How to never accidentally run Malware: Must Have Windows Tweaks

Поділитися
Вставка
  • Опубліковано 18 лис 2024

КОМЕНТАРІ • 798

  • @notme232
    @notme232 8 місяців тому +2379

    file extensions should be enabled by default, the fact that it is even an option is a major windows security flaw.

    • @nabieladrian
      @nabieladrian 8 місяців тому +116

      ​@osniko How can you expect such tiny little startup like MS to simply allow rename A file, not THE file. Of course they can't.

    • @IIGrayfoxII
      @IIGrayfoxII 8 місяців тому +60

      @osnikoThis was an issue in the XP days, where the whole filename and extension was selected, but since vista the name part is selected and you must manually move the cursor to the extension part.

    • @alphatech__
      @alphatech__ 8 місяців тому +7

      File extension doesn't have to be at the end of the file ,it can be in the middle, like apdf.exe can be exepdf.a

    • @TheLukemcdaniel
      @TheLukemcdaniel 8 місяців тому +17

      I'm okay with it being an /option/, but it should be an opt-IN not an opt-OUT.

    • @TheLukemcdaniel
      @TheLukemcdaniel 8 місяців тому

      @@alphatech__ True. I think I have seen some do that, where they name it "totallynotsketchy.pdf.scr"

  • @AviatingRandom
    @AviatingRandom 8 місяців тому +1020

    I would argue it’s best to turn “ask me where to save each file” on because while it may be a little annoying, it will show you the file extension when you download it and it’s useful to ensure a site isn’t downloading files in the background.

    • @joepjoep9531
      @joepjoep9531 8 місяців тому +8

      This is about not instinctively open it in your browser by taking away the button if you don’t you still can

    • @rizkyadiyanto7922
      @rizkyadiyanto7922 8 місяців тому +77

      browsers these days actualy warn you if you download exes.

    • @theycallmeken
      @theycallmeken 8 місяців тому +6

      Great suggestion

    • @portman8909
      @portman8909 8 місяців тому +12

      I have on not just for that but I don’t want to clutter my downloads folder. I only use it for exe. The rest go into other folders.

    • @crimsonkarma13
      @crimsonkarma13 8 місяців тому

      @@rizkyadiyanto7922 does it? I have only downloaded trustable exe so I have yet to see that error

  • @lil----lil
    @lil----lil 8 місяців тому +52

    The people that are most in need of watching this video aren't watching it. The people that are hyper-aware of virus/scams (me) are watching it. That's life.

  • @TheNkatsar
    @TheNkatsar 8 місяців тому +239

    Showing file extensions is the first tip I would suggest, it would immediately distinguish between the 2 files in the video

    • @chrisseal1467
      @chrisseal1467 8 місяців тому +12

      Yes, why is this not step one in the video. The rest of the things are unnecessary.

    • @x-user3462
      @x-user3462 8 місяців тому

      ​​@@chrisseal1467there also maybe file somexe.pdf that is actually an exe (som\u202Efdp.exe) with RTLO in filename, so showing file type in table view is a great tip.

    • @gramblor1
      @gramblor1 8 місяців тому +4

      I don’t think he’d have a very long video if he did that.
      I still found it useful, though.

    • @samfkt
      @samfkt 8 місяців тому +11

      And turning preview pane off..... it can execute malware jyst by previewing it

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @Inventors_Toolbox
    @Inventors_Toolbox 8 місяців тому +528

    Worst thing Microsoft ever did was hide the file extension by default. Would that really have confused anyone? What they should set explorer to do is have all executable show up in an obvious contrast color or highlight scheme with a 'caution this is an app' identifier next to it. Make people look and go why is that highlighted like that.

    • @UNcommonSenseAUS
      @UNcommonSenseAUS 8 місяців тому

      Microsoft is owned by Israel, so nevermind clicking a pdf, if you're running Windows you're already infected with state sponsored malware

    • @DezXereanas
      @DezXereanas 8 місяців тому +3

      Wasn't it default in windows xp?

    • @ayoCC
      @ayoCC 8 місяців тому +3

      Could maybe show it separately or inside the file icon or recolored as well so that it pops out.

    • @Inventors_Toolbox
      @Inventors_Toolbox 8 місяців тому +5

      @@ayoCCExactly!, the question then becomes if you and I can see this almost immediately multiple people at Microsoft must have as well. They then decided that, no were not going to implement this obvious and simple fix. My question becomes, why? There must be some overriding motivation to not do this, I just don't see what it could be.

    • @paulfrayne6519
      @paulfrayne6519 8 місяців тому

      Directory opus does this, and sadly it is not cheap to purchase a license in some places

  • @TheCocoaDaddy
    @TheCocoaDaddy 8 місяців тому +148

    I'm fortunate I've never "accidentally" clicked or run an infected file and I've never been hit, personally, with a malware infection. Several of my friends have but I haven't. I think videos like this can really be helpful so thanks for posting!

