How to never accidentally run Malware: Must Have Windows Tweaks

Sdílet
Vložit
  • čas přidán 22. 02. 2024
  • Most users still run malware accidentally thinking it is a pdf or a contract document. This video shows you some simple must have windows tweaks on how to not get hacked by your run of the mill infostealer or ransomware pretending to be a pdf contract. • When I accidentally ra... Try Malwarebytes with new features for free: mwb.link/4ay7nag (sponsor)
    Buy the best antivirus: thepcsecuritychannel.com/best...
    Join the discussion on Discord: discord.tpsc.tech/
    Get your business endpoints tested by us: tpsc.tech/
    Contact us for business: thepcsecuritychannel.com/contact
  • Věda a technologie

Komentáře • 653

  • @notme232
    @notme232 Před 3 měsíci +1410

    file extensions should be enabled by default, the fact that it is even an option is a major windows security flaw.

    • @nabieladrian
      @nabieladrian Před 3 měsíci +72

      ​@@osniko How can you expect such tiny little startup like MS to simply allow rename A file, not THE file. Of course they can't.

    • @IIGrayfoxII
      @IIGrayfoxII Před 3 měsíci +47

      @@osnikoThis was an issue in the XP days, where the whole filename and extension was selected, but since vista the name part is selected and you must manually move the cursor to the extension part.

    • @alphatech__
      @alphatech__ Před 3 měsíci +4

      File extension doesn't have to be at the end of the file ,it can be in the middle, like apdf.exe can be exepdf.a

    • @TheLukemcdaniel
      @TheLukemcdaniel Před 3 měsíci +7

      I'm okay with it being an /option/, but it should be an opt-IN not an opt-OUT.

    • @TheLukemcdaniel
      @TheLukemcdaniel Před 3 měsíci

      @@alphatech__ True. I think I have seen some do that, where they name it "totallynotsketchy.pdf.scr"

  • @AviatingRandom
    @AviatingRandom Před 3 měsíci +635

    I would argue it’s best to turn “ask me where to save each file” on because while it may be a little annoying, it will show you the file extension when you download it and it’s useful to ensure a site isn’t downloading files in the background.

    • @joepjoep9531
      @joepjoep9531 Před 3 měsíci +5

      This is about not instinctively open it in your browser by taking away the button if you don’t you still can

    • @rizkyadiyanto7922
      @rizkyadiyanto7922 Před 3 měsíci +46

      browsers these days actualy warn you if you download exes.

    • @theycallmeken
      @theycallmeken Před 3 měsíci +5

      Great suggestion

    • @portman8909
      @portman8909 Před 3 měsíci +5

      I have on not just for that but I don’t want to clutter my downloads folder. I only use it for exe. The rest go into other folders.

    • @crimsonkarma13
      @crimsonkarma13 Před 3 měsíci

      @@rizkyadiyanto7922 does it? I have only downloaded trustable exe so I have yet to see that error

  • @noneofyourbusiness1304
    @noneofyourbusiness1304 Před 3 měsíci +282

    I highly disagree with turning off "Ask to Save" in browsers. Not only can it show the type of file you are even saving, it also can stop random files being downloaded automatically if you happen to click a wrong link, since it now always tries to ask about the file, overall giving the chance of saving you from even having the chance to click the file to begin with.

    • @TheLukemcdaniel
      @TheLukemcdaniel Před 3 měsíci +4

      Maybe turn it off temporarily if you're scraping a ton of files from one site real quick, but ftmp, the daily driver setting should be to ask for any downloaded file.

    • @mienoni5330
      @mienoni5330 Před 3 měsíci +6

      I can see why he's suggesting this, because it creates the habit of you needing to open explorer before opening anything, meaning you WILL see the extensionand the type for sure (which many non teccy people don't), but yeah it's never a good idea to not be able to stop something to be downloaded.

    • @MathiasYmagnus
      @MathiasYmagnus Před 3 měsíci +1

      Yup. What OP(Nonya) typed

    • @ArkenGAMES
      @ArkenGAMES Před 3 měsíci +2

      Yeah I am using Chrome and it always shows the file type. If that can be faked too I'm done for.

