Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 9 December 2005 22:02:20 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Feutel-AW is a backdoor Trojan for the Windows platform.
When first run Troj/Feutel-AW copies itself to <Windows folder>\G_Server2.0.exe and creates the following files:
<Windows folder>\ohadpl.dat
<Windows folder>\psslor.dat
<Windows folder>\vikyik.dat
The files ohadpl.dat, psslor.dat and vikyik.dat are plugin applications and may safely be deleted.
Troj/Feutel-AW inserts itself into Internet Explorer process space.
The file G_Server2.0.exe is registered as a new system driver service named "Plug and P1ay", with a display name of "Plug and P1ay" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\Plug and P1ay\

