Change of plan. I just couldn't stand that process explorer would no longer start and simply had to see if uninstalling Avast! and installing AVG instead made a difference: It has - process explorer starts precisely as it did when Panda was used as my anti-virus, independent of anything Procmon is or is not doing and whether it's running or not.
Sorry if this throws a monkey wrench into anything, but this is the kind of change in behavior, an inexplicable one, that I just have to see if backing out the latest change corrects it. The disk use at startup seems to be much better now when compared to what it was when Panda or Avast! were installed.
After removing Avast I rebooted and ran CCleaner for files and a registry cleanup. There wasn't much trash that it found in the registry, though there were two Panda entries that didn't get cleaned up along with two or three for Avast! Then I cleared the system and application logs and rebooted again. They're so short I'm going to include them here:
VEW System Log:
-------------------------------------------------------------------------------------------
Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 05/02/2015 5:23:00 PM
Note: All dates below are in the format dd/mm/yyyy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 05/02/2015 10:16:18 PM
Type: Error Category: 0
Event: 7034 Source: Service Control Manager
The Realtek DHCP Service service terminated unexpectedly. It has done this 1 time(s).
Log: 'System' Date/Time: 05/02/2015 10:16:07 PM
Type: Error Category: 0
Event: 4 Source: Microsoft-Windows-Time-Service
The time provider 'VMICTimeProvider' failed to start due to the following error: The specified module could not be found. (0x8007007E)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 05/02/2015 10:13:17 PM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.
Log: 'System' Date/Time: 05/02/2015 10:13:17 PM
Type: Warning Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped. Module Path: C:\Windows\system32\Rtlihvs.dll
-------------------------- End System Log -------------------------------------------
VEW Application Log:
-------------------------------------------------------------------------------------------
Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 05/02/2015 5:24:06 PM
Note: All dates below are in the format dd/mm/yyyy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 05/02/2015 10:13:09 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3700817450-263443993-1340972289-1001:
Process 1748 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-3700817450-263443993-1340972289-1001
-------------------------- End Application Log --------------------------------------