    • @SlinkyD
      @SlinkyD Před 3 měsíci +2

      ​@@ArkenGAMES File extensions can be bogus. Gotta check the magic and default program for each file type.
      The fact that 30+ years later this is still a problem because of basic computer knowledge being too troublesome to teach (not really) is a problem yet everything being computerized.

  • @Inventors_Toolbox
    @Inventors_Toolbox Před 3 měsíci +319

    Worst thing Microsoft ever did was hide the file extension by default. Would that really have confused anyone? What they should set explorer to do is have all executable show up in an obvious contrast color or highlight scheme with a 'caution this is an app' identifier next to it. Make people look and go why is that highlighted like that.

    • @UNcommonSenseAUS
      @UNcommonSenseAUS Před 3 měsíci

      Microsoft is owned by Israel, so nevermind clicking a pdf, if you're running Windows you're already infected with state sponsored malware

    • @DezXereanas
      @DezXereanas Před 3 měsíci +1

      Wasn't it default in windows xp?

    • @ayoCC
      @ayoCC Před 3 měsíci +2

      Could maybe show it separately or inside the file icon or recolored as well so that it pops out.

    • @Inventors_Toolbox
      @Inventors_Toolbox Před 3 měsíci +2

      @@ayoCCExactly!, the question then becomes if you and I can see this almost immediately multiple people at Microsoft must have as well. They then decided that, no were not going to implement this obvious and simple fix. My question becomes, why? There must be some overriding motivation to not do this, I just don't see what it could be.

    • @paulfrayne6519
      @paulfrayne6519 Před 3 měsíci

      Directory opus does this, and sadly it is not cheap to purchase a license in some places

  • @TheNkatsar
    @TheNkatsar Před 3 měsíci +83

    Showing file extensions is the first tip I would suggest, it would immediately distinguish between the 2 files in the video

    • @chrisseal1467
      @chrisseal1467 Před 3 měsíci +7

      Yes, why is this not step one in the video. The rest of the things are unnecessary.

    • @x-user3462
      @x-user3462 Před 3 měsíci

      ​​@@chrisseal1467there also maybe file somexe.pdf that is actually an exe (som\u202Efdp.exe) with RTLO in filename, so showing file type in table view is a great tip.

    • @gramblor1
      @gramblor1 Před 3 měsíci

      I don’t think he’d have a very long video if he did that.
      I still found it useful, though.

    • @samfkt
      @samfkt Před 3 měsíci +2

      And turning preview pane off..... it can execute malware jyst by previewing it

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @AyataHiragi
    @AyataHiragi Před 3 měsíci +97

    I always found Microsofts idea to hide the extensions ridiculous, it was always shown in 95 98 and 2000 after all

    • @varski76
      @varski76 Před 3 měsíci +6

      That is the reason more of these attack are like this as normal users don't use the details view anymore

    • @tarwod1098
      @tarwod1098 Před 3 měsíci +2

      Most users don't know what it means anyway and they only get irritated

    • @ghostnoise1711
      @ghostnoise1711 Před 3 měsíci +1

      98 SE, hidden by default

    • @e1woqf
      @e1woqf Před měsícem +1

      @@tarwod1098 Nobody should use a computer without some basic knowledge.

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @TheCocoaDaddy
    @TheCocoaDaddy Před 3 měsíci +87

    I'm fortunate I've never "accidentally" clicked or run an infected file and I've never been hit, personally, with a malware infection. Several of my friends have but I haven't. I think videos like this can really be helpful so thanks for posting!

    • @youravghuman5231
      @youravghuman5231 Před 3 měsíci +11

      The fact that you watched this video means you are not noob, so the probability of this happening to you is lower. You're not lucky, you're smart enough to use a pc unlike the majority of people.

    • @UNcommonSenseAUS
      @UNcommonSenseAUS Před 3 měsíci +2

      Well you're obviously not reverse engineering enough malwarw

    • @MrMarbles
      @MrMarbles Před 3 měsíci +1

      Send this to your grandma

    • @sdwone
      @sdwone Před 3 měsíci +3

      Think before you click! And scan ANYTHING that you download from the Internet! Be paranoid about it, and opt for a guilty, until proven innocent stance!
      Works for me!

    • @UNcommonSenseAUS
      @UNcommonSenseAUS Před 3 měsíci

      @@sdwone virus total is a useful tool...

