I recently took on a new position as Network Admin. While entering a new user account in the domain, I noticed that the person who I was copying permissions from was Enterprise Admin. This particular user is just a welder. When I logged out of my RDP session and sat at the console of the server, I looked again and the user had only 3 permissions, Everyone, Authenticated User and Eng_Drawings (read only access to Engineering drawings). I changed nothing. Is this some kind of rootkit or virus?