Games PC Medal Of Honor Allied Assault Spearhead
|
|
Bookmark Games PC Medal Of Honor Allied Assault Spearhead |
Medal of Honor: Allied Assault -- Spearhead Expansion Pack [PC Game]Developed by Electronic Arts Los Angeles - EA Games (2002) - First-Person Shooter - Rated Teen
Battle through the tumultuous final year of the Second World War in this expansion pack for EA Games' historical first-person shooter Medal of Honor: Allied Assault. Players take the roles of Sgt. Jack Barnes and a Russian officer as they complete missions during Operation Overlord, the Battle of the Bulge, and the fall of Berlin. The package adds nine new single-player missions, based on operations in Europe from June 1944 through May 1945, and also includes a dozen new multiplayer maps. As... Read more
Details
Platform: PC
Developer: Electronic Arts Los Angeles
Publisher: EA Games
Release Date: November 12, 2002
Controls: Keyboard, Mouse
UPC: 014633145670
[ Report abuse or wrong photo | Share your Games PC Medal Of Honor Allied Assault Spearhead photo ]
Manual
Preview of first few manual pages (at low quality). Check before download. Click to enlarge.
Download
(English)Games PC Medal Of Honor Allied Assault Spearhead, size: 3.3 MB |
Games PC Medal Of Honor Allied Assault Spearhead
Video review
Free download Medal of Honor Allied Assault Spearhead expansion
User reviews and opinions
| cfaber |
12:35am on Monday, August 9th, 2010 ![]() |
| Brilliant - ignore the moaners!! MOH Allied Assault was fabulous, but Spearhead is a brilliant add on. The graphics are great. Good Good is a word i would describe this game! I love WWII games and MOHAA was very good, MOHSH was just good! | |
| Peter Mount |
2:13pm on Tuesday, May 11th, 2010 ![]() |
| I wish 2015 did this one instead of EA. EA kind messed some stuff up, just a way for them to make a quick buck I guess. | |
| Blolover11 |
9:18am on Sunday, April 4th, 2010 ![]() |
| This game could use more weapons and more vareation in levels. They should also add a game type or just have them in the online system, vechiles. Overall this is a good game though it is a little short you will have multiplayer maps like the new Tug of War maps to keep you bisy after you beet th... Same high quality as MOHAA from EA. The graphics are well done but become see-through when you get too close. Otherwise an excellant game. | |
Comments posted on www.ps2netdrivers.net are solely the views and opinions of the people posting them and do not necessarily reflect the views or opinions of us.
Documents

Certified Reverse Engineering Analyst (CREA) Practical Analyst Date Malware Jason Swallows 1 February 2010 Practical 1252
Item A - File Provided: malware.exe, MD5: 0783505871f4d862b78d4a709827d42d 1) General function and functionality of the malware Item A is a Windows-based worm that: Opens a port on 113 and spoofs identd for IRC connections. Connects to an IRC server, joins a channel and waits for commands from the author. Commands give broad control of the machine to the author Can steal keys for many games. Can spread by exploiting network shares with weak passwords (uses a list of common user names and passwords).
2) Behavioral patterns of malware Since Item A attempts to propagate by scanning network shares, it has the behavioral pattern of a worm. It also could be classified as a Bot, since it sits and waits for commands from the author.
3) Local system interaction Makes the file and registry modifications listed under Question #4. Kills the following processes (See Illustration 1 & 2) "regedit.exe" "MSBLAST.exe" "msconfig.exe" "teekids.exe" "netstat.exe" "Penis32.exe" "msblast.exe" "bbeagle.exe" "zapro.exe" "SysMonXP.exe" "navw32.exe" "winupd.exe" "navapw32.exe" "winsys.exe" "zonealarm.exe" "ssate.exe" "wincfg32.exetaskmon.exe" "rate.exe" "PandaAVEngine.exe" "d3dupdate.exe" "sysinfo.exe" "irun4.exe" "mscvb32.exe" "i11r54n4.exe
Illustration 2: 0x00429DB0 starts the list of processes to be killed
Illustration 1: If one of the processes above is identified, open it, then terminate it.
Deletes the following shares (See Illustration 3) IPC$ ADMIN$ C$ D$
Illustration 3: Delete network shares
When controlled via IRC, commands can be issued by the controller to achieve objectives on the local system. There are many commands, but I will just document a few here as examples. Command: capture or cap, Purpose: Can capture an image or movie from a webcam or the desktop
Illustration 3: Code sample from screen/cam capture process
Command: execute or e, Purpose: Attempts to run a program on the local system
Illustration 4: Code sample from execution process
Command: readfile or rf, Purpose: Allows controller to read a file from local system
Illustration 5: Code sample from file reading process
Other commands, which I won't go into, provide capabilities for the following: E-mailing File searching, listing, deleting, etc. DNS queries or cache flushing File downloading and uploading Clipboard capture Processes listing and stopping Rebooting System information Network scanning Denial of service attacks TFTP capabilities Many more! Opens a port on 113 and spoofs identd for IRC connections.
