Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check the download’s source, heed browser and Windows warnings, and scan it with up-to-date security software before opening or running it. If you can, verify its digital signature. None of these checks proves a file is harmless; if the evidence still leaves you unsure, do not run it.

1. Check where the file came from

Prefer the software publisher’s official website or a trusted app store. Check the web address carefully: a familiar name in a page or file name does not establish that the site is genuine. Be especially cautious with shortened links, lookalike sites, and attachments you did not expect.

An attachment can be risky even when it appears to come from someone you know. If you were expecting it, confirm through a separate trusted channel that the person sent that specific file. CISA advises caution with email attachments and recommends scanning internet downloads before execution in its Malware Analysis Report.

2. Take browser and Windows warnings seriously

Do not dismiss a warning simply because you expected to download a program. Microsoft Defender SmartScreen uses reputation information to warn about potentially unsafe sites and applications, including downloads without established reputation. A new or uncommon program may be unfamiliar rather than malicious, but that uncertainty is a reason to verify the source—not to bypass the warning. See Microsoft’s SmartScreen overview.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On Windows 10 and Windows 11, Attachment Manager can record where a file came from and may warn that it could be unsafe or prevent it from opening. Treat that prompt as a signal to pause and check the file rather than as an obstacle to override. Microsoft explains this behavior in its Attachment Manager guidance.

3. Scan the file before opening or running it

  1. Update your security software. Make sure its protection and detection information are current.
  2. Scan the downloaded file. Use your installed security software’s scan option before opening or executing the file. CISA recommends scanning internet downloads before execution in its malware analysis report.
  3. Act on detections. If the scan flags the file, follow the security software’s quarantine or removal guidance; do not restore or run it just to see what happens.

A clean scan means the current scanner did not detect a threat. It does not prove the file is safe: scanners can miss new, modified, or evasive malware. Use the result alongside the source, warnings, and signature information.

4. Verify the publisher’s digital signature

For a Windows file, you can inspect its signature in the file’s Properties, or use Microsoft Sysinternals’ Sigcheck to view signature and certificate-chain details. Check that the signer is the publisher you expected and that the signature verifies. Microsoft documents Sigcheck version 2.91, published February 4, 2026, on its Sigcheck page.

A valid signature provides information about who signed the file and whether it has changed since signing. It does not establish that the software is safe for every use or that the publisher is trustworthy. An unsigned or unfamiliar file is not automatically malicious, but it gives you less identity information to rely on.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Use online scanning without exposing sensitive files

Online services can add reputation or analysis information, but consider privacy before submitting a file. If a file’s hash is already known, a hash lookup may let you check for an existing reputation without uploading the file. Microsoft Sigcheck supports VirusTotal hash queries; uploading a file is a separate option that must be explicitly enabled.

Do not submit personal, confidential, or work files to a public scanning service unless you have checked its terms and are permitted to share the file. VirusTotal describes a separate Private Scanning feature: submissions and reports are restricted to the user’s organization and are deleted after a retention period usually set to 24 hours. Private Scanning does not provide antivirus verdicts, so it is not equivalent to a public malware scan.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Decide whether to keep or discard the download

Use the checks together rather than treating any single one as a verdict:

Check What it can tell you What it cannot prove alone
Source and context Whether the route and publisher match what you intended That a familiar brand name or sender guarantees the file is genuine
Browser or Windows warning Whether a site or file is reported, unfamiliar, or lacks established reputation That no warning means the file is harmless
Local security scan Whether the current scanner detects a known or suspected threat That a clean result means there is no malware
Digital signature Signer and signature or certificate information That a signed file is necessarily benign
Online scanner Additional reputation or analysis results That consensus guarantees safety or that uploading is always privacy-safe

If the source is doubtful, a warning remains unexplained, or you still cannot establish that the file is the one you intended to get, do not open or run it. Delete it or leave it quarantined, and, if you need the software, get a fresh copy from a verified source. Do not disable protection or bypass warnings to install an unknown file. For a work device or sensitive file, follow your organization’s security procedures rather than submitting it to a third-party service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These are screening checks for ordinary downloads, not a forensic analysis method. Exact scan steps vary by operating system; the platform-specific guidance here is limited to Windows features documented by Microsoft.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.