    • @youravghuman5231
      @youravghuman5231 8 місяців тому +19

      The fact that you watched this video means you are not noob, so the probability of this happening to you is lower. You're not lucky, you're smart enough to use a pc unlike the majority of people.

    • @UNcommonSenseAUS
      @UNcommonSenseAUS 8 місяців тому +4

      Well you're obviously not reverse engineering enough malwarw

    • @MrMarbles
      @MrMarbles 8 місяців тому +2

      Send this to your grandma

    • @sdwone
      @sdwone 8 місяців тому +6

      Think before you click! And scan ANYTHING that you download from the Internet! Be paranoid about it, and opt for a guilty, until proven innocent stance!
      Works for me!

    • @UNcommonSenseAUS
      @UNcommonSenseAUS 8 місяців тому

      @@sdwone virus total is a useful tool...

  • @AyataHiragi
    @AyataHiragi 8 місяців тому +178

    I always found Microsofts idea to hide the extensions ridiculous, it was always shown in 95 98 and 2000 after all

    • @varski76
      @varski76 8 місяців тому +9

      That is the reason more of these attack are like this as normal users don't use the details view anymore

    • @tarwod1098
      @tarwod1098 8 місяців тому +6

      Most users don't know what it means anyway and they only get irritated

    • @ghostnoise1711
      @ghostnoise1711 8 місяців тому +2

      98 SE, hidden by default

    • @e1woqf
      @e1woqf 6 місяців тому +4

      @@tarwod1098 Nobody should use a computer without some basic knowledge.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @TeaBurn
    @TeaBurn 4 місяці тому +17

    Former game dev here. I've heard horror stories of my colleagues who think they're interacting with a potential business investor, open what they thought was a pdf to check the details in the proposal, and end up losing access to the only PC in the studio that has the one license key for a program that we needed to essentually make sure we can deliver the product on time. They did not make the deadline. Goes to show you should never put all your eggs into one basket. This is a good video to get us used to changing our mindset, and hopefully get rid bad habits of jumping the gun, clicking something we assume to be what it is.
    I personally use the "Ask to save" and scrutinize it. Way too many instances of saving an image preview, only for it to be a webp I have no use for.

  • @wolf1438
    @wolf1438 8 місяців тому +77

    In our country we got bear issues - picking up trash. So they are trying to develop better trash bins. There was an article interview with one of the developer when he was asked question why he just simply do not make more sophisticated mechanism. Here is his answer - you know the boundaries between the smartest bear and dumbest human is pretty narrow. In other words if I set up in our company group policy to show file extensions in few days I will have a dozens of tickets on IT people complaining they cannot open their powerpoint, excel or word document, because during renaming process they deleted file extension.

    • @ghoulbuster1
      @ghoulbuster1 8 місяців тому

      Sub 80 IQ barely functioning brain 😂

    • @romanm.4763
      @romanm.4763 8 місяців тому +10

      That developer (a smartest bear?) could write a renaming function which prevents to change a file extension or at least warnings about it

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому +4

      lmfao. the truth in this hurts

    • @ZeldagigafanMatthew
      @ZeldagigafanMatthew 2 місяці тому +4

      Windows gives warnings when you're about to change the extension, and in more modern releases leaves the extension unselected by default when you go to rename the file.

    • @leecowell8165
      @leecowell8165 27 днів тому +1

      linux doesn't care it examines the header to determine the default app to use to open it.. but you can override it.

  • @B0tAcH1
    @B0tAcH1 8 місяців тому +36

    Adding to this, you can also use the group by type function for files. adding that clear separation that you can collapse and expand at will is very helpful

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @npsit1
    @npsit1 8 місяців тому +80

    Anytime I have to log into a new computer, I always turn on file extensions. It's a habit from using DOS, I think.. It takes me 10 to 15 minutes changing all the settings from default - because I hate most of the default Windows settings.

    • @pleskbruce
      @pleskbruce 8 місяців тому +2

      Yes! And many other tweaks, such as resetting registry values, will speed up windows, allow me to reset file locations, etc.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @itenthusiast5988
    @itenthusiast5988 8 місяців тому +4

    Three things I like about your channel
    1. Informative for both noobs and pros.
    2. Ads placed at start or at the end.
    3. Explaining things with an example with less distraction and without external softwares
    Interesting of them all using your sponsor to showcase your example

  • @Seriously_Unserious
    @Seriously_Unserious 8 місяців тому +16

    As somebody who's studied network security and as a web developer who makes sure client's websites are secure and had clients get hacked before, I can definitely say these simple steps are a great first line of defense. May hacks like the one that took down Linus Tech Tips last fall could have been prevented just by doing these simple steps.

