Scanning the file first with a good AV, then opening in a VM should be a very good (nothing's perfect) way of keeping safe. Yes, he could get infected with an unknown virus. But since it's unknown, there's going to be little protection regardless of what he does.Rowhammer, Spectre and Meltdown have all shown the ability to leave the virtual environment.
Even using throwaway VMs isn't a safe we a first thought.
Alternatively, he can download it on a Mac, which will be largely immune to Windows-based viruses, then once he's inspected the file contents, he can move what's necessary.
But we all know this... I'm not sure what answers the OP is looking for.