"Hello, and welcome to our SANS@Night presentation on virtual machine
detection, and some possible methods for thwarting the types of detection
currently in use by malware in the wild.
We’ll start things off with an overview of some of the methods being used to
detect the use of virtual machine environments – how they work and what exactly
they are detecting. Finally, we’ll pass along some tips for making use of a
virtualized environment more difficult for the bad guys to detect.
So, please sit back, relax, and follow along. If you have any questions, please
feel free to ask!"
Read the full tutorial here :
hxxp://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf