Troj/Feutel-AW is a backdoor Trojan for the Windows platform.
When first run Troj/Feutel-AW copies itself to <Windows folder>\G_Server2.0.exe and creates the following files:
<Windows folder>\ohadpl.dat
<Windows folder>\psslor.dat
<Windows folder>\vikyik.dat
The files ohadpl.dat, psslor.dat and vikyik.dat are plugin applications and may safely be deleted.
Troj/Feutel-AW inserts itself into Internet Explorer process space.
The file G_Server2.0.exe is registered as a new system driver service named "Plug and P1ay", with a display name of "Plug and P1ay" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\Plug and P1ay\