Free file check CMC Sentinel Deutsch Windows guide

DO NOT DOUBLE-CLICK — CHECK THE SOURCE, FILE TYPE AND WARNINGS FIRST

How to check if a file is safe before opening it

An unexpected invoice, job application or ZIP file may be harmless. Do not open it out of curiosity. These seven checks help you assess the risk without running the file.

Check without running the fileMicrosoft and CISA referencesFree Shield pre-checkSentinel complements Defender
SHORT ANSWER

Do not open an unexpected file. Confirm the sender through a separate trusted channel, show the full file extension and scan the file with Microsoft Defender. A digital signature, SHA-256 hash and static pre-check add context, but no single result guarantees that a file is safe.

Before you do anything else

Do not open the file or bypass a security warning. Do not enable macros, select “Run anyway” or add an antivirus exclusion because a message tells you to.

If the attachment appears to come from someone you know, verify it using a phone number or account you already trust. Do not simply reply to the suspicious message.

1. Confirm the sender and the reason for the file

Ask whether you expected this exact document. A familiar sender address is not proof: accounts can be compromised and display names can be copied. Check the project, invoice number, language and any unusual pressure to act quickly.

CISA recommends verifying a doubtful message with the apparent sender before opening an attachment.

2. Show the complete file extension

In File Explorer, select View → Show → File name extensions. A file presented as “Invoice.pdf” may turn out to be “Invoice.pdf.exe”. Microsoft explains that the extension identifies the file type; renaming it does not convert its contents.

Be especially careful with executable or script-capable types such as .exe, .msi, .scr, .bat, .cmd, .js, .vbs, .ps1, macro-enabled Office files such as .docm, .xlsm, and archives that may contain them.

3. Scan the individual file with Microsoft Defender

Right-click the file, choose Show more options if needed, and select Scan with Microsoft Defender. Review the result in Windows Security → Virus & threat protection → Protection history.

No detection does not mean “guaranteed safe”. New or targeted malware may not be recognized yet. A detection is a clear reason not to open the file or casually choose “Allow”.

4. Check the publisher and digital signature

For executable files, open Properties → Digital Signatures. Microsoft’s Sigcheck utility can display version data, certificate-chain details and file hashes.

A valid signature improves traceability, but it does not prove that the file belongs to your particular request. A missing signature is not automatic proof of malware either. Consider origin, expected purpose, scan result and technical details together.

5. Record a SHA-256 hash

A SHA-256 hash identifies the exact file version without running it. In PowerShell, use Get-FileHash -Algorithm SHA256 "C:\Path\File". Even a small change produces a different value.

A hash is not a safety verdict. It helps compare a vendor-published value or identify the same sample in a support case. Do not upload confidential customer documents or personal data to a public scanning service without considering the privacy impact.

6. Add a static Shield pre-check

The free Shield checker examines supported Office, PDF and ZIP files for technical warning signs without executing their contents. Without an account, the file is not stored in a personal workspace. Open the full checker (the analysis form currently uses German labels).

This pre-check complements the local antivirus scan. It does not replace Microsoft Defender, sender verification or professional incident response.

7. If doubt remains, do not open it

Delete or quarantine the file and ask for a fresh copy through a verified channel. On a managed work device, let your IT or security contact decide.

If you already opened the file and then notice unusual processes, connections or remote control, disconnect the PC from the network. Continue with the Windows remote-access checklist. CMC Sentinel brings local process, connection and remote-access signals into one view, but it does not replace antivirus protection or forensic analysis.

SHIELD + CMC SENTINEL

Bring the manual checks into one understandable view.

Sentinel combines local process, connection, startup and remote-access visibility with deliberate Shield checks. It complements Microsoft Defender and keeps the limits of each finding clear.

€19.90for 1 month · up to 5 Windows PCs in one household

The total price and renewal period are shown before payment. Future renewal can be cancelled for the end of the paid period.

Common questions

Can I check a file without opening it?

Yes. Verify the sender, show the full extension, scan it with Defender, inspect its signature and calculate its hash without running the file.

Is a file safe if Defender finds nothing?

No single clean result is a guarantee. The expected source and purpose, extension, signature and other warning signs still need to fit.

Should I upload a confidential file to a public scanner?

Not without considering confidentiality and privacy. Customer documents, personal data and internal files may not be appropriate for public upload.

What if I already opened it?

If the PC behaves unexpectedly, disconnect it from the network, run a full Defender scan and secure important accounts from a separate trusted device. Document what happened instead of deleting random files.

Official references

Updated 30 September 2026. If an attack is active, money was lost or important accounts were compromised, also contact the relevant provider, bank or law-enforcement authority.