Running procmon comes up with all sorts of stuff, of course now I have to decide what is normal and what isnt.
When I ran procmon only when i tried to start explorer.exe I see quite a bit of stuff, but this one seems like a lead:
Date & Time: 3/7/2009 3:30:08 AM
Event Class: File System
Operation: DeviceIoControl
Result: INVALID PARAMETER
Path: C:\WINDOWS\explorer.exe
TID: 4648
Duration: 0.0000045
Control: IOCTL_MOUNTDEV_QUERY_DEVICE_NAME
And this one was next:
Date & Time: 3/7/2009 3:30:08 AM
Event Class: File System
Operation: CreateFile
Result: NAME INVALID
Path: C:\WINDOWS\explorer.exe
TID: 4648
Duration: 0.0000129
Desired Access: Read Attributes, Synchronize
Disposition: Open
Options: Synchronous IO Non-Alert, Open Reparse Point
Attributes: N
ShareMode: Read, Write
AllocationSize: n/a
Then this

ate & Time: 3/7/2009 3:30:08 AM
Event Class: File System
Operation: QueryNameInformationFile
Result: BUFFER OVERFLOW
Path: C:\WINDOWS\explorer.exe
TID: 4648
Duration: 0.0000111
Name: \W
And finally:
Date & Time: 3/7/2009 3:30:08 AM
Event Class: File System
Operation: UnlockFileSingle
Result: RANGE NOT LOCKED
Path: C:\WINDOWS\WiseHook.ini
TID: 3556
Duration: 0.0000048
Offset: 0
Length: 4,294,967,295
The wisehook.ini thing looks to be part of Alteris deployment, so maybe thats causing an issue. maybe..
To simplify this is everything procmon shows when i run explorer.exe.
4:12:40.5395346 AM explorer.exe 4264 UnlockFileSingle C:\WINDOWS\WiseHook.ini RANGE NOT LOCKED Offset: 0, Length: 4,294,967,295
4:12:40.5755826 AM explorer.exe 4264 RegEnumValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack NO MORE ENTRIES Index: 0, Length: 220
4:12:40.6302826 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell BUFFER OVERFLOW Length: 16
4:12:40.6304420 AM explorer.exe 4264 RegQueryKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon BUFFER OVERFLOW Query: Basic, Length: 24
4:12:40.6304709 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell BUFFER OVERFLOW Length: 16
4:12:40.6915542 AM explorer.exe 4264 RegEnumKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers NO MORE ENTRIES Index: 1, Length: 288
4:12:40.7319272 AM explorer.exe 4264 CreateFile C:\WINDOWS\Debug\UserMode\ChkAcc.bak SHARING VIOLATION Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
4:12:40.7415604 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7419119 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{36BBA8D2-CA5C-4847-81CC-4F807DD86C91}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7426377 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7429777 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7440665 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7443604 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6D69F546-C1AF-4049-AE9E-28627B91D3F5}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7452268 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7463137 AM explorer.exe 4264 RegQueryValue HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\StubPath BUFFER OVERFLOW Length: 144
4:12:40.7507131 AM explorer.exe 4264 RegEnumKey HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components NO MORE ENTRIES Index: 49, Length: 288
4:12:40.7754492 AM explorer.exe 4264 RegQueryValue HKCU\Software\Classes\http\shell\open\command\(Default) BUFFER OVERFLOW Length: 144
4:12:40.8278791 AM explorer.exe 4264 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\IconStreams BUFFER OVERFLOW Length: 144
4:12:40.8281281 AM explorer.exe 4264 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\IconStreams BUFFER OVERFLOW Length: 144
4:12:40.8285286 AM explorer.exe 4264 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\PastIconsStream BUFFER OVERFLOW Length: 144
4:12:40.8293490 AM explorer.exe 4264 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotify\PastIconsStream BUFFER OVERFLOW Length: 144