Prepare a Windows 8.1 image for analysis

Prev Next

Configure your Windows 8.1 virtual system for analysis.

  1. From the native system, set up Windows 8.1 to display in the Desktop mode instead of the default Metro UI mode when it starts.

    1. Press the Windows and R keys simultaneously, which is the shortcut to open the Run dialog box.

    2. In the Run dialog box, type regedit, then press Enter.

    3. In Registry Editor, select HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon, then double-click on Shell.

    4. Change Value data to explorer.exe, explorer.exe (instead of the default value of explorer.exe), then click OK.

  2. Log on to the virtual machine as administrator.

  3. Turn off the firewall in the virtual image:

    1. Press the Windows and X keys simultaneously, then select Control PanelSystem and SecurityTurn on Windows Firewall On or Off.

    2. Select Turn off Windows Firewall (not recommended) for both Home or work(private) network location settings and Public network location settings, then click OK.

  4. Disable Windows Defender:

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Windows DefenderSettingsAdministrators, deselect Turn on this app, then click Save changes.

    3. If a Windows Defender message appears, close the message screen.

  5. Disable first log on animation:

    1. Press the Windows and R keys simultaneously, type gpedit.msc, then press Enter.

    2. In the Local Group Policy Editor page, select Computer ConfigurationAdministrative TemplatesSystemLogon.

    3. Double-click Show first sign-in animation, select Disabled, then click OK.

  6. Enable required Windows features.

    1. Press the Windows and X keys simultaneously, then select Control PanelProgramsPrograms and FeaturesTurn Windows feature on or off.

    2. Select Internet Information ServicesFTP serverFTP Extensibility.

    3. Select Internet Information ServicesWeb Management ToolsIIS Management Service.

    4. Select Telnet Server.

    5. Select .NET Framework 3.5(includes .NET 2.0 and 3.0) and then select Windows Communication Foundation HTTP Activation and Windows Communication Foundation Non-HTP Activation options, then press OK.

    6. If the Windows needs files from Windows Update to finish installing some features message appears, select Download files from Windows Update.

      This operation might take around 5 minutes to complete. A confirmation message is displayed when the operation completes.

  7. Download and install the .NET Framework 4.6 on the VM image.

    If a Blocking Issues message appears, install the suggested components, then select Continue.

  8. Edit the power options:

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Power OptionsChoose when to turn off the display, select Never for both Turn off the display, and Put the computer to sleep options, then click Save changes.

    3. For shutdown settings, deselect Turn on fast startup and Hibernate options, then click Save changes.

  9. Start the telnet service in the virtual image:

    1. Press the Windows and X keys simultaneously, select Computer ManagementServices and ApplicationsServices, then double-click Telnet.

    2. In the Telnet Properties (Local Computer) page, select Automatic for the Startup type, then select ApplyStartOK.

  10. Configure FTP settings in the virtual image:

    1. Press the Windows and X keys simultaneously, select Control PanelSystem and SecurityAdministrative Tools, then double-click Internet Information Services.

    2. In the Internet Information Services page, expand the entry under Internet Information Services(IIS) Manager, then expand the tree under host name.

    3. If you see the Do you want to get started with Microsoft Web Platform to stay connected with latest Web Platform Components? message, select Do not show this message, then click Cancel.

    4. Select Sites, right-click on Default Web Site, select Remove, then click Yes to confirm.

    5. Right-click Sites, select Add FTP Site, then do the following.

      • Provide the FTP site name as root and Physical path as C:\, then click Next.

      • For Bindings and SSL Settings, select No SSL, then click Next.

      • For Authentication and Authorization Information, select Basic under Authentication, select All Users under Allow access to, select both Read, and Write under Permissions.

      • Click Finish.

    6. Close the Internet Information Services (IIS) Manager page.

  11. Turn off automatic updating for Windows:

    1. Press the Windows and X keys simultaneously, then select Control PanelWindows UpdateChange.

    2. Select Never check for updates (not recommended), then click OK

  12. Configure Telnet clients.

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Administrative toolsComputer Management.

    3. Select Computer Management (Local)System ToolsLocal Users and GroupsGroups.

    4. Double-click TelnetClients.

    5. Click Add, type Administrator, click Check Names, then click OK.

  13. Set automatic logon:

    1. Press the Windows and R keys simultaneously, type netplwiz, then press Enter.

    2. In the User Accounts window, deselect Users must enter a user name and password to use this computer, then click Apply.

    3. In the Automatically log on page, provide these credentials.

      • User nameAdministrator

      • Passwordcr@cker42

      • Confirm Passwordcr@cker42

  14. Configure Microsoft Office:

    1. To analyze Microsoft Word, Excel, and PowerPoint files, install Microsoft Office 2007 on the virtual machine.

    2. Lower the security to run macros for the Office applications. In Microsoft Word 2007, select the Microsoft Office option on the top left corner, then select Word optionsTrust CenterTrust Center SettingsMacro Settings, then select Enable all macros (not recommended potentially dangerous code can run). Do the same for other applications such as Microsoft Excel and PowerPoint.

    3. On the Welcome to Microsoft Office 2007 page, click Next button.

    4. On the Sign-up for Microsoft Update page, select I don't want to use Microsoft Update, then click Finish.

  15. Configure Adobe Reader:

    1. To analyze PDF files, download Adobe Reader to the native host and install it to the VM.

    2. In Adobe reader, if Adobe Reader Protected Mode message appears, select Open with Protected Mode disabled, then select OK.

    3. If Accessibility Setup Assistance message appears, select Cancel.

    4. Select Edit Preferences Updater, select Do not download or install updated automatically, select OK, then select Yes to confirm the changes.

  16. Configure Java:

    1. Open Java in the Control Panel.

    2. In the Update tab, deselect Check for Updates Automatically.

    3. In the Java Update Warning message, select Do Not Check and then click OK.

  17. Configure system startup:

    1. Run the msconfig command.

    2. From the Startup tab, then click Open Task Manager.

    3. Select Java(TM) Update Scheduler (jusched) (if listed), then click Disable.

    4. Select Adobe Acrobat SpeedLauncher (reader_sl) (if listed), then click Disable.

    5. In the System Configuration dialog, select Don't show this message again, then select Restart.

  18. Configure the default browser:

    1. In Internet Explorer, select ToolsInternet Options.

    2. In Home page select Use Blank or Use new tab based on the version of Internet Explorer.

    3. From the Privacy tab, uncheck Turn on Pop-up Blocker.

    4. Go to the Advanced tab of the Internet Options and locate Security, then select Allow active content to run in files on My Computer.

  19. Disable the HTTP auto proxy server: Open command prompt with administrator privilege, then run these commands.

    • Net stop WinHttpAutoProxySvc

    • Sc config WinHttpAutoProxySvc start= disabled

    Note

    The VM administrator password cr@cker42 is required for VM profile creation. ATD system updates it to a random string as a part of VM creation. The running sandbox VM will have a random password.