  • @npsit1
    @npsit1 Před 3 měsíci +53

    Anytime I have to log into a new computer, I always turn on file extensions. It's a habit from using DOS, I think.. It takes me 10 to 15 minutes changing all the settings from default - because I hate most of the default Windows settings.

    • @pleskbruce
      @pleskbruce Před 3 měsíci

      Yes! And many other tweaks, such as resetting registry values, will speed up windows, allow me to reset file locations, etc.

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @wolf1438
    @wolf1438 Před 3 měsíci +19

    In our country we got bear issues - picking up trash. So they are trying to develop better trash bins. There was an article interview with one of the developer when he was asked question why he just simply do not make more sophisticated mechanism. Here is his answer - you know the boundaries between the smartest bear and dumbest human is pretty narrow. In other words if I set up in our company group policy to show file extensions in few days I will have a dozens of tickets on IT people complaining they cannot open their powerpoint, excel or word document, because during renaming process they deleted file extension.

    • @ghoulbuster1
      @ghoulbuster1 Před 3 měsíci

      Sub 80 IQ barely functioning brain 😂

    • @romanm.4763
      @romanm.4763 Před 3 měsíci +1

      That developer (a smartest bear?) could write a renaming function which prevents to change a file extension or at least warnings about it

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      lmfao. the truth in this hurts

  • @B0tAcH1
    @B0tAcH1 Před 3 měsíci +24

    Adding to this, you can also use the group by type function for files. adding that clear separation that you can collapse and expand at will is very helpful

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @ansfridaeyowulfsdottir8095
    @ansfridaeyowulfsdottir8095 Před 3 měsíci +51

    I always set my machine to display extensions and file type and always View in Details.
    It really annoys me when LoseDoze changes it back to Icons or some other view for certain file types. It just wastes my time.
    {:o:O:}

    • @samfkt
      @samfkt Před 3 měsíci +2

      Preview pane should be disabled too

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @peterroper6055
    @peterroper6055 Před 3 měsíci

    Excellent advice - thanks! Have made these changes and tweaks. Must get into cast-iron routine with downloads.

  • @x-user3462
    @x-user3462 Před 3 měsíci +12

    Configuring windows explorer to show file extensions is the first thing I do after windows installation. Show type in the table view is also a great tip because of the RTLO attack.

    • @samfkt
      @samfkt Před 3 měsíci

      And disabling preview pane, it can execute malware

    • @filipetrujeira3359
      @filipetrujeira3359 Před 3 měsíci +1

      @@samfkt Do you have any sources on that?

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @kubbbercraft
    @kubbbercraft Před 3 měsíci +1

    file name extensions enabled is just in general a practical must for so many usecases. mostly to figure out what fileformats you are trying to open where or what they can, especially with photos or videos

  • @juwright1949
    @juwright1949 Před 3 měsíci

    Excellent! Just subscribed. Everything makes total sense. Thanks

  • @KentuckyFan8181
    @KentuckyFan8181 Před 3 měsíci +21

    Great video. That's why i always use sandboxie anytime i open a file or something I'm unsure of.👍

    • @youravghuman5231
      @youravghuman5231 Před 3 měsíci +1

      The thing is this method is to target unaware users, not just unsure about something. If you're frequently exchanging documents, you wouldn't be aware and never unsure about the file.

    • @KentuckyFan8181
      @KentuckyFan8181 Před 3 měsíci +3

      @@youravghuman5231 I agree. I was just pointing out what i use. Because i got a virus from doing it the normal way and it sucks.

    • @UNcommonSenseAUS
      @UNcommonSenseAUS Před 3 měsíci +3

      It's almost like vms were made for it

    • @user-od4gs3iu4t
      @user-od4gs3iu4t Před 3 měsíci

      good choice, sadboxie (-plus) is free and open source

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      @@UNcommonSenseAUS lol

  • @thelastgeneration102
    @thelastgeneration102 Před měsícem

    Yes! These kinds of details for security are much welcome! Thank you!

  • @juliocesarpereira4325
    @juliocesarpereira4325 Před 3 měsíci

    Some of these steps I've always done such as always open a recently downloaded file on windows explorer download folder. As I watched the video, I changed the view settings to show the extension. Very useful tips. Thanks.

  • @ironkrieg3368
    @ironkrieg3368 Před 3 měsíci

    Thanks for posting this. :) Made a couple of the changes recommended.