    • @pirateofpacific
      @pirateofpacific 8 місяців тому +1

      Since you studied network security, let me ask you this. Can I block port 443 and 80 on router without affecting my ability to mange router from web browser on a local PC that has wired connection to router and wifi disabled? I am getting a lot of DoS Attacks on port 443 when I check router log.

    • @Ilurk247
      @Ilurk247 8 місяців тому

      @@pirateofpacific Ask your question to google like this "without affecting my ability to mange router from web browser on a local PC that has wired connection to router and wifi disabled can I block port 443 and 80 on router?" The answer for your particular setup will be on the list of options. (I think probably port forwarding is the answer, but best to see what you need.)

    • @izgler
      @izgler 6 місяців тому

      @@pirateofpacificdepending on what you mean by “block”. If you truly block all 443 and 80 traffic you won’t be able to use the internet. Decent routers should all drop the DDOS packets anyway. If you aren’t hosting anything on 443 or 80 you’ll have nothing to worry about.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      @@pirateofpacific just send your login page to a defferet port

  • @photoshopman1972
    @photoshopman1972 8 місяців тому +14

    The only issue with removing the download prompts on an browser is if you have very poor internet connection, the user will not know if the download has failed and will not allow the user to have a chance to restart the download.
    On a legit file that is.
    Guess there is really no full proof way here. It also assumes that the user also knows the differences as well. An older person or person with very little computer knowledge will not know that difference.
    The true way is for the computer to be smarter than the individual using it with system policies and software that can prevent things like this from occurring.
    Still I do like some of the tips you provide here and thank you for tips!

  • @x-user3462
    @x-user3462 8 місяців тому +31

    Configuring windows explorer to show file extensions is the first thing I do after windows installation. Show type in the table view is also a great tip because of the RTLO attack.

    • @samfkt
      @samfkt 8 місяців тому +1

      And disabling preview pane, it can execute malware

    • @filipetrujeira3359
      @filipetrujeira3359 8 місяців тому +4

      @@samfkt Do you have any sources on that?

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @Aranimda
    @Aranimda 8 місяців тому +11

    Never ever open ANY file when extensions are hidden.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @noneofyourbusiness1304
    @noneofyourbusiness1304 8 місяців тому +436

    I highly disagree with turning off "Ask to Save" in browsers. Not only can it show the type of file you are even saving, it also can stop random files being downloaded automatically if you happen to click a wrong link, since it now always tries to ask about the file, overall giving the chance of saving you from even having the chance to click the file to begin with.

    • @TheLukemcdaniel
      @TheLukemcdaniel 8 місяців тому +7

      Maybe turn it off temporarily if you're scraping a ton of files from one site real quick, but ftmp, the daily driver setting should be to ask for any downloaded file.

    • @mienoni5330
      @mienoni5330 8 місяців тому +15

      I can see why he's suggesting this, because it creates the habit of you needing to open explorer before opening anything, meaning you WILL see the extensionand the type for sure (which many non teccy people don't), but yeah it's never a good idea to not be able to stop something to be downloaded.

    • @MathiasYmagnus
      @MathiasYmagnus 8 місяців тому +1

      Yup. What OP(Nonya) typed

    • @ArkenGAMES
      @ArkenGAMES 8 місяців тому +2

      Yeah I am using Chrome and it always shows the file type. If that can be faked too I'm done for.

    • @SlinkyD
      @SlinkyD 8 місяців тому +2

      ​@@ArkenGAMES File extensions can be bogus. Gotta check the magic and default program for each file type.
      The fact that 30+ years later this is still a problem because of basic computer knowledge being too troublesome to teach (not really) is a problem yet everything being computerized.

  • @johnmarmalade4345
    @johnmarmalade4345 8 місяців тому +8

    Great video for security awareness!
    I just keep the "show downloads when a download starts" switched on so that I know when something is downloading when there shouldn't be anything downloading. Using this, I find out about the strange javascript downloads some sites drop on my computer.
    I've also been using all the other tips since a few years ago. I also scan files typically infected with malware like PDFs, Microsoft office files, and executables before I run them. Kept me pretty safe the past few years.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @kubbbercraft
    @kubbbercraft 8 місяців тому +4

    file name extensions enabled is just in general a practical must for so many usecases. mostly to figure out what fileformats you are trying to open where or what they can, especially with photos or videos

  • @PatrickBijvoet
    @PatrickBijvoet 8 місяців тому +3

    The company who build my computer, must have seen your video. All settings where as you said. But thanks for making me aware.

