Troj/Agent-IW is a downloading Trojan.
The Trojan attempts to connect to the website dappc.com in order to download a file containing instructions about the URLs to visit and files to download and run. If the connection is successful, the file is saved as param.txt in the Windows system folder.
Troj/Agent-IW may be uploaded by the Trojan writer onto a web site. A web page may contain an exploit that attempts to drop and run the Trojan executable.
In order to run automatically when Windows starts up the Trojan copies itself to the file hiden.exe in the Windows system folder.
Troj/Agent-IW adds the following registry entry so that the Trojan file is run every time the user logs on to the computer:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
hiden
hiden.exe