Reviews & Opinions
Independent and trusted. Read before buy Games PC Shogun - Total War - Warlord Edition!

Games PC Shogun - Total War - Warlord Edition


Bookmark
Games PC Shogun - Total War - Warlord Edition

Bookmark and Share

 

Games PC Shogun - Total War - Warlord EditionShogun: Total War -- Warlord Edition [PC Game]

Sold Out Software (2003) - Empire-Building



Details
Platform: PC
Publisher: Sold Out Software
Release Date: September 26, 2003
UPC: 5037999006312


Here you can find all about Games PC Shogun - Total War - Warlord Edition, for example manual and review. You can also write a review.
[ Report abuse or wrong photo | Share your Games PC Shogun - Total War - Warlord Edition photo ]

 

 

Manual

Preview of first few manual pages (at low quality). Check before download. Click to enlarge.
Manual - 1 page  Manual - 2 page  Manual - 3 page 

Download (English)
Games PC Shogun-total War-warlord Edition, size: 2.2 MB

 

Games PC Shogun - Total War - Warlord Edition

 

 

Video review

116: Shogun: Total War Warlord Edition (Gameplay, german version)

 

User reviews and opinions

<== Click here to post a new opinion, comment, review, etc.

Comments to date: 2. Page 1 of 1. Average Rating:
Bug 2:36pm on Tuesday, October 5th, 2010 
A MILESTONE IN GAMING HISTORY!!! A MILESTONE IN GAMING HISTORY!!! the BEST war game ive played An absolutely awesome piece. The graphics and sound is just so fantastic! Able to coontrol hundreds of troops at a time.
VaMPiRiC_CRoW 2:32pm on Sunday, June 6th, 2010 
One of the best strategy games out there Shogun: Total War is one of the best strategy games ever.

Comments posted on www.ps2netdrivers.net are solely the views and opinions of the people posting them and do not necessarily reflect the views or opinions of us.

 

Documents

doc0

Certified Reverse Engineering Analyst (CREA) Practical Analyst Date Malware Jason Swallows 1 February 2010 Practical 1252
Item A - File Provided: malware.exe, MD5: 0783505871f4d862b78d4a709827d42d 1) General function and functionality of the malware Item A is a Windows-based worm that: Opens a port on 113 and spoofs identd for IRC connections. Connects to an IRC server, joins a channel and waits for commands from the author. Commands give broad control of the machine to the author Can steal keys for many games. Can spread by exploiting network shares with weak passwords (uses a list of common user names and passwords).
2) Behavioral patterns of malware Since Item A attempts to propagate by scanning network shares, it has the behavioral pattern of a worm. It also could be classified as a Bot, since it sits and waits for commands from the author.
3) Local system interaction Makes the file and registry modifications listed under Question #4. Kills the following processes (See Illustration 1 & 2) "regedit.exe" "MSBLAST.exe" "msconfig.exe" "teekids.exe" "netstat.exe" "Penis32.exe" "msblast.exe" "bbeagle.exe" "zapro.exe" "SysMonXP.exe" "navw32.exe" "winupd.exe" "navapw32.exe" "winsys.exe" "zonealarm.exe" "ssate.exe" "wincfg32.exetaskmon.exe" "rate.exe" "PandaAVEngine.exe" "d3dupdate.exe" "sysinfo.exe" "irun4.exe" "mscvb32.exe" "i11r54n4.exe
Illustration 2: 0x00429DB0 starts the list of processes to be killed
Illustration 1: If one of the processes above is identified, open it, then terminate it.
Deletes the following shares (See Illustration 3) IPC$ ADMIN$ C$ D$
Illustration 3: Delete network shares
When controlled via IRC, commands can be issued by the controller to achieve objectives on the local system. There are many commands, but I will just document a few here as examples. Command: capture or cap, Purpose: Can capture an image or movie from a webcam or the desktop
Illustration 3: Code sample from screen/cam capture process
Command: execute or e, Purpose: Attempts to run a program on the local system
Illustration 4: Code sample from execution process
Command: readfile or rf, Purpose: Allows controller to read a file from local system
Illustration 5: Code sample from file reading process
Other commands, which I won't go into, provide capabilities for the following: E-mailing File searching, listing, deleting, etc. DNS queries or cache flushing File downloading and uploading Clipboard capture Processes listing and stopping Rebooting System information Network scanning Denial of service attacks TFTP capabilities Many more! Opens a port on 113 and spoofs identd for IRC connections.
Illustration 6: A small section of the code for starting the listener.
Illustration 7: Sample of offsets to the received requests and related functions.

