Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
HKU\S-1-5-21-1522174088-88585167-861875459-1001\...\MountPoints2: {b5d0e2b6-7809-11eb-9670-001a7dda7113} - "D:\setup.exe"
HKU\S-1-5-21-1522174088-88585167-861875459-1001\...\MountPoints2: {b5d0e658-7809-11eb-9670-001a7dda7113} - "E:\setup.exe"
HKU\S-1-5-21-1522174088-88585167-861875459-1001\...\MountPoints2: {e56d042e-7915-11eb-9672-001a7dda7113} - "F:\HiSuiteDownLoader.exe"
VirusTotal: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BeTwinToggleDesktop.scf
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ограничение <==== ВНИМАНИЕ
FirewallRules: [{17F645EA-442E-4C30-A59A-E6046EBE08E8}] => (Allow) LPort=51111
FirewallRules: [{9BC94511-E359-4236-A57B-B954170BF36C}] => (Allow) LPort=51112
FirewallRules: [{6BED049D-639A-446A-9DD8-F308C5668578}] => (Allow) LPort=51113
cmd: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
EmptyTemp:
Reboot:
End::