What the warning means
SmartScreen compares the downloaded program with Microsoft's reputation data. It warns when a program is new, not widely used or has no valid signature. So a warning does not mean the program is malicious, but the absence of one does not mean it is safe either.
What to verify before running
- Did you download the file from the author's official site, not from a link in an ad or a message?
- Verify the publisher: in the file's Properties on the Digital Signatures tab, if one exists.
- Compare the checksum with the value the author published.
- If you are unsure, upload the file to a checking service such as VirusTotal. Do not upload files containing personal data.
How to compute a checksum
In PowerShell run the Get-FileHash command with the path to the file. The SHA-256 result must match exactly the value the author gave. A single differing character means the file is not the same, and you should not run it.
And what about an unsigned program
Smaller independent projects often do not have a paid signing certificate, which is why SmartScreen warns about them. The decision is yours: run only from a verified source and when the checksum matches. The trial version of BirdGuard is unsigned, so a warning there is expected.
