alibi 3.8 · python · consolidated reportscan BREAD-PC · 2026-05-25T23:48:18 · read-only · 1 outbound call to loldrivers.io (opt-in)
Verdict

CHEATS DETECTED

High-confidence indicators of cheat software, HWID spoofers, or DMA-cheat development artifacts were present on this machine within the last 180 days.

host
BREAD-PC
user
BradS
os
Windows 11 · 10.0.26200
admin
false
scan
2026-05-25 23:48:18 · pc-mode
Recent findings · last 180d
HIGH12verdict-drivingMEDIUM4dual-use signalsWARN2access deniedINFO4scan summary
cheat-kind 12input-kind 2dual-use 6archived 2 (off-verdict)

Why this verdict · 12 named items

click an item to jump & pin its finding card ↓
  • Prefetchengineowning — ENGINEOWNING
  • MUICacherut.gg — C:\Users\Bob\Downloads\RUT V4 Launcher.exe
  • DMApcileech firmware build output: pcileech_top.bin
  • KnownHashesRUT AND RUAVT LAUNCHER UPDATED.exe (rut.gg) — hash match - confirmed cheat sample
  • LOLDriversVULNERABLE DRIVER - hash confirmed (BYOVD risk): rtcore64.sys
  • UserScriptsbcdedit /set testsigning — ~\Desktop\setup.bat - high-risk command pattern inside script
  • UserScriptsMoveMouseRelative — ~\Documents\macros\norecoil.lua - mouse-macro / anti-recoil script pattern
  • AIVisionaimmy — AI-vision aimbot executable: aimmy.exe
  • AIVisionONNX model co-located with AI-aimbot executable: yolov8n.onnx
  • BCDTEST SIGNING ENABLED - unsigned drivers can load
  • ProcessENGINEOWNING.exe (PID 9128) running
  • ServiceHidHide service (Running)

Also detected · input devices (separate category)

  • USBcronus — Cronus Zen
  • AppDataCronus / Titan - 247 files, 38 distinct days
Forensic timeline

Log-scale recency · 22 recent + 2 archived findings

8in last 7 days
12in last 30 days
14in last 180 days
HIGHMEDWARNINFOtoday−1d−3d−1w−2w−1mo−3mo−6moarchive · 2> 180dlog compressed →1y7y
Category signal · which scanners firedclick to filter findings ↓

00All indicators · score distribution

findings + processes + services · 30 indicators
total30indicators
HIGH12 findings · 1 process · 1 service14
MEDIUM4 findings · 1 process · 1 service6
WARN2 findings · access denied2
INFO4 scan-summary findings · informational only4
LOW / CLEAN3 LOW/CLEAN processes · 1 LOW/CLEAN services4

Each slice is one score tier across all artifact classes. 14 HIGH indicators (46.7%) drive the verdict. A clean machine would show a single solid LOW/CLEAN ring — the more red and amber present, the worse the picture.

01Findings · cheat trace scan

recent (≤180d) · verdict-relevant

HIGH

12 findings

MEDIUM

4 findings

WARN · access denied

2 findings

INFO

4 findings · hidden by default

02·03Runtime · processes & services

hover a row to highlight linked findings ↑

Processes

1HIGH1MED3LOW/CLEAN
scorepidname · path
LOW12384chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
3 of 5 shown · 2 CLEAN hidden

Services

1HIGH1MED1LOW/CLEAN
scorestatename · path
2 of 3 shown · 1 CLEAN hidden
archived · > 180 days · did NOT affect verdict

2 finding(s) with a most-recent timestamp older than 180 days were demoted by the recency-decay rule. 1 originally HIGH-severity. They are logged here for transparency — old artifacts from games or tools the user has long since stopped using do not, on their own, make a currently-clean machine look dirty.

Coverage limitations

alibi 4.0 · python · read-only scan · no system state was modified1 outbound call to loldrivers.io (opt-in) · file self-contained