A
andrew
We've recently started experiencing a problem with some users in which
they are unable to login and are getting unable to load profile errors.
Upon investigating, we discovered that certain registry keys were being
changed from within:
"HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell
Folders"
For example, the default %USERPROFILE%\My Documents\My Pictures we
would get C:\Documents and Settings\Local Service\My Documents\My
Pictures. The same 6-8 keys are being changed on each user. Of over
6000 computers, this error is occuring in about a dozen or so. We
tried to figure out any commonalities between these users and have
found none. They don't appear to use the same applications other than
the usual Word, Excel, email, etc.
Obviously, the only way to fix it is to repoint the keys to
%USERPROFILE% and all is well.
Could it be some form of malware? I did a Google search and came up
with nothing that would change any of those keys.
Help!
Thanks
Andrew
they are unable to login and are getting unable to load profile errors.
Upon investigating, we discovered that certain registry keys were being
changed from within:
"HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell
Folders"
For example, the default %USERPROFILE%\My Documents\My Pictures we
would get C:\Documents and Settings\Local Service\My Documents\My
Pictures. The same 6-8 keys are being changed on each user. Of over
6000 computers, this error is occuring in about a dozen or so. We
tried to figure out any commonalities between these users and have
found none. They don't appear to use the same applications other than
the usual Word, Excel, email, etc.
Obviously, the only way to fix it is to repoint the keys to
%USERPROFILE% and all is well.
Could it be some form of malware? I did a Google search and came up
with nothing that would change any of those keys.
Help!
Thanks
Andrew