"The zip file, however, can be constructed so that it also decompresses to c:\windows\system32\explorer.exe."

So long as the file isn't in use, of course...which it will be, unless you're using something else as SHELL. Unless it somehow manages to terminate the process when it reaches that point in the archive, overwrite it and when the shell reloads - that's when your'e in for a world of pain.