  • @alexl7213
    @alexl7213 25 днів тому +1

    The first thing I do when I sit in front of a new computer is go to file explorer >visualization options> activate - show hidden folders, units, and files, and deactivate - hide extensions+hide operating system protected files.
    Then I slap an usb drive in it, copy a word file into it and check the usb drive. Most viruses will immediately add their poison into the usb drive, sign of an already infected windows pc.

  • @crollwtide9452
    @crollwtide9452 8 місяців тому +5

    2:05 This is why I dislike hiding file extensions...it makes it a bit more difficult to tell what the file type is at a glance. If you're not looking at a detail view that shows the Type column, this can be potentially confusing for an end user.

  • @lensy6
    @lensy6 5 місяців тому +1

    its insane that view file extensions not only isn't the default but that its even an option to hide it at all

  • @amaggard14
    @amaggard14 Місяць тому +1

    I’ve already learned all this the hard way 15 years ago, but I think every kid or teen should learn this before using a computer. Also getting an AdBlocker like ublock origin, an antivirus with realtime protection and shady website alerts like malwarebytes (and the extension), and knowing about fake download buttons on those crappy link shortener websites is also very important for them to know. Learn from my mistakes and don’t kill 2 laptops, and have to factory reset your pc at least 4 different times like I had to when I was younger.

  • @miro007ist
    @miro007ist 8 місяців тому +2

    your videos put me right to sleep thank you so much. I haven't been able to sleep for the past three years and your videos fixed my sleep

  • @robinweiland7533
    @robinweiland7533 8 місяців тому +1

    Really useful, espeacially after I realized that just enabling extensions might make me even more vulnerable to tricks with rtlo characters in filenames

  • @inthewoods6271
    @inthewoods6271 8 місяців тому +3

    Great video, Id only be hesitant to enable preview files since in some cases it was used to launch the malicious file

  • @ansfridaeyowulfsdottir8095
    @ansfridaeyowulfsdottir8095 8 місяців тому +54

    I always set my machine to display extensions and file type and always View in Details.
    It really annoys me when LoseDoze changes it back to Icons or some other view for certain file types. It just wastes my time.
    {:o:O:}

    • @samfkt
      @samfkt 8 місяців тому +2

      Preview pane should be disabled too

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @SMASHINGblargharghar
    @SMASHINGblargharghar 8 місяців тому

    This is a nice reminder for me. Most users have no idea about shit that seems instinctive to me. I should share this channel with family...

  • @ThePretender1
    @ThePretender1 8 місяців тому +4

    05:10 This is my default folder view since windows XP, a long time i have reached this conclusion. People are so unaware of the risks! 😥😥

  • @abdullahaljalil5218
    @abdullahaljalil5218 8 місяців тому

    It's a small tweak but very useful and helpful to have the habit not to rely on thumbnails

  • @hifiandrew
    @hifiandrew 8 місяців тому +2

    Two other things, if you're really on top of things. Have a completely separate local account for admin rights & do not disable UAC.

  • @PGW90RU14
    @PGW90RU14 8 місяців тому +2

    I recommend change the setting of "File Explorer" to show file extension, and scan any file before open it using right click menu on a file.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @juliocesarpereira4325
    @juliocesarpereira4325 8 місяців тому

    Some of these steps I've always done such as always open a recently downloaded file on windows explorer download folder. As I watched the video, I changed the view settings to show the extension. Very useful tips. Thanks.

  • @CT-ue4kg
    @CT-ue4kg 4 місяці тому

    I follow this guide each time i set up an employee laptop now - thanks

  • @featheredskeptic1301
    @featheredskeptic1301 8 місяців тому +4

    I've always had my system display file extensions and haven't been tricked into running mailware this way. I guess the reason why Windows doesn't come like that by default is because less experienced users can accidently change or delete a file extension while renaming a file, and not know what happened, or how to fix it.

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 8 місяців тому

      it won't happen "accidently" cause explorer asks if you want to change a file extension. But yeah this might be a "security" feature for masses, just in case

    • @featheredskeptic1301
      @featheredskeptic1301 8 місяців тому +1

      @@ТоварищКамрадовСоциалистКоммун People rarely read warnings like that. It's not beyond the realm of probability that they're just going to click "Ok", and then wonder what happened to their file.

  • @mbunds
    @mbunds 7 місяців тому

    These very basic tips are invaluable even for advanced users.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      i can spoof the extensions in 10 seconds. also, windows IS malware, if you run windows, youre already selling your privacy, why even care about hackers?

  • @robbiepilot
    @robbiepilot 8 місяців тому

    Excellent advice - thanks! Have made these changes and tweaks. Must get into cast-iron routine with downloads.

  • @D3K018
    @D3K018 3 місяці тому +4

    Windows is actively screwing up users by hiding the extensions by default, I never understood the logic of it, it's too annoying! Every linux OS has extensions by default...

