OllyDbg Detection Tricks

Teddy Rogers

About This File

The year is 2004. The ring-3 debuggers are used often and often. Since they offer Windows GUI they are more handy instead of the ring-0 debuggers (like SoftIce). In this essay I will talk (write) about the detection of one of the best ring-3 debuggers - OllyDbg. Many have heard of the IsDebbugerPresent and of the fs:[20] detecting tricks, but what about some other new ones? Here I will present you some of my own detecting tricks. I will give you the general explanation so you would be able to use your fantasy to improve it yourself.

