Configure your Windows Server 2012 R2 virtual system for analysis.
Log on to the virtual machine as administrator.
Note
The VM administrator password
cr@cker42is required for VM profile creation. ATD system updates it to a random string as a part of VM creation. The running sandbox VM will have a random password.If the Manage Your Server window page appears, select Don't Display the page at logon and close the page.
If the Server Manager windows is displayed, select → , select Do not start Server Manager automatically at logon, then select OK.
Disable the shutdown event tracker:
Select → , type
gpedit.msc, then click OK.In the Local Group Policy Editor page, select → → , then double-click Display Shutdown Event Tracker.
Select Disabled, then click OK.
Close the Local Group Policy Editor page.
Turn off the firewall in the virtual image:
Select → → → .
Select Off, then click OK.
Install telnet in the virtual image:
Select → → .
In the Server Manager window, select Add Roles and Features.
In Add Roles and Features Wizard, select Telnet Server.
Click Next, then Install.
Click Close after the installation succeeds.
Start the telnet service in the virtual image:
Select → → , then double-click Telnet.
In the Telnet Properties (Local Computer) page, select Automatic for the Startup type, then select → → .
Configure FTP settings in the virtual image:
Install IIS Manager if not already present and make sure you check the FTP Server checkbox when installing IIS Manager.
From Server Manager page, select Add Roles and Features, then click Next.
In the Installation type page, select Role-based or feature-based installation, then click Next.
In the Server selection page, select Select a server from the server pool, then click Next.
In the Server Roles page, expand the Web Server (IIS) node, expand the FTP Server node, select FTP Server, select FTP Service, then click Next.
In the Select features page, click Next, then click Install.
Select → → .
In the Internet Information Services Manager page, select Sites, select Add FTP Site
In the Add FTP Site wizard, do the following.
Provide the FTP site name as
rootand Physical path asC:\, then click Next.For Bindings and SSL Settings, select No SSL, then click Next.
For Authentication and Authorization Information, select Basic under Authentication, select All Users under Allow access to, select both Read and Write under Permissions.
Click Finish.
Download and install the .NET Framework 4.6 on the VM image.
If a Blocking Issues message appears, install the suggested components, then select Continue.
Set automatic logon:
Select → , type
netplwiz, then pressEnter.In the User Accounts window, deselect
Users must enter a user name and password to use this computer, then click Apply.In the Automatically log on page, provide these credentials.
User name —
AdministratorPassword —
cr@cker42Confirm Password —
cr@cker42
Disable Windows updates:
Select → → → .
Under Important updates, select Never check for updates (not recommended).
Deselect Recommended updates when downloading, installing, or notifying me about updates.
Click OK.
Configure Microsoft Office:
To analyze Microsoft Word, Excel, and PowerPoint files, install Microsoft Office 2007 on the virtual machine.
Lower the security to run macros for the Office applications. In Microsoft Word 2007, select the Microsoft Office option on the top left corner, then select → → → , then select Enable all macros (not recommended potentially dangerous code can run). Do the same for other applications such as Microsoft Excel and PowerPoint.
Lower the security to run ActiveX for the Office applications. In Microsoft Word 2007, select the Microsoft Office option on the top left corner, then select → → → , then select Enable all controls without restrictions and without prompting (not recommended potentially dangerous code can run). Do the same for other applications such as Microsoft Excel and PowerPoint.
On the Welcome to Microsoft Office 2007 page, click Next button.
On the Sign-up for Microsoft Update page, select I don't want to use Microsoft Update, then click Finish.
Configure Adobe Reader:
To analyze PDF files, download Adobe Reader to the native host and install it to the VM.
In Adobe reader, if Adobe Reader Protected Mode message appears, select Open with Protected Mode disabled, then select OK.
If Accessibility Setup Assistance message appears, select Cancel.
Select → → , select Do not download or install updated automatically, select OK, then select Yes to confirm the changes.
Configure Java:
Open Java in the Control Panel.
In the Update tab, deselect Check for Updates Automatically.
In the Java Update Warning message, select Do Not Check and then click OK.
Configure system startup:
Run the
msconfigcommand.From the Startup tab, deselect reader_sl and jusched, then click OK.
Note
reader_sl is available only when Adobe Reader is installed.
In the System Configuration dialog, select Don't show this message again, then select Restart.
Configure the default browser:
In Internet Explorer, select → .
In Home page select Use Blank or Use new tab based on the version of Internet Explorer.
From the Privacy tab, uncheck Turn on Pop-up Blocker.
Go to the Advanced tab of the Internet Options and locate Security, then select Allow active content to run in files on My Computer.