Check the source before you download anything

A safe download starts with knowing where it came from. If you found a link in an email from someone you don't know, on a pop-up ad, or on a website that looks hastily made, stop there. The file itself might be fine, but the source is already a warning sign.

Downloads from official websites are your safest bet. If you want Firefox, go to mozilla.org directly — don't search "Firefox download" and click the first result, which might be an ad pointing somewhere else. Same rule for any software: find the real company website, navigate to their Downloads or get your free guide page, and download from there. Avoid third-party download sites that bundle extra software or ads with the file you actually want.

If someone sent you a file, ask them directly whether they sent it. A message that looks like it came from a friend but includes a suspicious link or attachment often means their email account was hacked. Call them on the phone or text them separately to confirm.

Key Takeaways

  • Downloads from official company websites are safer than files from email links, pop-ups, or third-party download sites.
  • Your antivirus software can scan a file before you open it, and Windows Defender (built into Windows) does this automatically for most downloads.
  • File type matters: .exe, .msi, .bat, and .zip files can contain programs that run on your computer, while .pdf, .jpg, and .txt files are usually safer.
  • If a download seems too good to be true — free software that normally costs money, a movie file from a random site — it probably contains malware or a scam.
  • When in doubt, search the filename plus the word "malware" or "virus" to see whether other people have reported problems with it.

Understand what file type you're downloading

The three letters after the dot in a filename tell you what kind of file it is, and some types are riskier than others. An .exe file is a program that runs on your computer — it can do almost anything, which is why it's the most common target for malware. An .msi file is an installer, which also runs code on your computer. A .bat file is a batch script that executes commands. All three of these can be dangerous if they come from the wrong place.

A .zip file is a compressed folder that holds other files inside it. It won't run anything by itself, but once you unzip it, whatever's inside might. A .pdf is usually safe — it's a document that displays text and images. A .jpg, .png, or .gif is an image file and is almost always safe. A .txt file is plain text and can't run programs.

If you're downloading something that should be a document or image but it has an .exe extension, that's a red flag. Scammers sometimes hide executable files inside fake document names.

Use your antivirus software to scan before opening

Windows comes with Windows Defender built in, and it scans downloads automatically in the background. When you download a file, Defender checks it against a database of known malware. If it finds something, it will quarantine the file and warn you.

You can also scan a file manually. Right-click the file, select "Scan with Windows Defender," and wait for the result. If you use a different antivirus program like Norton, McAfee, or Bitdefender, the process is similar — right-click the file and look for a "Scan" option in the menu.

Keep in mind that antivirus software catches known threats. A brand-new malware that nobody has seen before might slip through. That's why the source of the download matters so much — antivirus is a safety net, not a substitute for downloading from trustworthy places.

Look for warning signs in the download itself

When you download a file, your browser usually shows you where it came from. In Chrome, Firefox, and Edge, click the Downloads button (usually in the top right corner) to see a list of recent downloads. If a file shows a warning icon or a message like "This file is not commonly downloaded," that's worth paying attention to — though it doesn't automatically mean the file is dangerous.

Check the file size. If you're downloading a small utility program and the file is 500 megabytes, something is off. If you're downloading a video and it's only 2 megabytes, that's also suspicious. A file that's wildly larger or smaller than you'd expect might contain extra code or be a fake.

Look at the filename itself. Scammers sometimes use names that look official: "Windows_Update.exe" or "Adobe_Reader_Install.exe" when you're actually on a random website. If the filename looks like it should come from Microsoft or Adobe but you're downloading from somewhere else, don't open it.

Search for the filename online to see what others say

Before you open a download, copy the filename and search for it in Google along with the word "malware" or "virus." If hundreds of people have reported that this file contains malware, you'll find those reports. If the file is legitimate, you'll usually find the official page where it's supposed to come from.

You can also search the filename on VirusTotal.com, a free website that scans files with dozens of antivirus engines at once. Upload the file (or paste the download link) and VirusTotal will tell you whether any of those engines flag it as dangerous. This is especially useful for files that your own antivirus didn't catch.

Read the comments and reports carefully. A single person saying "this is a virus" isn't proof, but if dozens of people across multiple websites report the same problem, believe them.

Recognize common scams disguised as downloads

Fake antivirus alerts are one of the most common tricks. You're browsing a website and suddenly a pop-up appears saying "Your computer is infected! Download our antivirus now!" This is almost always a scam. Real antivirus software doesn't advertise itself through pop-ups on random websites. Close the pop-up (don't click anything in it) and leave the site.

Pirated software is another risk. If you find a website offering Photoshop, Microsoft Office, or other expensive programs for free, it's not a bargain — it's usually malware. The same goes for movies, TV shows, and music from unofficial sources. The file might contain what you're looking for, but it often comes with hidden code that steals passwords or installs other malware.

Fake download buttons are designed to trick you. A website might show ten buttons that say "Download," but only one is real — the others download malware or take you to a scam page. Look for the official company logo and name, and download from the actual company website instead.

What to do if you've already opened a suspicious file

If you opened a file and now you're worried it might be malware, don't panic. Run a full antivirus scan right away. In Windows, open Windows Defender, click "Virus & threat protection," and select "Scan options." Choose "Full scan" and let it run — this can take an hour or more, but it checks your entire computer.

If the scan finds something, Defender will quarantine it (move it to a safe place where it can't run). You can then delete it. If the scan finds nothing, that doesn't may provide the file is safe, but it's a good sign.

If you're still concerned, restart your computer in Safe Mode (a limited version of Windows that loads only essential software) and run the scan again. Safe Mode makes it harder for malware to hide. You can also change your passwords for important accounts like email and banking, just to be safe.

Frequently Asked Questions

Is it safe to download from torrent sites?

Torrent sites are high-risk for malware because anyone can upload files with any name. Even if the filename looks legitimate, the actual contents might be malware or a fake. Stick to official sources for software, movies, and other files.

What does "This file is not commonly downloaded" mean?

Your browser shows this warning when a file hasn't been downloaded many times before. It's not a may provide the file is dangerous — new software or updates might trigger this warning. But combined with other red flags (unknown source, suspicious filename), it's worth investigating further.

Can I get malware from opening a PDF?

PDFs are usually safe, but malware can hide inside them if the PDF reader software has a security flaw. Keep your PDF reader updated and avoid opening PDFs from untrusted sources. If a PDF from a random website asks you to enable macros or install something, close it immediately.

Is it safer to download on my phone than my computer?

Android phones are vulnerable to malware from unofficial app stores, so stick to Google Play. iPhones are more restricted and harder to infect, but you should still download apps only from the official App Store. Both phones and computers benefit from the same rule: download from official sources only.

What should I do if my antivirus quarantines a file I need?

If you're certain the file is legitimate (you downloaded it from the official website), you can restore it from quarantine. Right-click the file in your antivirus software and select "Restore" or "Allow." But if you're not sure, leave it quarantined and download the file again from the official source instead.