Again, I'm guessing Kix2Exe, but if it is K2E, monitor the temp directory while the exe is running. It creates a folder to drop the kix32.exe and script in. The file will most likely be tokenized, but if not, you would have the script.