As to the rights of the user with "everything", you can find out via the AD Users & Computers MMC snap-in if she's a domain admin (and if not, who is). If that snap-in can't be found, any LDAP browser can be used against the DC to obtain the same information, but you do have to authenticate.