If you are about to install AtlasForgeX, you may run into a blue Windows warning, and a scan may report a couple of detections. Neither is hidden here. This page explains exactly what those warnings are, what causes them, what we have already done about it, and how to verify with your own eyes that the file you downloaded is the file we published.
The short version: the Windows warning is a publisher reputation check, not an antivirus result. Every major antivirus engine reports our installer as clean. A handful of machine-learning engines flag it because the installer is unsigned and compressed, which is the standard false-positive pattern for a small publisher. Every release ships with a SHA-256 checksum so you can verify the file yourself.
When you open the installer, Windows may show "Windows protected your PC". This is Microsoft Defender SmartScreen, and it checks one thing: whether the publisher of this file already has enough download history for Microsoft to recognise it. It appears for essentially every new application from a company that has not yet built that history.
It is not your antivirus finding a threat. Windows Defender scans the file separately, and it does not flag AtlasForgeX. If you choose to continue, here is what the screen looks like and where to click:
You should never click through that screen on faith alone, for our software or anyone else's. That is what section 3 is for: verify the checksum first, then decide.
Scans of our installer have consistently shown a small number of detections, typically four or five out of about seventy engines. We are not going to bury that number. What matters is which engines, and why.
Every detection comes from a machine-learning heuristic engine, the kind that guesses from structural traits rather than matching a known threat. The signature-based engines, the ones that identify actual malware families, are clean:
| Engine | Type | Result on our installer |
|---|---|---|
| Microsoft Defender | Signature + cloud | Clean |
| BitDefender | Signature | Clean |
| ESET | Signature | Clean |
| Kaspersky | Signature | Clean |
| Sophos | Signature | Clean |
| Fortinet | Signature | Clean |
| A few ML-only engines | Heuristic guess | Generic flag, no named malware family |
Those engines score structural traits, and an unsigned installer with a compressed payload scores badly no matter what is inside it. We can tell you precisely what is and is not in our package:
The last two points are not one-off fixes that might quietly disappear in a future build. Both are covered by automated tests that run as part of our build process, one asserting that no UPX packing is present, one asserting the publisher metadata is intact. If either ever regresses, the build fails.
You do not have to take any of the above on trust. Every file we publish has a SHA-256 checksum, a fingerprint that changes if even one byte of the file differs. Compare the fingerprint of your download to the one below. If they match, you have exactly the file we published, with nothing added in transit.
Open PowerShell in your Downloads folder and run:
Get-FileHash .\AtlasForgeX_Setup.exe -Algorithm SHA256
Compare the resulting string to the one above. Case does not matter, the characters do. If they differ, do not run the file, and please tell us, because that would mean something is wrong on our side or between us and you.
Want a second opinion from the scanners? Paste the checksum into VirusTotal's search to see every engine's verdict on this exact file, or upload the file there yourself. Now that you know what those detections are and where they come from, the number will not surprise you.
The real fix for the "unknown publisher" text is an Authenticode certificate. It signs each release with a verified company identity, so Windows names Tarmex Oy instead of calling us unknown, and it clears most heuristic detections at the same time.
We want to be accurate about two things that vendors often oversell:
Until then, everything in sections 2 and 3 is what we can offer instead: a build with nothing to hide in it, published checksums, and an explanation rather than a reassurance.
Once AtlasForgeX is installed, updates arrive inside the application through our own update channel. They do not go through the browser download path, so they do not trigger SmartScreen and there is no warning to click through. Existing customers see none of this after day one.
The installer on our download page is also deliberately kept stable rather than rebuilt with every release. Reputation in Windows attaches to a specific file, so replacing that file constantly would reset the very trust we are trying to accumulate, and new versions reach you through the in-app updater anyway.
AtlasForgeX is built by Tarmex Oy, a registered Finnish limited company. That is verifiable independently of anything we say here: look up business ID 3579018-8 in the public YTJ or PRH business register and you will find the company, its registration date and its status.
If anything on this page does not match what you observe, we want to hear about it. Write to atlasforgex@proton.me and a person will answer.
AtlasForgeX reads official company registers across 92 markets, pulls direct numbers and verified emails, and attaches buying signals to each company. Free trial, no card required.
Download AtlasForgeX →