It is in the passwd file, but no special characters.
no hits in splunkd.log
Was able to fix it tho...removed it via the cli.. then was able to re-add it with the GUI
./splunk remove user "user"
in linux shell run this command (replace "username" with your "lost" username):
grep "username" $SPLUNK_HOME/var/log/splunk/splunkd.log