A new paper by Michael Myers and Stephen Youndt explains how to exploit HVM rootkits. The paper says the rootkit runs in a more privileged state than the operating system. The practical detectability of HVM Rootkits is still hotly contested. Researchers are continually suggesting new detection methods, and the code required in the HVMrootkit to evade each one is successively layering more and more complexity into the design. The more complicated an HVMRootkit must be to avoid known detection schemes, the more presence it has within the system to have to work to hide.”]
Source: https://taosecurity.blogspot.com/2007/09/hardware-assisted-virtual-machine.html