  • @photoshopman1972
    @photoshopman1972 Před 3 měsíci +5

    The only issue with removing the download prompts on an browser is if you have very poor internet connection, the user will not know if the download has failed and will not allow the user to have a chance to restart the download.
    On a legit file that is.
    Guess there is really no full proof way here. It also assumes that the user also knows the differences as well. An older person or person with very little computer knowledge will not know that difference.
    The true way is for the computer to be smarter than the individual using it with system policies and software that can prevent things like this from occurring.
    Still I do like some of the tips you provide here and thank you for tips!

  • @johnmarmalade4345
    @johnmarmalade4345 Před 3 měsíci +6

    Great video for security awareness!
    I just keep the "show downloads when a download starts" switched on so that I know when something is downloading when there shouldn't be anything downloading. Using this, I find out about the strange javascript downloads some sites drop on my computer.
    I've also been using all the other tips since a few years ago. I also scan files typically infected with malware like PDFs, Microsoft office files, and executables before I run them. Kept me pretty safe the past few years.

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @inthewoods6271
    @inthewoods6271 Před 3 měsíci +3

    Great video, Id only be hesitant to enable preview files since in some cases it was used to launch the malicious file

  • @lensy6
    @lensy6 Před 2 dny

    its insane that view file extensions not only isn't the default but that its even an option to hide it at all

  • @robinweiland7533
    @robinweiland7533 Před 3 měsíci

    Really useful, espeacially after I realized that just enabling extensions might make me even more vulnerable to tricks with rtlo characters in filenames

  • @stultuses
    @stultuses Před 3 měsíci +13

    You check the extension but even if they change the type, try opening it up in notepad
    Notepad never opens it up as an application, even pdf's open up as a pure text file and you can look at the contents header and see a pdf type in the file with pdf version number etc. An application will open as a text file, and you can quickly see the data section of the file and the payload etc, and you can then exit and delete the file

    • @DigitalDissident
      @DigitalDissident Před 3 měsíci +5

      no one's be opening or analysing file contents in Notepad. impractical & cannot be understood

    • @Anjum9694
      @Anjum9694 Před 3 měsíci +4

      You mean a hex editor? If were going through that route might as well use the proper tool

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      lol, the 2453678765435678 notepad haks that have been evolving since windows 95 would disagree lm
      fao

  • @nakfan
    @nakfan Před 3 měsíci

    Great tips 👍 Thanks too for giving a short glimpse of Malwarebytes.

  • @PatrickBijvoet
    @PatrickBijvoet Před 3 měsíci +3

    The company who build my computer, must have seen your video. All settings where as you said. But thanks for making me aware.

  • @miro007ist
    @miro007ist Před 3 měsíci +1

    your videos put me right to sleep thank you so much. I haven't been able to sleep for the past three years and your videos fixed my sleep

  • @redvex2114
    @redvex2114 Před 3 měsíci +5

    File extensions by default is a thing, but also remove the large icons viewing mode. Who uses that ? It's like asking for malware.

  • @RudysRetroIntel
    @RudysRetroIntel Před 3 měsíci +1

    Excellent video and tips! Thanks for sharing

  • @TimVels
    @TimVels Před 3 měsíci +6

    I don't understand why people use icon/thumbnails, it is much faster to go through details. Since I have used detail view I had stuck with it for many years now. Never had an issue with any virus.

  • @Aranimda
    @Aranimda Před 3 měsíci +3

    Never ever open ANY file when extensions are hidden.

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @donturner3239
    @donturner3239 Před 3 měsíci

    Excellent tips, I will share this with my friends.

  • @Rivenworld
    @Rivenworld Před 3 měsíci +1

    Great advice, thank you for sharing.

  • @Turboflabs
    @Turboflabs Před 3 měsíci

    Was surprised to see you showing off your sponsors older version of Malwarebytes v4 while it recently released v5. So what do you think of the new one, does it perform any better ?

  • @jvanderhorst2011
    @jvanderhorst2011 Před 3 měsíci +1

    Really good video, viewing file ext is a MUST.

  • @user-sn9ph5cb8t
    @user-sn9ph5cb8t Před 3 měsíci +1

    Awsome video! I already had vew file extentions on as i am a software developer and i like that feture already. Nice tips!

