It's not at all clear to me this is really a major issue. I'm not exactly the "average user" and I'm guessing you're not either; so I can't really judge from my experience and preferences. I did spend 4 years as a tech in a local computer shop over ten years ago, and my experience is that people will click and do the oddest things regardless, but I'm not sure if that's really all that representative either because the more savvy users didn't really come to us with software problems.
I think this is a "further research needed". For starters, how often will these situations actually occur in the first place? This may be less often than feared. How many users will be confused? This may be less than one might assume. Is just downloading a .zip file actually a security risk or "merely" confusing? That would make a big difference. What design will help with that? This may be counter-intuitive.