High-confidence indicators of cheat software, HWID spoofers, or DMA-cheat development artifacts were present on this machine within the last 180 days.
19 dated events across 8 patterns. Diamonds are install dates from the Windows uninstall registry; circles are execution, write, USB-arrival, or run events. Hover any marker for the source field and date.
Each slice is one score tier across all artifact classes. 14 HIGH indicators (50.0%) drive the verdict. A clean machine would show a single solid LOW/CLEAN ring — the more red and amber present, the worse the picture.
C:\Users\Marcus\source\aimmy\aimmy.exeC:\Users\Marcus\source\aimmy\models\yolov8n.onnxC:\Users\Marcus\AppData\Local\ConsoleTunertestsigningC:\Users\Marcus\source\pcileech-fpga-build\pcileech_top.binC:\Users\Marcus\Downloads\RUT V4 Launcher.exeC:\Users\Marcus\AppData\Local\Temp\rtcore64.sysHKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCacheC:\Windows\Prefetch\ENGINEOWNING.EXE-7A4C2E91.pfVID_2E24&PID_1000C:\Users\Marcus\Desktop\setup.batC:\Users\Marcus\Documents\macros\norecoil.luaSysmon EID 7Cheat Engine 7.5C:\Users\Marcus\Downloads\3a7b9c1e2d4f6018.exeHKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettingsHKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache| score | pid | name · path |
|---|---|---|
| HIGH | 9128 | ENGINEOWNING.exe C:\Users\Marcus\AppData\Local\engineowning\EO.exe matches 'engineowning' (cheat keyword) · cmd "C:\Users\Marcus\AppData\Local\engineowning\EO.exe" --loader |
| MEDIUM | 7416 | cheatengine-x86_64.exe C:\Program Files\Cheat Engine 7.5\cheatengine-x86_64.exe matches 'cheatengine' (dual-use tool) · cmd "C:\Program Files\Cheat Engine 7.5\cheatengine-x86_64.exe" |
| LOW | 12384 | chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe |
| score | state | name · path |
|---|---|---|
| HIGH | Running Auto | HidHide · HidHide Service C:\Program Files\Nefarius Software Solutions\HidHide\x64\HidHideClient.exe matches 'hidhide' (input-device keyword) |
| MEDIUM | Running Manual | ViGEmBus · Virtual Gamepad Emulation Bus C:\Windows\System32\drivers\ViGEmBus.sys matches 'vigembus' (dual-use tool) |
1 finding(s) with a most-recent timestamp older than 180 days were demoted by the recency-decay rule. 1 originally HIGH-severity. They are logged here for transparency — old artifacts from games or tools the user has long since stopped using do not, on their own, make a currently-clean machine look dirty.
C:\Windows\Prefetch\OLDCHEAT.EXE-9F8E7D6C.pf