All right, this time I remembered of the process tree view in procmon
You've got a VBS script on your desktop that triggers Open With:
Looks like some kind of a modem stats collector.
Why is it residing on the Desktop and why is it trying to launch? I don't know. It's unlikely to be malicious, so there may be a scheduled task launching it at startup. That would explain why it doesn't start in safe mode, but not listed in msconfig/taskmgr.
Start Autoruns as Administrator and Ctrl+S the data file for me to take a look.