4) Files and registry keys created, modified and accessed File access/modification: Copies itself, as scrgrd.exe, to the %System% folder and creates a new process with the newly copied executable.
Illustration 6: The name for the new executable is scrgrd.exe
Illustration 7: Initialize CopyFileA to esi to be called later
Potentially accesses <Soldier of Fortune II Install Path>\base\mp\sof2key to check for a CD Key. Potentially access <Neverwinter Nights Install Path>\nwncdkey.ini to check for CD keys. Potentially files created, changed by author over IRC Registry (Creates, to ensure execution of the malware on startup) Creates HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Restore with the value %System%\scrgrd.exe Creates HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Restore with the value %System%\scrgrd.exe Creates HKEY_LOCAL_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Restore with the value %System%\scrgrd.exe
Illustration 8: Registry entry creation area.
Registry (Changes value of)
Sets the value of HKLM\Software\Microsoft\OLE\EnableDCOM to N Sets the value of HKLM\SYSTEM\CurrentControlSet\ Control\Lsa\restrictanonymous to 1 Registry (Checks for and gets value of) "HKCU\Software\\Valve\\CounterStrike\\Settings\CDKey" "HKCU\Software\\Eugen Systems\\The Gladiators\RegNumber" "HKCU\Software\\Valve\\Gunman\\Settings\Key" "HKCU\Software\\Valve\\Half-Life\\Settings\Key" "HKCU\Software\\JoWooD\\InstalledGames\\IG2\prvkey" "HKCU\Software\\3d0\\Status\CustomerNumber" "HKCU\Software\Silver Style Entertainment\Soldiers Of Anarchy\Settings\CDKey" "HKLM\Software\Microsoft\Windows\CurrentVersion\ProductId" "HKLM\Software\Unreal Technology\Installed Apps\UT2003\CDKey" "HKLM\Software\Unreal Technology\Installed Apps\UT2004\CDKey" "HKLM\Software\IGI 2 Retail\CDKey" "HKLM\Software\Electronic Arts\EA Distribution\Freedom Force\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942 The Road to Rome\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield 1942 Secret Weapons of WWII\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Battlefield Vietnam\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Black and White\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Command and Conquer Generals Zero Hour\ergc" "HKLM\Software\Electronic Arts\EA GAMES\James Bond 007 Nightfire\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Generals\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Global Operations\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Breakthrough\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Medal of Honor Allied Assault Spearhead\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Need For Speed Hot Pursuit 2\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Need For Speed Underground\ergc" "HKLM\Software\Electronic Arts\EA GAMES\Shogun Total War - Warlord Edition\ergc" "HKLM\Software\Electronic Arts\EA Sports\FIFA 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\FIFA 2003\ergc" "HKLM\Software\Electronic Arts\EA Sports\NHL 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\NHL 2003\ergc" "HKLM\Software\Electronic Arts\EA Sports\Nascar Racing 2002\ergc" "HKLM\Software\Electronic Arts\EA Sports\Nascar Racing 2003\ergc" "HKLM\Software\Red Storm Entertainment\RAVENSHIELD\CDKey" "HKLM\Software\Westwood\Tiberian Sun\Serial" "HKLM\Software\Westwood\Red Alert\Serial" "HKLM\Software\Westwood\Red Alert 2\Serial" "HKLM\Software\Westwood\NOX\Serial" "HKLM\Software\\Techland\\Chrome\SerialNumber" "HKLM\Software\Illusion Softworks\Hidden & Dangerous 2\key"

