Create a virtual disk file for Windows 10

Prev Next

If you are using Windows 10, use these steps to create the virtual disk file.

  1. From the installation wizard, select the language, time and currency format, keyboard or input method, then click Next.

  2. Click Install Now, then click Next.

    Installation process is completed in various stages. The setup is first initialized.

  3. On the Activate Windows page, enter your Windows product key, or select I don't have a product key to activate it later, then click Next.

  4. Accept the license terms, then click Next.

  5. On the Windows Setup page, select Custom: Install Windows only (advanced), use the default disk space settings, then click Next.

    The step is completed in five stages. Wait for all stages to complete.

  6. Choose United States in region, and in primary keyboard, select English (United States).

  7. In the Settings window, select Use Express settings.

  8. For the type of owner, select I do, then click Next.

  9. In the Make it yours window, select Skip this step.

  10. In the Meet Cortana windows, select Not now.

  11. In the Choose how you'll connect' window, select Join a local Active Directory domain.

  12. In the Create an account for this PC window, use these credentials, then click Next.

    • User nameadmin

    • Passwordcr@cker42

  13. In the Choose Privacy settings window, keep the default settings, then click Next.

  14. Wait until the installation is complete, then install the required software.

  15. Run the VM Provisioner tool as an administrator or prepare the image for analysis. On Windows 10, Administrator account is disabled by default. To enable, do the following:

    1. Run VM Provisioner Tool as a non-administrator user.

    2. Restart the virtual machine.

      The Administrator account is enabled once the virtual machine is started.

    3. Log on to Windows as the Administrator user.

      Note

      admin and Administrator user accounts are not the same.

    4. Run VM Provisioner Tool again.

  16. Check that these redistributable packages are installed.

    • Microsoft Visual C++ 2005 Redistributable Package (32-bit and 64-bit)

    • Microsoft Visual C++ 2008 Redistributable Package (32-bit and 64-bit)

    • Microsoft Visual C++ 2010 Redistributable Package (32-bit and 64-bit)

    • Microsoft Visual C++ 2012 Redistributable Package (32-bit and 64-bit)

    • Microsoft Visual C++ 2013 Redistributable Package (32-bit and 64-bit)

    • Microsoft Visual C++ 2019 Redistributable Package (32-bit and 64-bit)

    • Microsoft .NET Framework 3.5 and above which must be enabled manually or via an offline executable.

    Note

    • The VM administrator password cr@cker42 is required for VM profile creation. ATD system updates it to a random string as a part of VM creation. The running sandbox VM will have a random password.

    • If you are using any later build/version of win 10 1909.18363.418, its required to switch off tamper protection manually inside win 10VMs for better detection.

    Following are the steps to turn off Tamper Settings:

    1. Click on the Start button.

    2. Click on Settings.

    3. Go to Updates and Security

    4. Select Windows Security

    5. Switch to Virus and Threat Protection

    6. Select Manage Settings

    7. Scroll a bit to find Tamper Protection

    8. Toggle Off.