Thanks for the paper, it was a nice read. I was stunned to see how straightforward it was.
Basically by order of appearance you look for
* well know files, or registry keys
* patterns in a memory dump
* use a great hack called "the red pill" using the SIDT instruction
* vm specific hardwares
* specific instructions/capabilities