  • @davebrzeski
    @davebrzeski 8 місяців тому

    One of the advantages to being a computer user since the early 90s is that I was used to all those settings, and didn't like the new less secure defaults when Microsoft introduced them, so I've always changed them back out of preference.

  • @abitterberry2149
    @abitterberry2149 8 місяців тому

    YES, thank you !!! I'm forced to harass my entourage because Microsoft chose to hide by default the most important property of a file... Who the F complained about seeing extentions?
    Even if you're not tech savvy, you've probably heard that .exe can be dangerous, you alse probably know that a pdf ends with .pdf, but you probably don't take the time to go through every settings.
    Settings pages which are themselves increasingly fragmented and hidden behind layers of menus. This is so frustrating, we're talking about an issue that could be fixed in a few minutes !

  • @supecoop
    @supecoop 8 місяців тому

    Simple but effective ideas to make your downloads safe to open. Thanks

  • @nakfan
    @nakfan 8 місяців тому

    Great tips 👍 Thanks too for giving a short glimpse of Malwarebytes.

  • @SMJSmoK
    @SMJSmoK 8 місяців тому +2

    The sad thing is that we used to joke about "Linkin Park-Numb.mp3.exe" 15 years ago, and apparently, it's still relevant. I guess that Microsoft didn't get the memo that hiding file extensions by default is a horrible idea.

    • @portman8909
      @portman8909 8 місяців тому +1

      Even with that many users will be fooled into downloading it without a check from the IT team.

  • @stultuses
    @stultuses 8 місяців тому +16

    You check the extension but even if they change the type, try opening it up in notepad
    Notepad never opens it up as an application, even pdf's open up as a pure text file and you can look at the contents header and see a pdf type in the file with pdf version number etc. An application will open as a text file, and you can quickly see the data section of the file and the payload etc, and you can then exit and delete the file

    • @DigitalDissident
      @DigitalDissident 8 місяців тому +6

      no one's be opening or analysing file contents in Notepad. impractical & cannot be understood

    • @Anjum9694
      @Anjum9694 8 місяців тому +3

      You mean a hex editor? If were going through that route might as well use the proper tool

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому +1

      lol, the 2453678765435678 notepad haks that have been evolving since windows 95 would disagree lm
      fao

  • @joinglobalnetworks
    @joinglobalnetworks 8 місяців тому +1

    Most important thing is that to make sure the computer mouse is functioning without any problems in its buttons because sometime if if you click one the file using your moue your mouse buttons got dirt between then there is a chance that you doouble clickj the file/application without noticing that you aleady did that, so the teporary solution is that you still can use your keyboard to move up/down with your arrow keys on your keyboard and when use your keyboard to investigate do normale task whether riht click or double click but with the keyboard capabilities, this will ensure that you don't make anyting wring by mistake to your pc.

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      if you think thats gonna help youre crazy bro. windows IS malware

  • @Hutch2Much
    @Hutch2Much 8 місяців тому

    the fact that a malware attack happened RIGHT AFTER windows 95 turned off “show file extensions” by default and they DIDNT immediately switch it back is unbelievable

    • @MegaSunspark
      @MegaSunspark Місяць тому

      That's just a coincidence. You think an average Joe/Jane blow would know what they are even looking at when it comes to extensions?

  • @jvanderhorst2011
    @jvanderhorst2011 8 місяців тому +1

    Really good video, viewing file ext is a MUST.

  • @thelastgeneration102
    @thelastgeneration102 6 місяців тому

    Yes! These kinds of details for security are much welcome! Thank you!

  • @frankfields6283
    @frankfields6283 8 місяців тому

    ABSOLUTELY SPOT ON ! i DO MOST OF THE THINGS THIS GENTLEMAN SUGGESTS AND THEY HELP!!! i LEARNED OVER THE YEARS BY MAKING A FEW BAD MISTAKES TO DO THE SIMPLE THINGS HES SUGGESTING ...DON'T YOU MAKE THE SAME MISTAKES AND FOLLOW THIS MANS ADVICE. THANK YOU!

  • @makojuicedaniel9307
    @makojuicedaniel9307 3 місяці тому

    Never look at files in large like that, always look at them in details.

  • @rjjeffreys
    @rjjeffreys 8 місяців тому

    PDF malware has become one of the leading causes of ransomware infections on PC’s. As an MS MVP (Most Valued Professional), I believe you have well addressed these most important fail-safe settings to prevent PDF malware infections. But I feel that the prompt in your browser to "Ask to Save" should remain enabled. I also use MWB pro (have for many years) and it is well worth the price.

    • @sdwone
      @sdwone 8 місяців тому +2

      I honestly don't bother with PDFs anymore! It's not just the security flaws, but the constant updates of software, like Adobe, which also makes my blood boil!

