I know that there is malware that will edit that registry entry and may even set it to "null" or blank, which I suppose is what " " is?
Here is an (old) example:
I would have thought that the current entry would mean that the desktop wouldn't load? I just find it odd that so many machines have been affected without someone saying something sooner.
Probably a thing of the past, but in the old days (NT 4) we used to use logon scripts to do that sort of thing.
I would be interested to know what runs when you boot an affected machine? Are the users supposed to get the normal desktop?