To cut this long story short, unless someone lets us know a certain file is to be trusted, we WILL tell the user that the file is new. This is hardly something unexpected. You can let us know by sending the file to us, or by digitally signing the file and let us know the signature.

I am not aware of the pricing models of signatures, nor what the benefits of more expensive signatures are. From my point of view, unless there in malware signed with that signature, our systems will automatically hide all warnings about low prevalence of a signed file.

Small and medium developers either have digital signatures, or send the files to us prior to release, or don’t care about a couple of users getting a warning about a new file.