KB 943576 fixes a problem I have not seen myself, but could easily bite someone after performing an auth restore in a multi-domain environment.
After you do an auth restore, AD recalculates the USNs it uses to replicate with its partners (the high water marks I presume), but in the case of objects that have been moved from another NC, this process fails in some way.
Hmm, yet another reason to stick with a single domain .