Same here.

I know that there is malware that will edit that registry entry and may even set it to "null" or blank, which I suppose is what " " is?

Here is an (old) example:

http://www.ca.com/us/securityadvisor....aspx?id=58501

I would have thought that the current entry would mean that the desktop wouldn't load? I just find it odd that so many machines have been affected without someone saying something sooner.

Probably a thing of the past, but in the old days (NT 4) we used to use logon scripts to do that sort of thing.

I would be interested to know what runs when you boot an affected machine? Are the users supposed to get the normal desktop?