Troj/Agent-DW is a Trojan used in DDoS attacks.
The Trojan opens multiple SMTP connections to IP addresses chosen at random within a 24-bit netmask specified by the author.
Troj/Agent-DW copies itself to the file svchost.exe in the Windows system folder then creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
WindowsUpdate = "C:\Windows\svchost.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
WindowsUpdate = "C:\Windows\svchost.exe"
After installing itself, the Trojan waits for up to five minutes before executing its payload.