Most of the time when the exe is executed the file is extracted to the %TEMP% dir. Since there are no real kix compilers. There probably will be a file.tmp or something similar, easy to spot, clean %temp% before you run the exe. After the script is finished the tmp file will most commonly be deleted so make sure the user who runs it doesn't have delete NTFS permissions, so the tmp file stays afterwards. Then just open it with notepad and hope it isn't encrypted \:\)