09/11/09 03:08:08 PM LogName=Security SourceName=Microsoft Windows security auditing. EventCode=4718 EventType=0 Type=Information ComputerName=WIN-L25DGSHI03K TaskCategory=Authentication Policy Change OpCode=Info RecordNumber=169 Keywords=Audit Success Message=System security access was removed from an account. Subject: Security ID: S-1-5-18 Account Name: WIN-L25DGSHI03K$ Account Domain: WORKGROUP Logon ID: 0x3e7 Account Modified: Account Name: S-1-5-32-544 Access Removed: Access Right: SeRemoteInteractiveLogonRight