I got a really good tip from a Colleague Richard Diver the other day which helps verify whether a customer had the conficker virus. This was a tip passed on to him by Lesley Kipling a Senior Support Engineer within Microsoft Security team in the U.K.

Top Tip

To prevent panicking your customer when they might have a Conficker infection, keep this snippet handy to check for sure:

1. In Registry Editor, locate and then click the following registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
2. In the details pane, right-click the netsvcs entry, and then click Modify.
If the computer is infected with the Win32/Conficker virus, a random service name will be listed.

