Hello again, sorry about the delay I've been away from the machine for a few days...
Here is the file list (btw the dir command gave a 'file not found'):
Volume in drive C is XPPro
Volume Serial Number is 08FB-1CFB
Directory of C:\Documents and Settings\Colin\Local Settings\Temp\WER4a7d.dir00
2006-09-06 09:16 0 explorer.exe.mdmp
1 File(s) 0 bytes
Directory of C:\pebuilder3110a\BartPE\I386
2004-08-04 13:00 1,032,192 EXPLORER.EXE
1 File(s) 1,032,192 bytes
Directory of C:\Program Files\Microsoft Platform SDK\Samples\Com\Administration\Explore.Vb
2005-04-04 18:45 43,781 Explorer.Frm
2005-04-04 18:45 13,498 Explorer.Frx
2 File(s) 57,279 bytes
Directory of C:\Program Files\Microsoft Visual Studio\Common\Graphics\Bitmaps\Outline\NoMask
1998-04-24 00:00 246 EXPLORER.BMP
1 File(s) 246 bytes
Directory of C:\Program Files\Microsoft Visual Studio\Common\Graphics\Bitmaps\Outline\RedMask
1998-04-24 00:00 246 EXPLORER.BMP
1 File(s) 246 bytes
Directory of C:\Program Files\Microsoft Visual Studio\Common\Graphics\Icons\Win95
1998-04-24 00:00 1,078 EXPLORER.ICO
1 File(s) 1,078 bytes
Directory of C:\Program Files\Microsoft Visual Studio\MSDN\2001OCT\1033\SAMPLES\VB98\WcDemo
1999-07-26 00:00 20,278 EXPLORER.BMP
1 File(s) 20,278 bytes
Directory of C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\Graphics\bitmaps\Outline\NoMask
2000-11-21 02:18 246 EXPLORER.BMP
1 File(s) 246 bytes
Directory of C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\Graphics\bitmaps\Outline\RedMask
2000-11-21 02:18 246 EXPLORER.BMP
1 File(s) 246 bytes
Directory of C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\Graphics\icons\Win95
2000-11-21 02:39 1,078 EXPLORER.ICO
1 File(s) 1,078 bytes
Directory of C:\Program Files\Microsoft Visual Studio .NET 2003\SDK\v1.1\Samples\Technologies\Interop\Basic\InternetExplorer
2001-08-27 21:39 8,982 Explorer.cs
1 File(s) 8,982 bytes
Directory of C:\Program Files\Microsoft Visual Studio .NET 2003\SDK\v1.1\Tool Developers Guide\Samples\adepends\gui
2001-06-26 19:14 7,336 explorer.cs
1 File(s) 7,336 bytes
Directory of C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\ItemTemplatesCache\VisualBasic\1033
2005-03-22 10:35 <DIR> Explorer.zip
0 File(s) 0 bytes
Directory of C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\ItemTemplatesCache\VisualBasic\1033\Explorer.zip
2004-04-21 15:04 33,165 explorer.designer.vb
2004-04-01 11:49 41,569 explorer.resx
2004-04-01 11:49 13,964 explorer.vb
2004-04-01 11:49 2,224 explorer.vstemplate
4 File(s) 90,922 bytes
Directory of C:\Usr\Bin
2004-08-04 13:00 1,032,192 explorer.exe
1 File(s) 1,032,192 bytes
Directory of C:\WINDOWS
2004-08-04 13:00 1,032,192 explorer.exe
2004-08-04 13:00 1,032,192 explorer.exe.orig
2004-08-04 13:00 80 explorer.scf
3 File(s) 2,064,464 bytes
Directory of C:\WINDOWS\Prefetch
2006-08-25 09:23 8,556 EXPLORER.EXE-082F38A9.pf
2006-09-01 11:33 39,994 EXPLORER.EXE-0C648EA3.pf
2006-09-06 09:53 86,604 EXPLORER.EXE-2722A18E.pf
3 File(s) 135,154 bytes
Directory of C:\WINDOWS\Symbols\exe
2004-08-03 23:17 994,304 explorer.pdb
1 File(s) 994,304 bytes
Directory of C:\WINDOWS\system32\dllcache
2004-08-04 13:00 1,032,192 explorer.exe
1 File(s) 1,032,192 bytes
and here is the registry search:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "explorer.exe" 2006-09-06 10:03:26
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\explorer.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\WINWORD.EXE\TaskbarExceptionsIcons\explorer.exe,16]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Briefcase\shell\open\command]
@="explorer.exe %1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}]
"LocalizedString"="@explorer.exe,-7020"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}]
"InfoTip"="@explorer.exe,-7000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}]
"LocalizedString"="@explorer.exe,-7021"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}]
"InfoTip"="@explorer.exe,-7001"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}]
"LocalizedString"="@explorer.exe,-7022"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}]
"LocalizedString"="@explorer.exe,-7023"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}]