    • @BettysBike
      @BettysBike 8 місяців тому

      Have you tried the other free, low bloat, pdf viewers on Google play store?​ @@sdwone

    • @rjjeffreys
      @rjjeffreys 8 місяців тому +1

      ​@@sdwoneIt's hard to avoid them, as they are basically used by almost everyone and are everywhere now. Adobe has become the Spawn of Satan to me with their Machiavellian subscription model.

  • @xav9793
    @xav9793 8 місяців тому

    My gf reccomend me this and I'm surprised me and you both use an Asus brand PC, shout-out to her and you my good sir!

  • @morarucosmin6776
    @morarucosmin6776 8 місяців тому +1

    When using windows....first, go into Control Panel -> Folder options -> Disable "Hide extensions for known file types"

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      when using wndows, understand that your entire OS is malware from a malicious company. then stop using it.

    • @chaos.....
      @chaos..... Місяць тому

      @@dgggghfhfhfg ok cope

  • @juwright1949
    @juwright1949 8 місяців тому

    Excellent! Just subscribed. Everything makes total sense. Thanks

  • @ironkrieg3368
    @ironkrieg3368 8 місяців тому

    Thanks for posting this. :) Made a couple of the changes recommended.

  • @kittentheboss2796
    @kittentheboss2796 8 місяців тому

    I have been saying this for ages but Microsoft should enable file extensions by default on their crapy os. I don't care you don't use it or you screw something up. File extensions help users learn different file types early on and are just extremely helpful. Especially for windows 7.

  • @johnrichardson4507
    @johnrichardson4507 8 місяців тому

    This is brilliant I have learned how to protect and not accidentally open malware thanks

  • @TimVels
    @TimVels 8 місяців тому +8

    I don't understand why people use icon/thumbnails, it is much faster to go through details. Since I have used detail view I had stuck with it for many years now. Never had an issue with any virus.

    • @Sonario648
      @Sonario648 Місяць тому

      I use Icon thumbnail for images and videos that I've saved. It helps me know which image/video is what.

    • @TimVels
      @TimVels Місяць тому

      @@Sonario648 That's good. But for all the files if you use this view you will take time to search through when looking for something. You give a try for detailed view.

  • @markoshun
    @markoshun 8 місяців тому

    Totally agree with viewing file extensions before opening new files. But I prefer to use the browser’s download window where it shows the file with extension and I can choose to view it in it’s destination folder before running it. Eliminates a couple steps. And I often like to see download progress and keep track of where file is going.
    Seems like the browsers have already addressed these issues.. with a couple less steps.

  • @TechNow-z7m
    @TechNow-z7m 8 місяців тому +1

    Awsome video! I already had vew file extentions on as i am a software developer and i like that feture already. Nice tips!

    • @dgggghfhfhfg
      @dgggghfhfhfg 5 місяців тому

      you develop on windows? no wonder so many softwaare companies cant keep their corporate secrets secret

  • @crollwtide9452
    @crollwtide9452 8 місяців тому

    This, in a nutshell, is why you should never open ANY e-mail attachments from unknown/unverifiable sources or from parties you do not expect to hear from. Delete them on the spot.

  • @rolandschlossmacher1859
    @rolandschlossmacher1859 6 місяців тому

    1. I ever have enabled the option details
    2. I never save sensible files on the internal disk
    3. I never open for me unknown files
    4. I use as much as possible my - especially for bank account transactions - my Mac or my Unix-Based-Machine (with Mate GUI) ….yes I know Mac is based on Unix …I mean my dedicated Unix machine.
    5. If I need to use my Windows PC I do the recommended security checks / updates as much as possible
    6. If this is a file I need and still unsure safe or not - I transfer it to a special Notebook with minimal software equipped that machine I can re-build quickly
    Hope this will help as much as possible but I cannot close out my self to make failure too

  • @RudysRetroIntel
    @RudysRetroIntel 8 місяців тому +1

    Excellent video and tips! Thanks for sharing

  • @outcast4973
    @outcast4973 4 місяці тому

    Thank You. I did not know that icon can be changed on my computer, without my knowledge.

  • @peacefusion
    @peacefusion 5 місяців тому

    Bless all people that make the world a safer place.
    You never know when someone just wants to give back to others and give a helping hand.
    Life is harsh and those that suffered know it well.

  • @Funkx2g
    @Funkx2g 8 місяців тому

    Another strong reason to keep away from weird websites and only download pdfs and documents , books even , from the internet archive
    God bless

  • @sethbenjamin9326
    @sethbenjamin9326 Місяць тому

    The disguise thing is super old trick. Since (or before) yahoo messenger, there are icons of pictures, mp3, or other icons were used to disguise shortcuts (or url with dos commands) to do many crazy things just like todays virus, malware, backdoor would.
    VB macro can still be a threat as well.
    Since MS DOS, i’ve always show extensions. 😂

  • @snazzysailor
    @snazzysailor 2 місяці тому

    Basic but gold. Thank you for your service.

