Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\winlogon.lnk
- %WINDIR%\Zango\winlogon.exe
- %WINDIR%\Zango\Command.txt
- %WINDIR%\Zango\Zango.dll
- 'za###.usite.pro':80
- http://za###.usite.pro/Area51/zcommand.txt
- http://za###.usite.pro/load/0-0-0-5-20
- DNS ASK za###.usite.pro
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\Zango\winlogon.exe'