Configure your Windows 7 virtual system for analysis.
Log on to the virtual machine as administrator.
Turn off the firewall in the virtual image:
Select → → → .
Select Turn off Windows Firewall (not recommended) for both Home or work(private) network location settings and Public network location settings, then click OK.
Enable required Windows features.
Select → → → → .
Select → → .
Select → → .
Select Telnet Server, then click OK.
This operation might take around 5 minutes to complete.
Start the telnet service in the virtual image:
Click Start and right-click My Computer.
Select → → , then double-click Telnet.
In the Telnet Properties (Local Computer) page, select Automatic for the Startup type, then select → → .
Configure FTP settings in the virtual image:
Select → → → , then double-click Internet Information Services.
In the Internet Information Services page, expand the entry under Internet Information Services(IIS) Manager, then expand the tree under host name.
Select Sites, right-click on Default FTP Site, select Remove, then click Yes to confirm.
Right-click Sites, select Add FTP Site, then do the following.
Provide the FTP site name as
rootand Physical path asC:\, then click Next.For Bindings and SSL Settings, select No SSL, then click Next.
For Authentication and Authorization Information, select Basic under Authentication, select All Users under Allow access to, select both Read and Write under Permissions.
Click Finish.
Close the Internet Information Services (IIS) Manager page.
Set automatic logon:
Select → , type
netplwiz, then pressEnter.In the User Accounts window, deselect
Users must enter a user name and password to use this computer, then click Apply.In the Automatically log on page, provide these credentials.
User name —
AdministratorPassword —
cr@cker42Confirm Password —
cr@cker42
Disable Windows updates:
Select → → → .
Under Important updates, select Never check for updates (not recommended).
Deselect all options under Recommended updates, Who can install updates, Microsoft update, Software notifications.
Click OK.
Configure Microsoft Office:
To analyze Microsoft Word, Excel, and PowerPoint files, install Microsoft Office 2003 on the virtual machine.
Lower the security to run macros for the Office applications. In Microsoft Word 2003 and select → → , select Low, then click OK. Do the same for other applications such as Microsoft Excel and PowerPoint.
Go to http://www.microsoft.com/en-us/download/details.aspx?id=3 and download the required Microsoft Office compatibility pack for Word, Excel, and PowerPoint File Formats, then install them on the virtual machine.
You need the compatibility pack to open Microsoft Office files that were created in a newer version of Microsoft Office. For example, to open a .docx file using Office 2003, you need the corresponding compatibility pack installed.
In the Compatibility Pack for the 2007 Office system dialog, select Click here to accept the Microsoft Software License Terms, then click OK.
Configure JustSystems Ichitaro word processing software:
To analyze JTD and JTDC files, install Ichitaro word processing software.
Recommended versions Govt8 or Pro3.
Disable automatic updates.
If you want analyze Microsoft Office files using Ichitaro, manually change the file association.
Configure Adobe Reader:
To analyze PDF files, download Adobe Reader to the native host and copy it to the VM.
Open Adobe Reader and click Accept.
In Adobe Reader, select → → , then remove Check for updates.
In Adobe Reader, select → → , then deselect Adobe Updates.
Configure Java:
Open Java in the Control Panel.
In the Update tab, deselect Check for Updates Automatically.
In the Java Update Warning message, select Do Not Check and then click OK.
Configure system startup:
Run the
msconfigcommand.From the Startup tab, deselect reader_sl and jusched, then click OK.
Note
reader_sl is available only when Adobe Reader is installed.
In the System Configuration message, select Restart.
In the System Configuration Utility message, select Don't show this message or launch the System Configuration Utility when Windows start, then click OK.
Configure the default browser:
In Internet Explorer, select → .
In Home page select Use Blank or Use new tab based on the version of Internet Explorer.
From the Privacy tab, uncheck Turn on Pop-up Blocker.
Go to the Advanced tab of the Internet Options and locate Security, then select Allow active content to run in files on My Computer.
Disable the HTTP auto proxy server: Open command prompt with administrator privilege, then run these commands.
Net stop WinHttpAutoProxySvcSc config WinHttpAutoProxySvc start= disabled
Note
The VM administrator password
cr@cker42is required for VM profile creation. ATD system updates it to a random string as a part of VM creation. The running sandbox VM will have a random password.