Reviews & Opinions
Independent and trusted. Read before buy Games PC Medal Of Honor - Allied Assault - Spearhead!

Games PC Medal Of Honor - Allied Assault - Spearhead


Bookmark
Games PC Medal Of Honor - Allied Assault - Spearhead

Bookmark and Share

 

Games PC Medal Of Honor - Allied Assault - SpearheadMedal of Honor: Allied Assault -- Spearhead Expansion Pack [PC Game]

Developed by Electronic Arts Los Angeles - EA Games (2002) - First-Person Shooter - Rated Teen

Battle through the tumultuous final year of the Second World War in this expansion pack for EA Games' historical first-person shooter Medal of Honor: Allied Assault. Players take the roles of Sgt. Jack Barnes and a Russian officer as they complete missions during Operation Overlord, the Battle of the Bulge, and the fall of Berlin. The package adds nine new single-player missions, based on operations in Europe from June 1944 through May 1945, and also includes a dozen new multiplayer maps. As... Read more

Details
Platform: PC
Developer: Electronic Arts Los Angeles
Publisher: EA Games
Release Date: November 12, 2002
Controls: Keyboard, Mouse
UPC: 014633145670
[ Report abuse or wrong photo | Share your Games PC Medal Of Honor - Allied Assault - Spearhead photo ]

 

 

Manual

Preview of first few manual pages (at low quality). Check before download. Click to enlarge.
Manual - 1 page  Manual - 2 page  Manual - 3 page 

Download (English)
Games PC Medal Of Honor-allied Assault-spearhead, size: 3.3 MB

 

Games PC Medal Of Honor - Allied Assault - Spearhead

 

 

Video review

Free download Medal of Honor Allied Assault Spearhead expansion

 

User reviews and opinions

<== Click here to post a new opinion, comment, review, etc.

Comments to date: 4. Page 1 of 1. Average Rating:
Serhiy Kuznyetsov 1:51am on Wednesday, October 20th, 2010 
Good Good is a word i would describe this game! I love WWII games and MOHAA was very good, MOHSH was just good!
rtanner@cheshiresgrin.net 12:39am on Sunday, September 5th, 2010 
Allied Assault Detraction Pack: Spearhead The original PC-game Medal of Honour: Allied Assault is a great game.
VaMPiRiC_CRoW 2:22pm on Saturday, August 14th, 2010 
I wish 2015 did this one instead of EA. EA kind messed some stuff up, just a way for them to make a quick buck I guess. Overall this is a good game though it is a little short you will have multiplayer maps like the new Tug of War maps to keep you bisy after you beet th...
Frederic12 3:55pm on Thursday, March 25th, 2010 
This game could use more weapons and more vareation in levels. They should also add a game type or just have them in the online system, vechiles. Same high quality as MOHAA from EA. The graphics are well done but become see-through when you get too close. Otherwise an excellant game.

Comments posted on www.ps2netdrivers.net are solely the views and opinions of the people posting them and do not necessarily reflect the views or opinions of us.

 

Documents

doc1

Certified Reverse Engineering Analyst (CREA) Practical Analyst Date Malware Jason Swallows 1 February 2010 Practical 1252
Item A - File Provided: malware.exe, MD5: 0783505871f4d862b78d4a709827d42d 1) General function and functionality of the malware Item A is a Windows-based worm that: Opens a port on 113 and spoofs identd for IRC connections. Connects to an IRC server, joins a channel and waits for commands from the author. Commands give broad control of the machine to the author Can steal keys for many games. Can spread by exploiting network shares with weak passwords (uses a list of common user names and passwords).
2) Behavioral patterns of malware Since Item A attempts to propagate by scanning network shares, it has the behavioral pattern of a worm. It also could be classified as a Bot, since it sits and waits for commands from the author.
3) Local system interaction Makes the file and registry modifications listed under Question #4. Kills the following processes (See Illustration 1 & 2) "regedit.exe" "MSBLAST.exe" "msconfig.exe" "teekids.exe" "netstat.exe" "Penis32.exe" "msblast.exe" "bbeagle.exe" "zapro.exe" "SysMonXP.exe" "navw32.exe" "winupd.exe" "navapw32.exe" "winsys.exe" "zonealarm.exe" "ssate.exe" "wincfg32.exetaskmon.exe" "rate.exe" "PandaAVEngine.exe" "d3dupdate.exe" "sysinfo.exe" "irun4.exe" "mscvb32.exe" "i11r54n4.exe
Illustration 2: 0x00429DB0 starts the list of processes to be killed
Illustration 1: If one of the processes above is identified, open it, then terminate it.
Deletes the following shares (See Illustration 3) IPC$ ADMIN$ C$ D$
Illustration 3: Delete network shares
When controlled via IRC, commands can be issued by the controller to achieve objectives on the local system. There are many commands, but I will just document a few here as examples. Command: capture or cap, Purpose: Can capture an image or movie from a webcam or the desktop
Illustration 3: Code sample from screen/cam capture process
Command: execute or e, Purpose: Attempts to run a program on the local system
Illustration 4: Code sample from execution process
Command: readfile or rf, Purpose: Allows controller to read a file from local system
Illustration 5: Code sample from file reading process
Other commands, which I won't go into, provide capabilities for the following: E-mailing File searching, listing, deleting, etc. DNS queries or cache flushing File downloading and uploading Clipboard capture Processes listing and stopping Rebooting System information Network scanning Denial of service attacks TFTP capabilities Many more! Opens a port on 113 and spoofs identd for IRC connections.
Illustration 6: A small section of the code for starting the listener.
Illustration 7: Sample of offsets to the received requests and related functions.
4) Files and registry keys created, modified and accessed File access/modification: Copies itself, as scrgrd.exe, to the %System% folder and creates a new process with the newly copied executable.