Illustration 6: A small section of the code for starting the listener.
Illustration 7: Sample of offsets to the received requests and related functions.
4) Files and registry keys created, modified and accessed File access/modification: Copies itself, as scrgrd.exe, to the %System% folder and creates a new process with the newly copied executable.
Illustration 6: The name for the new executable is scrgrd.exe
Illustration 7: Initialize CopyFileA to esi to be called later
Potentially accesses <Soldier of Fortune II Install Path>\base\mp\sof2key to check for a CD Key. Potentially access <Neverwinter Nights Install Path>\nwncdkey.ini to check for CD keys. Potentially files created, changed by author over IRC Registry (Creates, to ensure execution of the malware on startup) Creates HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Restore with the value %System%\scrgrd.exe Creates HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Restore with the value %System%\scrgrd.exe Creates HKEY_LOCAL_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Restore with the value %System%\scrgrd.exe
Illustration 8: Registry entry creation area.
Registry (Changes value of)
Sets the value of HKLM\Software\Microsoft\OLE\EnableDCOM to N Sets the value of HKLM\SYSTEM\CurrentControlSet\ Control\Lsa\restrictanonymous to 1 Registry (Checks for and gets value of) "HKCU\Software\\Valve\\CounterStrike\\Settings\CDKey" "HKCU\Software\\Eugen Systems\\The Gladiators\RegNumber" "HKCU\Software\\Valve\\Gunman\\Settings\Key" "HKCU\Software\\Valve\\Half-Life\\Settings\Key" "HKCU\Software\\JoWooD\\InstalledGames\\IG2\prvkey" "HKCU\Software\\3d0\\Status\CustomerNumber" "HKCU\Software\Silver Style Entertainment\Soldiers Of Anarchy\Settings\CDKey" "HKLM\Software\Microsoft\Windows\CurrentVersion\ProductId" "HKLM\Software\Unreal Technology\Installed Apps\UT2003\CDKey" "HKLM\Software\Unreal Technology\Installed Apps\UT2004\CDKey" "HKLM\Software\IGI 2 Retail\CDKey" "HKLM\Software\Electronic Arts\EA Distribution\Freedom Force\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942 The Road to Rome\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942 Secret Weapons of WWII\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield Vietnam\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Black and White\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Command and Conquer Generals Zero Hour\ergc" "HKLM\Software\Electronic Arts\EA GAMES\James Bond 007 Nightfire\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Generals\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Global Operations\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Breakthrough\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Spearhead\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Need For Speed Hot Pursuit 2\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Need For Speed Underground\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Shogun Total War - Warlord Edition\ergc" "HKLM\Software\Electronic Arts\EA Sports\FIFA 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\FIFA 2003\ergc" "HKLM\Software\Electronic Arts\EA Sports\NHL 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\NHL 2003\ergc" "HKLM\Software\Electronic Arts\EA Sports\Nascar Racing 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\Nascar Racing 2003\ergc" "HKLM\Software\Red Storm Entertainment\RAVENSHIELD\CDKey" "HKLM\Software\Westwood\Tiberian Sun\Serial" "HKLM\Software\Westwood\Red Alert\Serial" "HKLM\Software\Westwood\Red Alert 2\Serial" "HKLM\Software\Westwood\NOX\Serial" "HKLM\Software\\Techland\\Chrome\SerialNumber" "HKLM\Software\Illusion Softworks\Hidden & Dangerous 2\key"
Illustration 9: A portion of the key stealer code.
Registry (Other) If "HKLM\Software\Activision\Soldier of Fortune II - Double Helix\InstallPath exists, gets its value, which is the installation path of this game, then under that path, checks for the file base\mp\sof2key to get the key If Software\\BioWare\\NWN\\Neverwinter\Location exists, gets its value, which is the installation path of this game, then under that path, checks for the file nwncdkey.ini. If this file is found, checks for the text Key1=, Key2= and Key3= to get the key for Neverwinter Nights and its expansion packs (assuming they are installed too).
