There's nothing like HSTS for signed programs, so it can't be helped, though.
>When I installed it said it couldn't be trusted, I installed anyway but it did nothing.
Users have no way of knowing which things are safe and which things aren't if almost everything comes with a "this isn't safe" warning.
Then build out a reputation system for signers. I was recently given a link via steam to watch a video. It had an embedded fake Flash updater. The installer was very clever as it was signed by something like "Browser Company" and looked like the official Flash installer. My local AV and virustotal.com didn't detect it at the time either.
I think the age of it being convenient to run arbitrary executables in Windows is ending. There's just too much liability now, especially in the age of ransomware and kiddie hackers doing it for the lulz.