Illustration 6: The name for the new executable is scrgrd.exe
Illustration 7: Initialize CopyFileA to esi to be called later
Potentially accesses <Soldier of Fortune II Install Path>\base\mp\sof2key to check for a CD Key. Potentially access <Neverwinter Nights Install Path>\nwncdkey.ini to check for CD keys. Potentially files created, changed by author over IRC Registry (Creates, to ensure execution of the malware on startup) Creates HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Restore with the value %System%\scrgrd.exe Creates HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Restore with the value %System%\scrgrd.exe Creates HKEY_LOCAL_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Restore with the value %System%\scrgrd.exe
Illustration 8: Registry entry creation area.
Registry (Changes value of)
Sets the value of HKLM\Software\Microsoft\OLE\EnableDCOM to N Sets the value of HKLM\SYSTEM\CurrentControlSet\ Control\Lsa\restrictanonymous to 1 Registry (Checks for and gets value of) "HKCU\Software\\Valve\\CounterStrike\\Settings\CDKey" "HKCU\Software\\Eugen Systems\\The Gladiators\RegNumber" "HKCU\Software\\Valve\\Gunman\\Settings\Key" "HKCU\Software\\Valve\\Half-Life\\Settings\Key" "HKCU\Software\\JoWooD\\InstalledGames\\IG2\prvkey" "HKCU\Software\\3d0\\Status\CustomerNumber" "HKCU\Software\Silver Style Entertainment\Soldiers Of Anarchy\Settings\CDKey" "HKLM\Software\Microsoft\Windows\CurrentVersion\ProductId" "HKLM\Software\Unreal Technology\Installed Apps\UT2003\CDKey" "HKLM\Software\Unreal Technology\Installed Apps\UT2004\CDKey" "HKLM\Software\IGI 2 Retail\CDKey" "HKLM\Software\Electronic Arts\EA Distribution\Freedom Force\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942 The Road to Rome\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942 Secret Weapons of WWII\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield Vietnam\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Black and White\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Command and Conquer Generals Zero Hour\ergc" "HKLM\Software\Electronic Arts\EA GAMES\James Bond 007 Nightfire\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Generals\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Global Operations\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Breakthrough\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Spearhead\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Need For Speed Hot Pursuit 2\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Need For Speed Underground\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Shogun Total War - Warlord Edition\ergc" "HKLM\Software\Electronic Arts\EA Sports\FIFA 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\FIFA 2003\ergc" "HKLM\Software\Electronic Arts\EA Sports\NHL 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\NHL 2003\ergc" "HKLM\Software\Electronic Arts\EA Sports\Nascar Racing 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\Nascar Racing 2003\ergc" "HKLM\Software\Red Storm Entertainment\RAVENSHIELD\CDKey" "HKLM\Software\Westwood\Tiberian Sun\Serial" "HKLM\Software\Westwood\Red Alert\Serial" "HKLM\Software\Westwood\Red Alert 2\Serial" "HKLM\Software\Westwood\NOX\Serial" "HKLM\Software\\Techland\\Chrome\SerialNumber" "HKLM\Software\Illusion Softworks\Hidden & Dangerous 2\key"