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      you develop on windows? no wonder so many softwaare companies cant keep their corporate secrets secret

  • @PlutoniumDG
    @PlutoniumDG Před 3 měsíci +3

    I always have "ask me where to save each file" on. That way i can see what I'm downloading before it even downloads. One time i clicked on a fake link that automatically tried to download something, thanks to my setting i could prevent that from happening

  • @jenb1973
    @jenb1973 Před 3 měsíci

    Very informative! Took me a while to figure out you must be in Edge (not Chrome) to change the download settings. Just wish it had been clarified in the beginning. Thx for the info!

  • @johnrichardson4507
    @johnrichardson4507 Před 3 měsíci

    This is brilliant I have learned how to protect and not accidentally open malware thanks

  • @IakobusAtreides
    @IakobusAtreides Před 3 měsíci

    Extremely helpful, thank you!

  • @D.von.N
    @D.von.N Před měsícem

    Thanks for the recap, will go and double check. In the meantime, how about the UAC set up to the max, so if a text document wants to make changes to the computer I will not allow it? That's for my personal PC.

  • @polykoma
    @polykoma Před 3 měsíci

    This is very valuable. I use those settings for so long time I didnt even thought about it beeing a thing because thats just soooooooo basic things. I can also recommend to not use default browser with you critical logins. Use another browser

  • @d-proc
    @d-proc Před 3 měsíci

    Are you recommending Edge over Brave, with the normal default installation? And would you prefer to have Malwarebytes installed in addition of MS Defender or is Defender enough on its own?

  • @supecoop
    @supecoop Před 3 měsíci

    Simple but effective ideas to make your downloads safe to open. Thanks

  • @rustyshackleford2841
    @rustyshackleford2841 Před měsícem

    Great video! Thank you.

  • @markoshun
    @markoshun Před 3 měsíci

    Totally agree with viewing file extensions before opening new files. But I prefer to use the browser’s download window where it shows the file with extension and I can choose to view it in it’s destination folder before running it. Eliminates a couple steps. And I often like to see download progress and keep track of where file is going.
    Seems like the browsers have already addressed these issues.. with a couple less steps.

  • @CesarAugustoRL
    @CesarAugustoRL Před 3 měsíci

    Another good video for malware security, thank you!

  • @paulwhelan7123
    @paulwhelan7123 Před 3 měsíci

    Great helpful stuff, thank you!

  • @gutohertzog
    @gutohertzog Před 3 měsíci

    Another awesome video. Thank you.

  • @technicallyme
    @technicallyme Před 3 měsíci +2

    Couldn't the preview window run script on for instance a word document with a macro

  • @ktheodor3968
    @ktheodor3968 Před 3 měsíci +1

    Before clicking to open any downloaded file, like a PDF, shouldn't one first right-click on it and run the antivirus/malware software, Windows' own or any such paid software? Wouldn't that save one from any problems? Thanks

  • @antonnycer
    @antonnycer Před 3 měsíci

    Is there any alternative program or file explorer where executable files are marked so we don't confuse them with other types? I think it would be an interesting way to stay alert

  • @jackdeago3639
    @jackdeago3639 Před dnem

    Thank you so much for such excellent videos

  • @lopzinc
    @lopzinc Před 3 měsíci

    1:41
    the one on the right is slightly brighter, very obvious on the red and the top right corner of the page where it is folded

  • @Khual
    @Khual Před 3 měsíci

    That is an amazing tips to learn. Should definitely inform our peers about these basic tips that could someday come in handy.

    • @TheLukemcdaniel
      @TheLukemcdaniel Před 3 měsíci +1

      Some day? This has been an issue since WinXP. That they STILL haven't fixed. A simple change to the default behavior(back to what it WAS) would fix this instantly.

  • @Seriously_Unserious
    @Seriously_Unserious Před 3 měsíci +5

    As somebody who's studied network security and as a web developer who makes sure client's websites are secure and had clients get hacked before, I can definitely say these simple steps are a great first line of defense. May hacks like the one that took down Linus Tech Tips last fall could have been prevented just by doing these simple steps.

    • @michaelferreira2651
      @michaelferreira2651 Před 3 měsíci

      Since you studied network security, let me ask you this. Can I block port 443 and 80 on router without affecting my ability to mange router from web browser on a local PC that has wired connection to router and wifi disabled? I am getting a lot of DoS Attacks on port 443 when I check router log.

