a broad audience.
When Smart App Control blocks the file
Windows 11 may also use Smart App Control, which is separate from ordinary SmartScreen prompts. Find it at Windows Security > App & browser control > Smart App Control settings.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Its modes are:
| Mode | Behavior |
|---|---|
| Evaluation mode | Windows evaluates whether the feature is suitable for the device. |
| On | Untrusted applications can be blocked. Microsoft’s prediction model and valid signatures help determine what can run. |
| Off | Smart App Control is disabled. |
Smart App Control can block a legitimate unsigned or untrusted application. Unlike a normal warning, there may be no “Run anyway” route. It works alongside Microsoft Defender or a third-party antivirus product.
There are two important limitations. Smart App Control is restricted to new Windows 11 installations; if it arrived through an update on an existing installation, enabling it may require resetting or reinstalling Windows. Also, after evaluation finishes or you manually switch it on or off, returning to Evaluation mode normally requires a reset or reinstall.
Office files: don’t confuse “Enable Editing” with trust
Downloaded Word, Excel, and other Office files may open in Protected View. They can be read-only, have editing disabled, or have macros and other active content disabled.
Older Office warning banners may show Enable Editing or Enable Content. Microsoft’s newer SECURITY RISK banner for files from the Internet may block macros without offering an Enable Content button.
Do not remove MOTW just to activate a macro unless you have verified the document and understand what the macro does. Office Trusted Locations bypass MOTW macro checks, so use them sparingly. Network locations can be configured as Trusted Locations, but Microsoft does not recommend that arrangement. A Windows-wide trusted publisher setting can also affect scenarios beyond one Office application, so do not add a publisher casually.
Best Value
What to do when “Run anyway” is missing
The bypass option may be unavailable because of Smart App Control, Group Policy, Microsoft Defender settings, SmartScreen policy, or file-attachment policies. This is common on business and school computers. Do not try to work around an organization’s control without approval from its administrator.
If a known-safe file continues to trigger warnings, work through these possibilities:
- Install pending Windows and application updates.
- Download the file again in case the first copy was corrupted.
- Compare its checksum with one published by the vendor, if available.
- Ask whether an organizational policy is blocking it.
- Check whether a third-party download manager or security product is interfering.
- Contact the publisher for a current, properly signed installer.
Microsoft lists temporarily disabling a third-party download manager or security product only as a troubleshooting test. Do not leave protection disabled, and do not use this as the normal method for running a questionable file.
A practical decision checklist
| Situation | Recommended action |
|---|---|
| Official source, expected file type, clean Defender scan, valid signature | Usually reasonable to run, while still reviewing the installer’s requested permissions. |
| Official source but new signed file with an unrecognized-app warning | Confirm the publisher, scan it, verify the signature and checksum if offered, then decide whether the warning is consistent with a new release. |
| Unknown source, unexpected attachment, or misleading extension | Do not run it. Obtain the file through a verified channel. |
| Unsigned file from a trusted developer | Ask why it is unsigned and verify it through another channel; a trusted source does not remove the risk. |
| Defender detects malware | Stop, quarantine or remove the file, and contact the source through a known address. |
| Smart App Control blocks it and no bypass exists | Do not disable Windows protection merely to run it. Find a signed or Microsoft-approved version. |
What not to do
- Do not disable SmartScreen globally because one installer is new.
- Do not treat a digital signature as a guarantee that the software is honest or harmless.
- Do not select Unblock before verifying the source and scanning the file.
- Do not enable Office macros in an Internet-downloaded document just to view its contents.
- Do not assume a missing warning means the file is safe.
- Do not install cracked software or tools advertised as ways to bypass Windows security.
FAQ
Does a SmartScreen warning mean the download is malware?
No. It means Windows does not have enough reputation information about the website, publisher, or specific file hash, or that the file has other risk indicators. A new signed file can still trigger a warning. Verify the source, scan the file, check its type, and inspect its signature before deciding.
Should I click Run anyway?
Only after independently verifying the file’s source, expected type, antivirus result, and signature. If the source is unknown or the file was unexpected, do not bypass the warning. On some systems, organizational policy or Smart App Control removes the option entirely.
Does Unblock make a Windows 11 download safe?
No. Unblock removes the Mark of the Web download-origin block. It does not authenticate the publisher or replace an antivirus scan. Use it only for a file from a source you have already verified.
How do I check whether a file has Mark of the Web?
Right-click the file in File Explorer, choose Properties, and inspect the bottom of the General tab for the security message. You can also run notepad “C:\Path\file.exe:Zone.Identifier” in PowerShell or Command Prompt and inspect the ZoneId.
Is a digitally signed file safe?
A valid signature identifies the signer and helps confirm that the file has not changed since signing. It does not prove that the signer is reputable, that the software is free from vulnerabilities, or that SmartScreen will trust the file.
Why is Enable Content missing in Office?
Microsoft’s newer SECURITY RISK banner for files from the Internet can block macros without offering an Enable Content button. This is different from older SECURITY WARNING banners. Do not move an unverified document to a Trusted Location just to bypass the protection.
The Bottom Line
Trust a Windows 11 download through evidence, not through a single button: use the publisher’s real site, confirm the extension, scan the file, check its signature, and understand its Mark of the Web status. Keep SmartScreen and Microsoft Defender enabled. If the file remains questionable—or Smart App Control blocks it—find a verified, signed replacement instead of weakening Windows security.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