  • @PoseyLane
    @PoseyLane 2 місяці тому

    Thank you so much for the tutorial. Yes, this was helpful and very easy for a non IT person to understand.
    My husband works for a company that’s been hit by ransomware twice. That had to pay up a good sum of money. Maybe it’s time they invest in a top-notch IT professional-if they can pry open the budget that’s been locked tighter than their servers!

  • @mikinozz
    @mikinozz 3 місяці тому

    Thanks very much for this information. I’ve set up my PC accordingly.

  • @josephyeo6966
    @josephyeo6966 7 місяців тому

    Very good advice thanks. Should be taught to every new employee and all students and pensioners like myself.

  • @rursus8354
    @rursus8354 8 місяців тому

    Running Linux here, teaching Windows users how to program and manage their files. This idea of hiding the file extension to the user annoys me no end. Pupils complaining about their hosts files not working (needed for some tasks in network programming) and the file browser hiding the fact that the name is actually hosts.txt. In Linux you cannot get rid of viewing the file extension, you cannot change the icon of the file, and you cannot run exes from the file browser!

  • @lamikal2515
    @lamikal2515 8 місяців тому

    You should link that video to all and every LTT employee.

  • @jenb1973
    @jenb1973 8 місяців тому

    Very informative! Took me a while to figure out you must be in Edge (not Chrome) to change the download settings. Just wish it had been clarified in the beginning. Thx for the info!

  • @salsspar2132
    @salsspar2132 8 місяців тому +1

    thank you, had me 2nd guessing all my pdf's, checked them and im good but i put these good prevention methods that i looked. and personally i missed seeing extensions in my old pc

  • @polygonekoma
    @polygonekoma 8 місяців тому

    This is very valuable. I use those settings for so long time I didnt even thought about it beeing a thing because thats just soooooooo basic things. I can also recommend to not use default browser with you critical logins. Use another browser

  • @Cesar33-pl
    @Cesar33-pl 8 місяців тому

    Another good video for malware security, thank you!

  • @jpdemer5
    @jpdemer5 8 місяців тому

    Most of these suggestions are equally applicable to MacOS machines. The fact that an exe file won't run at all is a bit an added advantage, and the OS does warn you if you double-click on a downloaded application.

  • @StanWu
    @StanWu 7 місяців тому +1

    macOS or Linux users never worry about this…

  • @Khual
    @Khual 8 місяців тому

    That is an amazing tips to learn. Should definitely inform our peers about these basic tips that could someday come in handy.

    • @TheLukemcdaniel
      @TheLukemcdaniel 8 місяців тому +1

      Some day? This has been an issue since WinXP. That they STILL haven't fixed. A simple change to the default behavior(back to what it WAS) would fix this instantly.

  • @ut561
    @ut561 8 місяців тому

    i agree about the extensions, it's amazing microsoft still hides those !

  • @donturner3239
    @donturner3239 8 місяців тому

    Excellent tips, I will share this with my friends.

  • @redvex2114
    @redvex2114 8 місяців тому +5

    File extensions by default is a thing, but also remove the large icons viewing mode. Who uses that ? It's like asking for malware.

    • @ZeldagigafanMatthew
      @ZeldagigafanMatthew 2 місяці тому

      Easier to make sure you hit the one you intend with large icons.

  • @Skeware
    @Skeware 4 місяці тому

    I've always had file extensions turned visible on all my computers over the years, that's one of the first things I do on a new PC.
    Not only for safety but I also need to see that info quickly while working.

  • @7john7able
    @7john7able 6 місяців тому

    Very helpful. I've never done it, but I uselly use a Linux O/S
    Just got my first Windows computer in 20 years. Wish me luck 🙄

  • @PlutoniumDG
    @PlutoniumDG 8 місяців тому +3

    I always have "ask me where to save each file" on. That way i can see what I'm downloading before it even downloads. One time i clicked on a fake link that automatically tried to download something, thanks to my setting i could prevent that from happening

  • @FPI23
    @FPI23 8 місяців тому +1

    Good tips. I use Comodo Firewall by the way.

  • @mkatakm
    @mkatakm 8 місяців тому

    The man is working hard not to enable "show file extensions".

  • @Rivenworld
    @Rivenworld 8 місяців тому +1

    Great advice, thank you for sharing.

  • @HenryCalderonJr
    @HenryCalderonJr 8 місяців тому +1

    Thank you I have become lazy. So time to go old school and do list again

  • @dONALDBLOOD
    @dONALDBLOOD 8 місяців тому +3

    If it's still on my PC at this time, which I would be quite surprised about having proper security software, I usually right-click and scan it with my security software.
    It's amazing that windows hides file extensions by default since two decades, it's an insanely dangerous practice.