    • @Ilurk247
      @Ilurk247 Před 3 měsíci

      @@michaelferreira2651 Ask your question to google like this "without affecting my ability to mange router from web browser on a local PC that has wired connection to router and wifi disabled can I block port 443 and 80 on router?" The answer for your particular setup will be on the list of options. (I think probably port forwarding is the answer, but best to see what you need.)

    • @izgler
      @izgler Před 20 dny

      @@michaelferreira2651depending on what you mean by “block”. If you truly block all 443 and 80 traffic you won’t be able to use the internet. Decent routers should all drop the DDOS packets anyway. If you aren’t hosting anything on 443 or 80 you’ll have nothing to worry about.

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      @@michaelferreira2651 just send your login page to a defferet port

  • @Pymmusic
    @Pymmusic Před 3 měsíci

    Thank you very much! This video is very important!!!

  • @salsspar2132
    @salsspar2132 Před 3 měsíci +1

    thank you, had me 2nd guessing all my pdf's, checked them and im good but i put these good prevention methods that i looked. and personally i missed seeing extensions in my old pc

  • @abdullahaljalil5218
    @abdullahaljalil5218 Před 3 měsíci

    It's a small tweak but very useful and helpful to have the habit not to rely on thumbnails

  • @bruceritchings5336
    @bruceritchings5336 Před 3 měsíci

    Thanks for the excellent advice!

  • @peterwassmuth4014
    @peterwassmuth4014 Před 3 měsíci

    Awesome! Thank you for Sharing! 💯✴

  • @juankfayad5788
    @juankfayad5788 Před 3 měsíci

    If you use other file explorers, check if color filters can be applied to file types. For example, I use Dopus, and every executable file automatically gets a red background.

  • @deadby15
    @deadby15 Před 3 měsíci +1

    Shouldn't Windows Defendor block the disguised malware app when you click on it?

  • @Eeveewashere
    @Eeveewashere Před 3 měsíci

    Are you still effed if you right click on properties when you have doubts about it? And is there a downside to having Google Chrome asking you on every download where you want the file saved to?

  • @PGW90RU14
    @PGW90RU14 Před 3 měsíci +2

    I recommend change the setting of "File Explorer" to show file extension, and scan any file before open it using right click menu on a file.

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @michaelferreira2651
    @michaelferreira2651 Před 3 měsíci

    Because you are a security expert, let me ask you this. Can I block port 443 and 80 on router without affecting my ability to mange router from web browser on a local PC that has wired connection to router and wifi disabled? I am getting a lot of DoS Attacks on port 443 when I check router log.

  • @mbunds
    @mbunds Před měsícem

    These very basic tips are invaluable even for advanced users.

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @winwincsk
    @winwincsk Před 3 měsíci

    Useful information 👍

  • @morarucosmin6776
    @morarucosmin6776 Před 3 měsíci +2

    When using windows....first, go into Control Panel -> Folder options -> Disable "Hide extensions for known file types"

    • @dgggghfhfhfg
      @dgggghfhfhfg Před 5 dny

      when using wndows, understand that your entire OS is malware from a malicious company. then stop using it.

  • @xion637
    @xion637 Před 3 měsíci

    Unfortunately, depending on the size of the pdf, preview will not always work in file explorer. None of the workshop repair manuals for my vehicles can be previewed. They aren't password protected, you just can't preview them.

  • @featheredskeptic1301
    @featheredskeptic1301 Před 3 měsíci +2

    I've always had my system display file extensions and haven't been tricked into running mailware this way. I guess the reason why Windows doesn't come like that by default is because less experienced users can accidently change or delete a file extension while renaming a file, and not know what happened, or how to fix it.

    • @user-od4gs3iu4t
      @user-od4gs3iu4t Před 3 měsíci

      it won't happen "accidently" cause explorer asks if you want to change a file extension. But yeah this might be a "security" feature for masses, just in case

    • @featheredskeptic1301
      @featheredskeptic1301 Před 3 měsíci

      @@user-od4gs3iu4t People rarely read warnings like that. It's not beyond the realm of probability that they're just going to click "Ok", and then wonder what happened to their file.