Illustration 9: A portion of the key stealer code.
Registry (Other) If "HKLM\Software\Activision\Soldier of Fortune II - Double Helix\InstallPath exists, gets its value, which is the installation path of this game, then under that path, checks for the file base\mp\sof2key to get the key If Software\\BioWare\\NWN\\Neverwinter\Location exists, gets its value, which is the installation path of this game, then under that path, checks for the file nwncdkey.ini. If this file is found, checks for the text Key1=, Key2= and Key3= to get the key for Neverwinter Nights and its expansion packs (assuming they are installed too).
5) Network behavior (including hosts, domains and IP addresses accessed) As mentioned earlier, Opens a port on 113 and spoofs identd for IRC connections Connects to an IRC server at: pwned.tr1n1.net, or pwned2.tr1n1.net Also scans the local network for shares protected by weak passwords Could also be used for network scans and DDOS attacks
6) Time and local system dependent features The local system must have a network connection for many of the features to work As noted earlier, the malware will pretend to be an identd server to fool IRC servers when connecting. Some of the local system attributes it will query to send back to the IRC server include: The computer's name The specified local Information about the operating system When reporting back to the author, it usually will include the local time Author can query many local system attributes over IRC
7) Method and means of communication Opens a server listener on port 113 that can receive commands Connects to an IRC server at pwned.tr1n1.net or pwned2.tr1n1.net, then joins the channel #scrub and waits for commands from the author
8) Original infection vector and propagation methodology Network shares protected by weak passwords Tricking someone into running the executable
9) Use of encryption for storage, communication None that I could find
10) Use of self modifying or encrypted code The executable is packed with UPX 0.89.6 - 1.02 / 1.05 1.24. I was able to unpack it manually using OllyDBG and Import Reconstructor. On initial analysis, it appears that the only library used is kernel32, since it is the only one statically linked. On further analysis, there is a particular function (at address 0x0040780C) that dynamically loads the other libraries which are used. See Figure for a sample from this function.

Illustration 10: Sample from Library Importing Function
As far as I can tell, there doesn't appear to be any encrypted code.
11) Any information concerning development of malware (compiler type, country of origin, author names/handles, etc.) The malware contains uses the Microsoft Visual C++ Runtime Library so it was probably compiled from within Visual Studio, possibly using CL.exe. The closest thing I could come to a signature by an author was the following strings: neTmaNiac netmaniac was here 12/12/04 13:13:13 netninjaz_place 131.131.131.131 3.72.0.0 I was not able to determine the country of origin from the provided executable.

 

Technical specifications

Full description

Battle through the tumultuous final year of the Second World War in this expansion pack for EA Games' historical first-person shooter Medal of Honor: Allied Assault. Players take the roles of Sgt. Jack Barnes and a Russian officer as they complete missions during Operation Overlord, the Battle of the Bulge, and the fall of Berlin. The package adds nine new single-player missions, based on operations in Europe from June 1944 through May 1945, and also includes a dozen new multiplayer maps. As with previous Medal of Honor games, developers strove for historical authenticity in this release, working closely with both the Congressional Medal of Honor Society and respected military consultant Capt. Dale Dye. ~ T.J. Deci, All Game Guide

 

Tags

2405 D-540 Zoom AG-DP800 LH-D6530A Omnipcx 4400 PS42A451p1 LC-65GE1 Turbotec HD7832 Realis SX60 40R86WD 3750I Vhrm340 LD-14AW3 FE-320 20PF5121 Center 2 28ZD06G XP500-2008 Decathlon DC9 Samsung 940B Navteq NN4D TX-P42g20ES Korg TM40 KD-G632E M228WA-BM Urc-8811 CE-200 Silver Evo3 MC-E3002 SA-XR700 Scanner TH-A35 Pentax MZ-5 PCG-GRX516SP MC-7826M GA-X58a-ud3R KDC-MP225 IG-80 V101 EEA130 E-100 RS PRO 8 Force DEM10 MDX-C670 MP1400 Nx-670 Kodak C340 SP-43T8HE Lambda Euro 220 22S81B FX-570D Hearts R-657 GC720R IR5075 CK-100 ONE Deep Review LAC5800R RSA1utvg ZBC741R 900-0146 BGR200XL Yashica T HT-DDW880 AVR-4800 Iwde 7145 System VGS50 MIX-R1U CD491 MXB-4125 DSR-1 RSP-980 LS-K2460HL Rmcm101 Vocal 300 DCS-900 Server 1400-503 HZ50W DI551 UX-W70CL Combo 480-24 T Colortrak SX-LX08 Rdvd1002 SLV-D920N Handykit 202E SN81840-5I 96740 WF-402 FTR9965 12S DST-BX300 Xsmall Abit IS7 Tybox 110 RDR-VX420

 

manuel d'instructions, Guide de l'utilisateur | Manual de instrucciones, Instrucciones de uso | Bedienungsanleitung, Bedienungsanleitung | Manual de Instruções, guia do usuário | инструкция | návod na použitie, Užívateľská príručka, návod k použití | bruksanvisningen | instrukcja, podręcznik użytkownika | kullanım kılavuzu, Kullanım | kézikönyv, használati útmutató | manuale di istruzioni, istruzioni d'uso | handleiding, gebruikershandleiding

 

Sitemap

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101