Doesn't necessarily mean a user tampered with it. They should've been prompted for a password and it would've simply failed if given the wrong password. The service should not be stopped nor can it be by the user so there may be a different problem with the client here.
Have you tried a reboot of the system? If that didn't work, did you try a repair?
You could check the Security log on the client as it *may* show any user activity in regards to trying to stop the service. Windows Application event log may show something as well.