Is anyone familiar with this executable? It lives in the Rsview Enterprise folder and runs as a process. At one minute intervals, it raises an event id 4625 on the computer (failed login attempt) and eventually locks out the active directory account that logs into the machine.