Illustration 9: A portion of the key stealer code.
Registry (Other) If "HKLM\Software\Activision\Soldier of Fortune II - Double Helix\InstallPath exists, gets its value, which is the installation path of this game, then under that path, checks for the file base\mp\sof2key to get the key If Software\\BioWare\\NWN\\Neverwinter\Location exists, gets its value, which is the installation path of this game, then under that path, checks for the file nwncdkey.ini. If this file is found, checks for the text Key1=, Key2= and Key3= to get the key for Neverwinter Nights and its expansion packs (assuming they are installed too).
5) Network behavior (including hosts, domains and IP addresses accessed) As mentioned earlier, Opens a port on 113 and spoofs identd for IRC connections Connects to an IRC server at: pwned.tr1n1.net, or pwned2.tr1n1.net Also scans the local network for shares protected by weak passwords Could also be used for network scans and DDOS attacks
6) Time and local system dependent features The local system must have a network connection for many of the features to work As noted earlier, the malware will pretend to be an identd server to fool IRC servers when connecting. Some of the local system attributes it will query to send back to the IRC server include: The computer's name The specified local Information about the operating system When reporting back to the author, it usually will include the local time Author can query many local system attributes over IRC
7) Method and means of communication Opens a server listener on port 113 that can receive commands Connects to an IRC server at pwned.tr1n1.net or pwned2.tr1n1.net, then joins the channel #scrub and waits for commands from the author
8) Original infection vector and propagation methodology Network shares protected by weak passwords Tricking someone into running the executable
9) Use of encryption for storage, communication None that I could find
10) Use of self modifying or encrypted code The executable is packed with UPX 0.89.6 - 1.02 / 1.05 1.24. I was able to unpack it manually using OllyDBG and Import Reconstructor. On initial analysis, it appears that the only library used is kernel32, since it is the only one statically linked. On further analysis, there is a particular function (at address 0x0040780C) that dynamically loads the other libraries which are used. See Figure for a sample from this function.

Illustration 10: Sample from Library Importing Function
As far as I can tell, there doesn't appear to be any encrypted code.
11) Any information concerning development of malware (compiler type, country of origin, author names/handles, etc.) The malware contains uses the Microsoft Visual C++ Runtime Library so it was probably compiled from within Visual Studio, possibly using CL.exe. The closest thing I could come to a signature by an author was the following strings: neTmaNiac netmaniac was here 12/12/04 13:13:13 netninjaz_place 131.131.131.131 3.72.0.0 I was not able to determine the country of origin from the provided executable.

 

Tags

WPN824 3000AD CPX885 Trident DAV-DZ230 Laserjet 3600 Istdl NRL-LS533 GTO1504D Dmclz7 VGN-SR19VN AR-NB3 HD160JJ-P UB1002 C3205 AVR-1505 970CSE CX-DP803 Player Inspiron 1200 VCM-100 MX6448 CCD-TRV66E SV8004H Theater 3 BAP1700-CN MR F55 Mobile Photo R245 Shotgun F505T VP-DX102 ROM 9 GMR1838-2CK 32LG5030 P92 Echo Malice Series Portege M100 IC-281H WUR0108T Gpsmap 60 Rangefinders NAS-S55HDE HP 210 Swing 105-R Date WD-16NEW Satellite 31 To Life BV7250T DV-DS251E VM 200 PCG-GRX516MD 240V Rd 168 ES100 Psch-L Vpointhd 445TR Yamaha RY30 ION 230 TL-WR941ND Honeywell SDC KRC-779R UR19A MF2140 Satellite 1400 DVD-P350K 24-5H Motorola V550 DPF-E75 KDC-5021V SPA-240 EW524F Jetflash V30 Audioline 30 42PFL5522D 05 Review HDC-HS100P HR7775 00 Zyxel V300 Digimax430 VP-DC563I DPM-07065A 1LE21S SP250 5XI 400VTX 620 USB PC1864 L1720B Est-CE PA-3000 EN7100SI Gravity Kxtg1100PD ESD6000 HI-202E CDX-HS70MW

 

manuel d'instructions, Guide de l'utilisateur | Manual de instrucciones, Instrucciones de uso | Bedienungsanleitung, Bedienungsanleitung | Manual de Instruções, guia do usuário | инструкция | návod na použitie, Užívateľská príručka, návod k použití | bruksanvisningen | instrukcja, podręcznik użytkownika | kullanım kılavuzu, Kullanım | kézikönyv, használati útmutató | manuale di istruzioni, istruzioni d'uso | handleiding, gebruikershandleiding

 

Sitemap

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101