("Adfind" OR "ASP\/BackDoor\ " OR "ATK\/" OR "Backdoor.ASP" OR "Backdoor.Cobalt" OR "Backdoor.JSP" OR "Backdoor.PHP" OR "Blackworm" OR "Brutel" OR "BruteR" OR "Chopper" OR "Cobalt" OR "COBEACON" OR "Cometer" OR "CRYPTES" OR "Cryptor" OR "Destructor" OR "DumpCreds" OR "Exploit.Script.CVE" OR "FastReverseProxy" OR "Filecoder" OR "GrandCrab\ " OR "HackTool" OR "HKTL" OR "HTool\-" OR "\/HTool" OR ".HTool" OR "IISExchgSpawnCMD" OR "Impacket" OR "JSP\/BackDoor\ " OR "Keylogger" OR "Koadic" OR "Krypt" OR "Lazagne" OR "Metasploit" OR "Meterpreter" OR "MeteTool" OR "mikatz" OR "Mimikatz" OR "Mpreter" OR "MsfShell" OR "Nighthawk" OR "Packed.Generic.347" OR "PentestPowerShell" OR "Phobos" OR "PHP\/BackDoor\ " OR "Potato" OR "PowerSploit" OR "PowerSSH" OR "PshlSpy" OR "PSWTool" OR "PWCrack" OR "PWDump" OR "Ransom" OR "Rozena" OR "Ryzerlo" OR "Sbelt" OR "Seatbelt" OR "SecurityTool\ " OR "SharpDump" OR "Shellcode" OR "Sliver" OR "Splinter" OR "Swrort" OR "Tescrypt" OR "TeslaCrypt" OR "TurtleLoader" OR "Valyria" OR "Webshell") (-(("anti_ransomware_service.exe" OR "Anti\-Ransomware" OR "Crack" OR "cyber\-protect\-service.exe" OR "encryptor" OR "Keygen") OR Level:4 OR Provider_Name:Microsoft\-Windows\-RestartManager))