is a member of the Win32/Lolyda
family of trojans. This family steals account information from popular online games and sends it to a remote server.
PWS:Win32/Lolyda.AU is dropped by other Lolyda components, which may also be detected as PWS:Win32/Lolyda.AU.
Steals online game information
PWS:Win32/Lolyda.AU attempts to steal the following information from currently-running online game processes:
- User name
- Server address
- Character information
This information is then collected and sent to a remote server.
In the wild, PWS:Win32/Lolyda.AU has been observed to steal information from the games 'AskTao' and 'Perfect World'.
PWS:Win32/Lolyda.AU may also take a snapshot of the user's screen, which is also sent to a remote server.
Analysis by Chun Feng
There are no common symptoms associated with this threat. Alert notifications from installed antivirus software may be the only symptom(s).