Hi there ByTe,

Sorry for the delay in replying, but time zones, sleep and ............the usual suspects?

I have looked at my home setup and two small clients'.............no sign of this here. I seem to recall that you could make this adjustment so that if "" was detected it then opened a new shell specific to a user or possibly user group? You had to define this somewhere so if you search for the registry string you mentioned you will probably find the M$ article, and where to look for what the system will now do?

I seem to recall that the general idea was to cut the login time caused by loading explorer.exe and possibly stop users going where the shouldn't (albeit a Smith & Wesson is a better solution for the latter)

To be honest with you mate I don't like the looks of this?.............My first (CYA) move would be to isolate one of the machines and run a few online AV scanners against it..............then MalwareBytes and SpyBot S&D for good measure.

I would also ask myself "who within the organisation is empowered to make such changes?"

Has someone tried to do something "clever"?????????

As ever, Good Luck mate!