  • @tech.curiosity
    @tech.curiosity Před 3 měsíci

    Good to know, thanks for sharing this.

  • @crollwtide9452
    @crollwtide9452 Před 3 měsíci

    2:05 This is why I dislike hiding file extensions...it makes it a bit more difficult to tell what the file type is at a glance. If you're not looking at a detail view that shows the Type column, this can be potentially confusing for an end user.

  • @louey2x
    @louey2x Před 3 měsíci

    I think you'r wrong in the browser. "always ask" setting so I decide where the file goes. I can monitor the download and tell it where to go and not have to worry about random whatever downloading because I get to see basically what it is first. So hit DL, PC asks where to save and I notice "Oh, that's not what I wanted" OR " PC ask where to save and I notice something off I can pick a specific location for the download to investigate later or cancel the download.

  • @Maxym-sk4zq
    @Maxym-sk4zq Před 3 měsíci

    I always tur on the option in my browser that prompts me every time I try to download a file, so nothing will be downloaded without me actually seeing the filename and extension and accepting the download

  • @Mr.C0ffee
    @Mr.C0ffee Před 3 měsíci

    Thanks for great videos! Any suggestion for an antivirus for gaming in 2024? 🙏🏼

  • @itenthusiast5988
    @itenthusiast5988 Před 3 měsíci +1

    Three things I like about your channel
    1. Informative for both noobs and pros.
    2. Ads placed at start or at the end.
    3. Explaining things with an example with less distraction and without external softwares
    Interesting of them all using your sponsor to showcase your example

  • @josephyeo6966
    @josephyeo6966 Před měsícem

    Very good advice thanks. Should be taught to every new employee and all students and pensioners like myself.

  • @louf7178
    @louf7178 Před 3 měsíci

    Good suggestions.
    I already do this.

  • @fredvomjupiter8849
    @fredvomjupiter8849 Před 3 měsíci

    Thank you for that very useful video. 👍👍👍

  • @mk83_Daniel_Williams
    @mk83_Daniel_Williams Před 3 měsíci

    Great advice, thanks.

  • @neemakhtarpandapk
    @neemakhtarpandapk Před 3 měsíci

    From where you download the Ransomware? I want to use to test some products for myself. Thanks in advance.❤

  • @davebrzeski
    @davebrzeski Před 3 měsíci

    One of the advantages to being a computer user since the early 90s is that I was used to all those settings, and didn't like the new less secure defaults when Microsoft introduced them, so I've always changed them back out of preference.

  • @TruthSeekerAll
    @TruthSeekerAll Před 18 dny

    Thanks for this great tip.

  • @oddcraft18
    @oddcraft18 Před 3 měsíci

    Does it increasure secury even more by disabling running exe files in downloads? May prevent yt'ers from getting hacked

  • @FPI23
    @FPI23 Před 3 měsíci +1

    Good tips. I use Comodo Firewall by the way.

  • @VultUxTube
    @VultUxTube Před 3 měsíci

    What I don't understand is why Micro$oft doesn't make it the default showing file extensions?
    We at IT keep repeating every day for users not to double-click on executables, but it becomes difficult when the company that manufactured the OS hides this information by default.
    PS: yes, I know there is a GPO that forces extensions to be shown, I already apply it to the company, but I think Micro$oft could help by doing its part.

  • @DayzGone
    @DayzGone Před 3 měsíci

    I thought "show file extension" was on by default. It is whenever I install Windows 10. I turn it off. It's kind of annoying when renaming files.

  • @davidhollfelder9940
    @davidhollfelder9940 Před 3 měsíci

    I don’t see how you got the menu bar (with “new” on the left and “details” on the right).

  • @ardeof
    @ardeof Před 3 měsíci +1

    I've a question about Windows Defender. Defender has this thing called "Isolated Browsing", or more specifically the Window Defender Application Guard. How effective would that be in preventing viruses? Should I have this enabled?

    • @Ilurk247
      @Ilurk247 Před 3 měsíci

      It's not 100% effective, you still need anti-virus software but yes it should be enabled.

