Don't open a surprise .exe or .zip just because the download finished. Microsoft Edge classifies downloads as not dangerous, dangerous (blocked), or allowed only after you click the link yourself. Microsoft Defender SmartScreen checks files against reported malware and against a list of well-known, frequently downloaded files — if yours isn't on that list, Windows warns you. Treat that warning as a stop. Check the website, look for HTTPS and the padlock, then scan the saved file in Windows Security before you run it. Extra paid antivirus is optional; Defender with SmartScreen left on is a valid household setup. An unexpected email or text with an attachment is phishing — don't open it.

Check the website and the file type before you click

Confirm the site and the file type before you start the download — SmartScreen cannot undo a click on the wrong page.

  1. Expected sender. Only download from a site you meant to visit, such as the vendor's own page. Microsoft's Edge guidance (Aug 15, 2023, US) is to skip third-party, unknown, or poorly made sites for software and add-ons.
  2. HTTPS and the padlock. Check the address bar for https:// and the padlock before you click Download. That shows TLS encryption; it does not prove the file is clean, but a missing padlock is a reason to stop.
  3. File type matches what you asked for. If you wanted a PDF manual and the site hands you an .exe or a .zip full of .exe files, don't open it. Rename tricks like invoice.pdf.exe are still programs.
  4. No fake popup telling you to download a cleaner. A banner that says your PC is infected and you must download a tool is not a file you chose. Close it and follow 8 ways to tell a virus warning popup is fake. For unexpected email or text attachments, see how to spot a phishing email.

SmartScreen warning vs ignore anyway

A Microsoft Defender SmartScreen or Edge warning is reputation-based protection, not a suggestion to click through.

What Edge or SmartScreen saysWhat it meansWhat you should do
Dangerous / blockedThe download matched reported malicious software, or Edge classified it as dangerous and blocked it.Do not override. Delete the file. Return to the company's own HTTPS site if you still need the software.
Unfamiliar / not on the known-safe listThe file is not on SmartScreen's list of well-known, frequently downloaded files. No established reputation for the file, app, or signature.Do not ignore the warning. Confirm the publisher, scan with Defender, and prefer a signed installer from the official site. You can submit a file to Microsoft for review if the warning looks wrong — still do not Run it first.
No warning / not dangerousEdge classified it as not dangerous, or the URL, file, app, or certificate already has an established reputation.You can keep the file, but still match the file type to what you wanted and run a Defender scan before you double-click an .exe or unpack a .zip.

SmartScreen is built into household Windows 10 and later and checks files apps try to download and run. It does not protect files sitting on internal network shares (UNC or SMB). Those still need a Defender scan.

Scan the file with Defender before you run it

Scan the saved file in Windows Security before you run an .exe or unzip a .zip — leave SmartScreen on the whole time.

  1. Leave the file in Downloads. Do not double-click it yet.
  2. Open Windows Security → Virus & threat protection → Scan options → Custom scan and select that file (or the whole Downloads folder). Let it finish.
  3. Keep Microsoft Defender SmartScreen on under Windows Security → App & browser control. Do not turn SmartScreen off to let the installer through.
  4. If File Explorer → Properties shows an Unblock checkbox, do not check it just to silence a warning. That mark means Windows still treats the file as coming from the internet. Scan first; Unblock only if you fully trust the official publisher and the scan is clean.
  5. Stay on one real-time antivirus. If Microsoft Defender is already on, do not add another real-time engine (including Malwarebytes real-time) on top of it. See Is Microsoft Defender enough.
  6. If you already opened a bad attachment, the FTC says to update your security software, run a scan, and remove what it finds. If the scammer may have your Social Security number, card, or bank numbers, use IdentityTheft.gov.

FAQ

Should I open an exe or zip that showed up in an unexpected email?

No. The FTC treats unexpected email or text with an attachment or link as a phishing pattern. Don't open it. Confirm through a site or number you already trust. See how to spot a phishing email.

What does an unrecognized-app SmartScreen warning mean?

It means the file is not on the list of well-known, frequently downloaded files, so Windows is advising caution. That is not permission to click Run anyway.

Do I need paid antivirus to check a download?

No. Microsoft Defender plus SmartScreen, kept on and set to update, is a valid household setup. Paid suites are optional extras, not a requirement before every download.

The installer will not run unless I turn SmartScreen off. Should I?

No. Leave SmartScreen on. Get the file from the vendor's own HTTPS page, scan it, and submit it to Microsoft for review if you think the warning is wrong. Turning SmartScreen off is how a blocked installer gets through.

I already ran the file. Now what?

Update Windows Security, run a full scan, and remove what it finds (FTC). Change passwords on a different device if you typed any. If financial or Social Security details may have been taken, use IdentityTheft.gov.

Can SmartScreen see a file I copied from a shared folder at work?

Not as internet protection. Microsoft states SmartScreen does not protect against malicious files on internal network shares (UNC or SMB). Scan those with Defender the same way.

Buy-nothing is valid if Defender and SmartScreen stay on. If you want a paid suite for extra devices or features, compare only these on-site pages: TotalAV, Norton, Bitdefender, McAfee, Avast. Do not run a second real-time antivirus next to Defender.