I tried uploading it to their web-thing so it could be examined in detail and verified but the installer was too large for it, apparently... some AV always false-positives it, it seems like.
Yeah, it's odd. I remember for the last release smartscreen would just take like 15+ minutes to scan the download, so most people thought the download had failed.
The executables aren't signed which is probably the main issue. They want executables to be signed with Extended Validation (EV) code signing certificates. It will get rid of the unknown publisher warning and over time I guess their AV will also start trusting you as a publisher.
Yeah, I think the solution is getting an OV code signing certificate which is probably ~$70-100/year. I don't know the cheapest option.
An EV certificate appears to start out as reputable but costs ~$200-300/year and the EV verification process likely involves further costs too.