  • @XSpImmaLion
    @XSpImmaLion Před 3 měsíci

    Agreed that file extensions should be visible by default...
    But I think this is something we've been warning about since... I think Windows 7 made that change, right? Making file extensions hidden by default. I vaguely remember it being a major security complaint back when the shift was made.
    Now, let me ask a question here. Is there a way to simply block the execution of certain extensions, period? Like, an administrative tool that does not let people run say... bat, exe and msc files? Or at least puts some 2 layers of warning on top of it before execution? Or, for instance, forces a timed quarantine into all new files.
    Sounds trivial to me to implement something like this. Particularly on the often abused .msc extension.
    Given that a whole ton of people don't have the habit of running a bunch of recently downloaded executables anymore, a tool that does this should be very useful to go against this sort of attack.
    I know some anti-virus and anti-malware tools already detects recently downloaded executables and nags users to scan it... Malwarebytes does this. And you have the usual Windows Security warning... but I think more options and control over this could be good, particularly for administrators.

  • @jacfmx1882
    @jacfmx1882 Před 3 měsíci +6

    And can a normal PDF include malware?
    For example, I usually open PDF files on the web browser by default (so the icon changes for the web browser icon instead the one showed in the video) but can I PDF, which displays content, still include malware?
    P.S. Thanks for the tips

    • @Tomas-yg1xz
      @Tomas-yg1xz Před 3 měsíci +1

      Not sure if it's possible to have an infected PDF (with correct extension) but I think the icon of an EXE file can be dynamically generated (just like picture thumbnails) so the malicious executable could easily look up what is the default app for opening a PDF on your computer and set it's own icon to look exactly the same.

    • @machintrucGaming
      @machintrucGaming Před 3 měsíci +1

      Or even have an exe files disguising as a .pdf file extension ? So windows tells you it's a pdf, but when you click on it instead of opening pdf reader it launches itself ? Are we really safer if we display the extension ?

    • @vandecasa3795
      @vandecasa3795 Před 3 měsíci +1

      @@machintrucGaming No. That won't work. If file extension is indeed pdf then Windows will open it with whatever your default pdf viewer is.

    • @tablettablete186
      @tablettablete186 Před 3 měsíci +3

      Yes, it can. In fact, Adobe thought for some reason that is was a good ideia to add a scripting langauge to a PDF document (is is similar to JS).
      I will later add the name of the scripting langauge, because I don't remember right now.
      Edit: Adobe added actual support for JavaScrpit... 💀

    • @user-od4gs3iu4t
      @user-od4gs3iu4t Před 3 měsíci +1

      scripts macros and like this are a huge security flaw for any office suit, as well as for pdf suit.
      Small correction: if file has a .pdf extention, then windows will ATTEMPT to open it with your default pdf reader. However your .pdf file may have some metadata which will open some more information about the file, and windows may automatically find a right way to proceed.
      Displaying the extension, and - not less important - the size, and other metadata will give you an idea about the file and might become an important signal about the way how to handle it.
      So answer is Yes, displaying extension, size, creation date, permissions etc are a sign of a good practice for file handling
      As for JS, and other scripts and macros, for most users it would be advisable to go through your office/adobe or other suits that you use and carefully look through all the security/privacy settings and disable/harden your settings. Disable JS by default. You will get prompt if your file asks to run the script.
      Disable internet access. You will be asked if file has a link or requires connection.
      And so on

  • @SMASHINGblargharghar
    @SMASHINGblargharghar Před 3 měsíci

    This is a nice reminder for me. Most users have no idea about shit that seems instinctive to me. I should share this channel with family...

  • @nakotaapache4674
    @nakotaapache4674 Před 3 měsíci

    great basic and powerful advice

  • @Graham6410
    @Graham6410 Před 3 měsíci

    The show file extensions option is one of the first settings I turn on in Windows.

  • @alphatech__
    @alphatech__ Před 3 měsíci

    File extension doesn't have to be at the end of the file ,it can be in the middle, like apdf.exe can be exepdf.a

  • @airfixer9461
    @airfixer9461 Před 3 měsíci

    Good tips, a lot of people will benefit from them.

  • @Xudmud
    @Xudmud Před 3 měsíci

    It might be my imagination, but the color of the red background on the "fake" PDF looks slightly off. Though without the side-by-side it definitely wouldn't have been noticeable.

  • @RK-ly5qj
    @RK-ly5qj Před 3 měsíci

    You may also create material about "how to check if a website isnt malware-ish" or how to verify domains etc etc :)