First of all, scan it with another anti virus program like Malwarebytes, or an online scanning service; just to be safe.
It is not unknown for a virus to make its way through the supply chain and onto otherwise trusted servers; GitHub was spewing malware a year or so ago, and Linux repository was also hit.
If the other scans say it is clean, you will have to manually shut down Win Defender while you extract and install the file - and also report it as a false positive to MicroGit.