Downloads are not equally risky. A file from the developer’s official site is very different from a free cracked installer, surprise invoice attachment, or pop-up download. A few checks before opening a file prevent most infections.
Does this affect you?
Use this for Windows PCs when downloading programs, documents, email attachments, files from messaging apps, or anything already downloaded but not yet opened.
Spot risky downloads before clicking
Check the source and file type before trust.
- Prefer the software developer’s official website, Microsoft Store, or a download you intentionally requested. Avoid search ads, pop-ups, download portal sites, and unsolicited links.
- Be especially careful with free versions of paid software, cracks, keygens, and license bypass tools. These are common malware carriers.
- Turn on visible extensions in File Explorer under View > Show > File name extensions.
- Avoid files pretending to be documents or images but ending in .exe, .scr, .bat, .js, or another executable extension.
- Do not trust countdown timers, expiring download claims, or click-now pressure.
- For attachments, verify the sender address and context. An unexpected invoice, shipping notice, or document from a slightly wrong address is a classic phishing pattern.
Check a file before opening it
If the file is already downloaded, scan first.
- Right-click the file in File Explorer.
- Choose Scan with Microsoft Defender or the equivalent option for your antivirus.
- Wait for the result before opening it.
- For an unfamiliar file, upload it to VirusTotal.com for a multi-engine check.
- If SmartScreen says Windows protected your PC, do not choose Run anyway unless you are completely sure of the source.
If you already opened something risky
Do not panic, but act quickly.
- Disconnect from the internet by turning off Wi-Fi or unplugging ethernet.
- Open Windows Security > Virus & threat protection and run a Full scan.
- Remove or quarantine anything found.
- Reconnect only after the scan is clean.
- Change important passwords from a separate trusted device, especially email and banking.
- If the file showed a ransom note or encrypted files, stay disconnected and get professional help before paying or experimenting.
More control
Extensions can be risky too
Browser extensions can see pages and typed data. Install them only from official browser stores, and check reviews, permissions, and install counts.
Do not enable macros casually
Word or Excel files that demand Enable Content or Enable Editing to view properly are a long-running malware trick. Only enable content when you fully trust the source.
Torrents and sideloading raise risk
Peer-to-peer downloads and apps installed outside official stores lack the review process that catches many malicious files.
Sources
- Microsoft Support – Protect yourself from phishing (2025)
- CISA – Protect yourself from malicious cyber actors (2025)
- Malwarebytes – What is malware? (2025)