  • @Consequator
    @Consequator 8 місяців тому

    I can't believe that MS still defaults to hiding extensions even though this has been a problem since forever.

  • @kane_lives
    @kane_lives 8 місяців тому +2

    Sorry, the entire premise is just wrong.
    If your big organization relies on individual non-technical workers to be paying attention every minute of every day to which types of files they open, as a deterrence strategy not to get infected, then you are dead lost already.
    Due to the law of large numbers someone will eventually be inattentive due to some kind of human factor: they were sick/sleepy/inattentive/having stressful family/personal relationship/stressful deadline issues that day and just clicked the infected file without giving security considerations a thought.
    Big organizations have dedicated security departments with dedicated enterprise security software to prevent exactly this scenario from happening.

  • @GYTCommnts
    @GYTCommnts 8 місяців тому +3

    I simply can't understand WHY file extensions are hidden on Windows as default. It's stupid and ridiculous.

    • @vandecasa3795
      @vandecasa3795 8 місяців тому

      Microsoft desperately wants to copy the look and feel of macOS. The difference is: macOS doesn't need file extensions in the first place because it looks at the file header to determine the file type.

  • @tzviasegal3003
    @tzviasegal3003 8 місяців тому +1

    Turning on show file extensions for known file types should be the first thing done, along with details view, for Windows computers. And while Malwarebytes has made some improvements, I still consider it a secondary security app. Maybe it's because I've had the licenses for a long time, well before they went from a 'forever' license to subscription. They were lackluster back then, but I kept them installed because it can't hurt and heck it is free lifetime anyway. I use another product with it and so far so good. I've been on the internet since dial up, and before that, to BBS's and never had an infection but it's 90% knowing what the score is and following best practice and 10% luck. The rest is education of family members...

  • @TheAnkit211
    @TheAnkit211 8 місяців тому

    On top of this tip , Best line of defense in this situation ,Use standard user accounts with all permissions stripped and use that account instead of an admin account . That way, it will prompt you for an admin pw. That's when you ll know it's an executable file and not a document .

  • @jacfmx1882
    @jacfmx1882 8 місяців тому +6

    And can a normal PDF include malware?
    For example, I usually open PDF files on the web browser by default (so the icon changes for the web browser icon instead the one showed in the video) but can I PDF, which displays content, still include malware?
    P.S. Thanks for the tips

    • @Tomas9970_1
      @Tomas9970_1 8 місяців тому +1

      Not sure if it's possible to have an infected PDF (with correct extension) but I think the icon of an EXE file can be dynamically generated (just like picture thumbnails) so the malicious executable could easily look up what is the default app for opening a PDF on your computer and set it's own icon to look exactly the same.

    • @machintrucGaming
      @machintrucGaming 8 місяців тому +1

      Or even have an exe files disguising as a .pdf file extension ? So windows tells you it's a pdf, but when you click on it instead of opening pdf reader it launches itself ? Are we really safer if we display the extension ?

    • @vandecasa3795
      @vandecasa3795 8 місяців тому +1

      @@machintrucGaming No. That won't work. If file extension is indeed pdf then Windows will open it with whatever your default pdf viewer is.

    • @tablettablete186
      @tablettablete186 8 місяців тому +3

      Yes, it can. In fact, Adobe thought for some reason that is was a good ideia to add a scripting langauge to a PDF document (is is similar to JS).
      I will later add the name of the scripting langauge, because I don't remember right now.
      Edit: Adobe added actual support for JavaScrpit... 💀

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 8 місяців тому +1

      scripts macros and like this are a huge security flaw for any office suit, as well as for pdf suit.
      Small correction: if file has a .pdf extention, then windows will ATTEMPT to open it with your default pdf reader. However your .pdf file may have some metadata which will open some more information about the file, and windows may automatically find a right way to proceed.
      Displaying the extension, and - not less important - the size, and other metadata will give you an idea about the file and might become an important signal about the way how to handle it.
      So answer is Yes, displaying extension, size, creation date, permissions etc are a sign of a good practice for file handling
      As for JS, and other scripts and macros, for most users it would be advisable to go through your office/adobe or other suits that you use and carefully look through all the security/privacy settings and disable/harden your settings. Disable JS by default. You will get prompt if your file asks to run the script.
      Disable internet access. You will be asked if file has a link or requires connection.
      And so on

  • @TANKBM
    @TANKBM 8 місяців тому

    Well done, my brother, for this wonderful video. It is true. A simple trick in the Windows file browser may save you from the virus trap.

  • @meshuggah24
    @meshuggah24 8 місяців тому

    MS taking away extension view by default is a massive security flaw.