Log Name: Security Source: Microsoft-Windows-Security-Auditing Date: 10/27/2009 9:52:55 PM Event ID: 4905 Task Category: Audit Policy Change Level: Information Keywords: Audit Success User: N/A Computer: dcc1.Logistics.corp Description: An attempt was made to unregister a security event source. Subject Security ID: S-1-5-18 Account Name: DCC1$ Account Domain: LOGISTICS Logon ID: 0x3e7 Process: Process ID: 0x69c Process Name: C:\Windows\System32\dfsrs.exe Event Source: Source Name: DFSR Audit Event Source ID: 0x2124ad