Forum Moderators: open
If a successful connection is made, Deloder drops a called INST.EXE in the Windows Start folder. This is a Trojan designed to open a backdoor access to compromised computer.Deloder then copies a file called DVLDR32.EXE, a copy of the worm itself, onto infected machines.
Then from Symantec [securityresponse.symantec.com]:
W32.HLLW.Deloder is a network-aware worm that attempts to connect to a target host, using TCP port 445. This worm affects Windows 2000 and Windows XP only.