Here is an event log I've managed to uncover for this user on every machine they log onto. Hopefully it will shine a light on the possible culprit and someone can point me in the right direction?

Event Type: Audit Failure
Event Source: Security
Event Category: Privilege Use
Event ID: 577
Date: 8/20/2003
Time: 9:58:01 AM
User: rodriguezm
Computer: SYSTEM1
Description:
Privileged Service Called:
Server: Security
Service: -
Primary User Name: rodriguezm
Primary Domain: AMSEC
Primary Logon ID: (0x0,0x2331ACD)
Client User Name: -
Client Domain: -
Client Logon ID: -
Privileges: SeIncreaseBasePriorityPrivilege
Data:
_________________________
silence is golden, but duct tape is silver