Prepare a Windows 8 image for analysis

Prev Next

Configure your Windows 8 virtual system for analysis.

  1. From the native system, set up Windows 8 to display in the Desktop mode instead of the default Metro UI mode when it starts.

    1. Press the Windows and R keys simultaneously, which is the shortcut to open the Run dialog box.

    2. In the Run dialog box, type regedit, then press Enter.

    3. In Registry Editor, select HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon, then double-click on Shell.

    4. Change Value data to explorer.exe, explorer.exe (instead of the default value of explorer.exe), then click OK.

  2. Log on to the virtual machine as administrator.

  3. Turn off the firewall in the virtual image:

    1. Press the Windows and X keys simultaneously, then select Control PanelSystem and SecurityTurn on Windows Firewall On or Off.

    2. Select Turn off Windows Firewall (not recommended) for both Home or work(private) network location settings and Public network location settings, then click OK.

  4. Disable Windows Defender:

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Windows DefenderSettingsAdministrators, deselect Turn on Windows Defender, then click Save changes.

    3. Close the Windows Defender message box.

  5. Disable first log on animation:

    1. Press the Windows and X keys simultaneously.

    2. In the Run dialog box, type gpedit.msc, then press Enter.

    3. In the Local Group Policy Editor page, select Computer ConfigurationAdministrative TemplatesSystemLogon.

    4. Double-click Show first sign-in animation, select Disabled, then click OK.

  6. Enable required Windows features.

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select ProgramsPrograms and FeaturesTurn Windows feature on or off.

    3. Select Internet Information ServicesFTP serverFTP Extensibility.

    4. Select Internet Information ServicesWeb Management ToolsIIS Management Service.

    5. Select Telnet Server.

    6. Select .NET Framework 3.5(includes .NET 2.0 and 3.0) and then select Windows Communication Foundation HTTP Activation and Windows Communication Foundation Non-HTP Activation options, then press OK.

    7. If the Windows needs files from Windows Update to finish installing some features message appears, select Download files from Windows Update.

      This operation might take around 5 minutes to complete. A confirmation message is displayed when the operation completes.

  7. Edit the power options:

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Power OptionsChoose when to turn off the display, select Never for both Turn off the display and Put the computer to sleep options, then click Save changes.

    3. Select Power Options Choose what the power buttons do, select Change Settings that are currently unavailable for both Turn off the display and Put the computer to sleep options, then click Save changes.

    4. For shutdown settings, deselect Turn on fast startup and Hibernate options, then click Save changes.

  8. Start the telnet service in the virtual image:

    1. Press the Windows and X keys simultaneously, select Computer ManagementServices and ApplicationsServices, then double-click Telnet.

    2. In the Telnet Properties (Local Computer) page, select Automatic for the Startup type, then select ApplyStartOK.

  9. Configure FTP settings in the virtual image:

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Administrative Tools, then double-click Internet Information Services.

    3. In the Internet Information Services page, expand the entry under Internet Information Services(IIS) Manager, then expand the tree under host name.

    4. If you see the Do you want to get started with Microsoft Web Platform to stay connected with latest Web Platform Components? message, select Do not show this message, then click Cancel.

    5. Select Sites, right-click on Default Web Site, select Remove, then click Yes to confirm.

    6. Right-click Sites, select Add FTP Site, then do the following.

      • Provide the FTP site name as root and Physical path as C:\, then click Next.

      • For Bindings and SSL Settings, select No SSL, then click Next.

      • For Authentication and Authorization Information, select Basic under Authentication, select All Users under Allow access to, select both Read and Write under Permissions.

      • Click Finish.

    7. Close the Internet Information Services (IIS) Manager page.

  10. Turn off automatic updating for Windows:

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Windows UpdateChange.

    3. Select Never check for updates (not recommended), then click OK

  11. Configure Telnet clients

    1. Press the Windows and X keys simultaneously, select Control Panel, then select Small Icons under View by.

    2. Select Administrator ToolsComputer Management.

    3. Select Computer Management (Local)System ToolsLocal Users and GroupsGroups.

    4. Double-click TelnetClients.

    5. Click Add, type Administrator, click Check Names, then click OK.

  12. Set automatic logon:

    1. Press the Windows and R keys simultaneously, type netplwiz, then press Enter.

    2. In the User Accounts window, deselect Users must enter a user name and password to use this computer, then click Apply.

    3. In the Automatically log on page, provide these credentials.

      • User nameAdministrator

      • Passwordcr@cker42

      • Confirm Passwordcr@cker42

  13. Configure Microsoft Office:

    1. To analyze Microsoft Word, Excel, and PowerPoint files, install Microsoft Office 2003 on the virtual machine.

    2. Lower the security to run macros for the Office applications. In Microsoft Word 2003 and select ToolsMacroSecurity, select Low, then click OK. Do the same for other applications such as Microsoft Excel and PowerPoint.

    3. Go to http://www.microsoft.com/en-us/download/details.aspx?id=3 and download the required Microsoft Office compatibility pack for Word, Excel, and PowerPoint File Formats, then install them on the virtual machine.

      You need the compatibility pack to open Microsoft Office files that were created in a newer version of Microsoft Office. For example, to open a .docx file using Office 2003, you need the corresponding compatibility pack installed.

    4. In the Compatibility Pack for the 2007 Office system dialog, select Click here to accept the Microsoft Software License Terms, then click OK.

  14. Configure Adobe Reader:

    1. To analyze PDF files, download Adobe Reader to the native host and copy it to the VM.

    2. Open Adobe Reader and click Accept.

    3. In Adobe Reader, select Edit PreferencesGeneral, then remove Check for updates.

    4. In Adobe Reader, select HelpCheck for updatesPreferences, then deselect Adobe Updates.

  15. Configure Java:

    1. Open Java in the Control Panel.

    2. In the Update tab, deselect Check for Updates Automatically.

    3. In the Java Update Warning message, select Do Not Check and then click OK.

  16. Configure system startup:

    1. Run the msconfig command.

    2. From the Startup tab, then click Open Task Manager.

    3. Select Java(TM) Update Scheduler (jusched) (if listed), then click Disable.

    4. Select Adobe Acrobat SpeedLauncher (reader_sl) (if listed), then click Disable.

    5. In the System Configuration message, select Restart.

    6. In the System Configuration Utility message, select Don't show this message or launch the System Configuration Utility when Windows start, then click OK.

  17. Configure the default browser:

    1. In Internet Explorer, select ToolsInternet Options.

    2. In Home page select Use Blank or Use new tab based on the version of Internet Explorer.

    3. From the Privacy tab, uncheck Turn on Pop-up Blocker.

    4. Go to the Advanced tab of the Internet Options and locate Security, then select Allow active content to run in files on My Computer.

  18. Disable the HTTP auto proxy server: Open command prompt with administrator privilege, then run these commands.

    • Net stop WinHttpAutoProxySvc

    • Sc config WinHttpAutoProxySvc start= disabled

    Note

    The VM administrator password cr@cker42 is required for VM profile creation. ATD system updates it to a random string as a part of VM creation. The running sandbox VM will have a random password.