5) Network behavior (including hosts, domains and IP addresses accessed) As mentioned earlier, Opens a port on 113 and spoofs identd for IRC connections Connects to an IRC server at: pwned.tr1n1.net, or pwned2.tr1n1.net Also scans the local network for shares protected by weak passwords Could also be used for network scans and DDOS attacks
6) Time and local system dependent features The local system must have a network connection for many of the features to work As noted earlier, the malware will pretend to be an identd server to fool IRC servers when connecting. Some of the local system attributes it will query to send back to the IRC server include: The computer's name The specified local Information about the operating system When reporting back to the author, it usually will include the local time Author can query many local system attributes over IRC
7) Method and means of communication Opens a server listener on port 113 that can receive commands Connects to an IRC server at pwned.tr1n1.net or pwned2.tr1n1.net, then joins the channel #scrub and waits for commands from the author
8) Original infection vector and propagation methodology Network shares protected by weak passwords Tricking someone into running the executable
9) Use of encryption for storage, communication None that I could find
10) Use of self modifying or encrypted code The executable is packed with UPX 0.89.6 - 1.02 / 1.05 1.24. I was able to unpack it manually using OllyDBG and Import Reconstructor. On initial analysis, it appears that the only library used is kernel32, since it is the only one statically linked. On further analysis, there is a particular function (at address 0x0040780C) that dynamically loads the other libraries which are used. See Figure for a sample from this function.
Illustration 10: Sample from Library Importing Function
As far as I can tell, there doesn't appear to be any encrypted code.
11) Any information concerning development of malware (compiler type, country of origin, author names/handles, etc.) The malware contains uses the Microsoft Visual C++ Runtime Library so it was probably compiled from within Visual Studio, possibly using CL.exe. The closest thing I could come to a signature by an author was the following strings: neTmaNiac netmaniac was here 12/12/04 13:13:13 netninjaz_place 131.131.131.131 3.72.0.0 I was not able to determine the country of origin from the provided executable.
Technical specifications
Full description
Battle through the tumultuous final year of the Second World War in this expansion pack for EA Games' historical first-person shooter Medal of Honor: Allied Assault. Players take the roles of Sgt. Jack Barnes and a Russian officer as they complete missions during Operation Overlord, the Battle of the Bulge, and the fall of Berlin. The package adds nine new single-player missions, based on operations in Europe from June 1944 through May 1945, and also includes a dozen new multiplayer maps. As with previous Medal of Honor games, developers strove for historical authenticity in this release, working closely with both the Congressional Medal of Honor Society and respected military consultant Capt. Dale Dye. ~ T.J. Deci, All Game Guide
Tags
RTH7400D Velo 8 Diamond 2 SX-218-K Modem 32FS2ANB Quicktips PSR-2100-PSR-1100 PX-tuan-01 Series UX-370 CF-21F80KX GR3400 IC-78 EOC-3220 Minolta 1216 DW7 60 VSF250 Service 5 3 KX-TG2122 DX8400 AVC-3310 DS-5000 NAV210W GT1417DV DSC-W7 ZKC5540W 8-125 CE SC-6500 Suunto G9 60840 6008 AF LBT-XG500 HY-10giii Aficio 2015 RQ1060 19 N-standard KDL-46NX700 Averatec 3150 K300I 50PF9631D Astro Electronics Nevo DCS 520 DMR-EH80V HTR-5240RDS Software HBR657 UX-F12CW AN-LP1 37PF5520D Dslr-A550 GE20S Diva A80 IB48290 AM1250 ZR850 Cs-18 PV-GS83 Multispeed 5 Plus DVR98 Dryer I-DOG C4501 C4 5 TX-36PD50 85276 HR-20E DV7711P Bissell 1672 John Ants AVR-1604 Deskjet F300 A25-S307 Pltv-32M Mercury F4 WS-65869 Crown-victoria-2001 GA-945gcmx-S2 S9500 26LC4R Review 42PFP5532D CD1920 MP-300 VGN-TX650p-B Mypal A636 VP-L710 Quicksteamer Dvdr77-17B TD4212W City 125 UE32C6600 Elite DUO Abit KT7A RS 125 HT-DDW660 DCX700
manuel d'instructions, Guide de l'utilisateur | Manual de instrucciones, Instrucciones de uso | Bedienungsanleitung, Bedienungsanleitung | Manual de Instruções, guia do usuário | инструкция | návod na použitie, Užívateľská príručka, návod k použití | bruksanvisningen | instrukcja, podręcznik użytkownika | kullanım kılavuzu, Kullanım | kézikönyv, használati útmutató | manuale di istruzioni, istruzioni d'uso | handleiding, gebruikershandleiding
Sitemap
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101








1. Medal of Honor Allied Assault War Chest
2. Medal of Honor 10th Anniversary Bundle
3. Medal of Honor: Allied Assault
4. Medal of Honor: Pacific Assault
5. Medal of Honor: Allied Assault Breakthrough Expansion Pack
6. Medal of Honor Allied Assault: Spearhead (Jewel Case)



