RESEARCHING RSTRUI PROCESS
Rstrui is a signed Microsoft executable, which handles the system restore features. This executable has “autoElevate” property set to true in the manifest which means it will run with high integrity level. While playing around in ProcessMonitor from Sysinternals, I found out that rstrui.exe accepts command line arguments, I focused on the “/RUNONCE” argument.