@mh holy crap, yup, seems maybe the only way to truly protect your machine is to run any files and internet connections thru a VM (tho i wouldn't be surprised if someone's found a way around that too).
only safe thing i have with this machine, it seems, is windoze can't see any of my linux partitions at all. seems like a windoze virus won't execute on linux so possible that linux/win10 machine doesn't pose a risk tho win/win does