Mal/Conficker-B is the latest variant of the Conficker botnet virus. It uses a set of virtual machine detection tests to see if its running inside a virtual machine. Conficker doesnt bail out if any of these detect that it is running in a VM. The most obvious explanation would be that the owners are harvesting that data to get a better idea of the computers they have available. Both of these samples share almost exactly the same spaghetti code obfuscation method.”]
Source: https://nakedsecurity.sophos.com/2009/03/27/confickers-virtual-machine-detection/

