Enterprise IT Support • Bangkok & Nationwide

Technology newsroom

Are downloaded files safe? 4 steps to check before opening to prevent computer damage and data leaks

Learn how to check whether files downloaded from the internet are safe in 4 simple steps, from checking the source, scanning with your computer's antivirus, using online services like VirusTotal, to checking the file extension, to prevent malware and keep your information safe.

Edited by SyncTech Solution Published Source Ask Leo
Are downloaded files safe? 4 steps to check before opening to prevent computer damage and data leaks

Did you accidentally download a weird file from the Internet and are afraid to open it? Whether it's free software, important documents, or email attachments, your hesitation is actually a good thing because that is the first line of defense against malware. This article from SyncTech Solution will guide you through a step-by-step process for checking files for general users, office employees, and SMEs so that you can confidently decide whether to open or delete the file.

Understand Before Fixing: Why Are Downloaded Files Dangerous?

When you download a file from the internet, it's like receiving a package from a stranger. Inside, it could be something you really want, or it might be something harmful that is hidden inside. Hackers often disguise dangerous files to look like document files (PDF, Word), installer programs (.exe, .msi), or compressed files (.zip, .rar) that we are familiar with.

When we double-click to open these files, what is hidden inside, called 'malware', will start working immediately. It can steal passwords, lock files for ransom (Ransomware), or control your computer remotely. Checking the files 'before' opening them is therefore the most important step in preventing damage.

Before Starting: Get Ready

Before you start checking any files, there is something important you need to do first:

1. Do not open the file under any circumstances: The first strict rule is 'do not double-click' that suspicious file at all. As long as it has not been opened, the file usually cannot cause any damage.
2. Check that your Antivirus is up to date: Your computer's antivirus program (such as Microsoft Defender that comes with Windows) should always have its virus database updated to the latest version to recognize new threats. Usually, the program updates automatically when connected to the internet.
3. Write down the name of the website you downloaded from: If you remember, write down the URL of the website where you downloaded the file, because the source is one of the most important pieces of information when evaluating credibility.

Safe way to do it: 4 steps to check files before running

Follow these steps to assess the risk of downloaded files

Step 1: Check the source and credibility
- WHAT: Assess the credibility of the website or email from which you received the file
- WHERE/HOW:
- Website: Is this the official website of the software manufacturer? For example, if you want to download the VLC Media Player program, you should get it directly from videolan.org, not from a program-sharing website full of ads. Pay close attention to the website name to make sure there are no deliberate misspellings imitating the real site.
- Email: Do you know the sender? Were you expecting to receive this file from them? Does the subject and content of the email seem suspicious? If you are unsure, contact the sender through another channel (e.g., phone) to confirm that they actually sent you the file.
- WHY: An unreliable source is the biggest warning sign. Files from official websites are usually safer than files from strange links or general file hosting websites.
- EXPECTED RESULT: You can distinguish whether this file comes from a trustworthy source or a suspicious source. If it comes from a very suspicious source, you can skip and delete it.

Step 2: Scan the file with the antivirus program on the computer
- WHAT: Use the antivirus program you already have on your computer (such as Microsoft Defender) to specifically scan that file
- WHERE/HOW: Go to the folder where you saved the file, right-click on the file, and look for a menu named "Scan with Microsoft Defender" or "Scan with [your Antivirus program name]" and click to start scanning (the menu name may vary in different versions of Windows or the program).
- WHY: This is the simplest and fastest initial check to see if the file matches the characteristics in the malware database recognized by the program.
- EXPECTED RESULT: The program will report the scan results. If it shows "No current threats" or "No threats found," it means the file has passed the first-level inspection. However, if there is an alert, follow the program's instructions to quarantine or delete the file immediately.

Step 3: Use online file scanning services for a second opinion
- WHAT: Upload the file to an online file scanning service website, such as VirusTotal.com, so that dozens of antivirus programs can help check it simultaneously.
- WHERE/HOW:
1. Open a web browser and go to www.virustotal.com
2. Click on the "File" tab and then press the "Choose file" button
3. Select the file you have downloaded and wait a moment for the website to upload and analyze the file
- WHY: No antivirus program is 100% perfect. Using VirusTotal is like asking for opinions from over 70 experts at the same time, increasing the chance of detecting new threats or threats that your computer's antivirus might have overlooked.
- EXPECTED RESULT: You will see the scan report pages from multiple Antivirus brands. If all brands show a green check mark (Undetected), it is highly likely that the file is safe. But if several brands alert with a red mark (Detected), it can almost be confirmed that the file is very dangerous.

Step 4: Check the file extension and icon
- WHAT: Check whether the file extension matches the type of file it should be
- WHERE/HOW: In File Explorer, look at the full file name including the extension, for example, Invoice.pdf is a document file, but if it is Invoice.pdf.exe, it indicates a program file trying to masquerade as a document. If you cannot see the file extension, go to the View tab at the top of File Explorer and check the "File name extensions" box.
- WHY: Hackers often use the "Double Extension" technique, or naming files with multiple extensions, and use fake icons to trick users into thinking the file is harmless. Seeing the real extension helps us avoid becoming victims.
- EXPECTED RESULT: You are able to identify what type of file it actually is if the extension does not match what is expected, for example, if you load a document but get a file .exe or .scr, delete it immediately.

Check Results

After completing all the steps, you will be able to better assess the safety of the file:

- High Security: Comes from the official website, scanned with the computer's Antivirus and found nothing, results from VirusTotal are all green, and the file extension is correct
- Suspicious (should be deleted): VirusTotal scan results show 1-2 vendors alerting (may be a false positive, but if this file is not really needed, it should be deleted), the source is unclear
- Dangerous (must delete immediately): The antivirus on the computer warns, VirusTotal reports multiple alerts, the file extension is .exe even though it should be a document file

If it hasn't healed yet (or unsure)

The most important rule is 'When in doubt, do not open it.' Deleting suspicious files is certainly better than risking your computer and all your data being in danger.

- Look for other options: Try to find the same program or document from a more reliable source
- Consult the IT department: If it is a company computer and the file is work-related, stop and notify the IT department immediately. Do not try to open the file yourself, as it may cause damage to the entire organization's system.

In summary, taking a few minutes to check a file for 2-3 minutes before opening it is a worthwhile investment for the safety of your data and devices. Make these habits a regular practice, and you will use your computer with greater peace of mind.

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.