"InfoTip"="@explorer.exe,-7003"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}]
"LocalizedString"="@explorer.exe,-7024"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}]
"InfoTip"="@explorer.exe,-7004"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}]
"LocalizedString"="@explorer.exe,-7025"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}]
"InfoTip"="@explorer.exe,-7005"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}\DefaultIcon]
@="C:\\WINDOWS\\explorer.exe,-103"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\AllDevices\shell\explore\command]
@="Explorer.exe /e,/idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\AllDevices\shell\open\command]
@="Explorer.Exe /idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\Camera\shell\explore\command]
@="Explorer.exe /e,/idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\Camera\shell\open\command]
@="Explorer.Exe /idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\CameraContainerItems\shell\explore\command]
@="Explorer.exe /e,/idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\CameraContainerItems\shell\open\command]
@="Explorer.Exe /idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\Scanner\shell\explore\command]
@="Explorer.exe /e,/idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E211B736-43FD-11D1-9EFB-0000F8757FCD}\Scanner\shell\open\command]
@="Explorer.Exe /idlist,%I,/L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Publishing Folder\shell\explore\command]
@="explorer.exe /e,/idlist,%I,%L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Publishing Folder\shell\open\command]
@="explorer.exe /idlist,%I,%L"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SHCmdFile\shell\open\command]
@="explorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name"="explorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\International]
"explorer.exe"="6.0.2600.0-6.0.9999.9999"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]
"explorer.exe"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION]
"explorer.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation]
"KillList"="%1;explorer.exe;dvdplay.exe;mplay32.exe;msohtmed.exe;quikview.exe;rundll.exe;rundll32.exe;taskman.exe;bck32api.dll;"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel\MyComp]
"Bitmap"="%SystemRoot%\\explorer.exe,100"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"Icon"="explorer.exe#0100"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"Icon"="explorer.exe#0100"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="c:\\usr\\bin\\explorer.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\explorer.exe]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Control\Nls\MUILanguages\RCV2\explorer.exe]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\explorer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"Icon"="explorer.exe#0100"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"Icon"="explorer.exe#0100"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"Icon"="explorer.exe#0100"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Dependency Walker\Recent File List]
"File1"="C:\\WINDOWS\\explorer.exe"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"q"="c:\\windows\\explorer.exe\\1"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"Icon"="explorer.exe#0100"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"Icon"="explorer.exe#0100"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@explorer.exe,-7023"="&Run..."
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@explorer.exe,-7020"="&Search"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@explorer.exe,-7021"="&Help and Support"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@explorer.exe,-7003"="Opens a program, folder, document, or Web site."
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"c:\\usr\\bin\\explorer.exe"="Windows Explorer"
[HKEY_USERS\S-1-5-21-1454471165-1580436667-839522115-1016\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\WINDOWS\\explorer.exe"="Windows Explorer"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"Icon"="explorer.exe#0100"