find the domain name of the ad (for exemple: thisisanad.com)
open cmd in administrator
type:
notepad C:\Windows\System32\drivers\etc\hosts
once your file is opened, redirect the domain to 0.0.0.0 or 127.0.0.1
for exemple ad the line:
0.0.0.0 thisisanad.com
and it will block the site...
yes you can if you don't trust the files
you can use sandboxie or a VM
you can check in ressource monitor what happening in real time (network and process) to see if anything weird goes
or use Linux, there way less attacks on it, but you'll need to master cli and the system