Hi, I'm hoping Marat Setdikov and/or another board member can help me out... I got ATI 11 with the sole intent of using it to back-up my hard drive in its entirety (I've installed XP but would need to put Vista back on if I had to send it in for repairs, and this would allow me to then put an exact copy of my XP system back on the laptop once returned). Not realizing that you can do this procedure from the bootable cd that the program is on, I installed the program. Then I realized that it started all these services, etc. that I didn't want on my computer. So I followed the manual removal instructions posted here: http://www.wilderssecurity.com/showpost.php?p=1120006&postcount=4 ...as I had read that used add/remove programs or other methods did not do a complete uninstall. I followed the instructions exactly (though please note that not all the files listed for the registry were there). Uninstall seemed to be successful. However, this morning I was looking through the Security logs and saw this entry: Event Type: Success Audit Event Source: Security Event Category: System Event Event ID: 514 Date: 12/28/2007 Time: 10:52:31 AM User: NT AUTHORITY\SYSTEM Computer: COMPUTRESS Description: An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\relog_ap.dll : ACRONIS_RELOGON_AUTHENTICATION_PACKAGE For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. I found the relog_ap.dll file in system32 and right-clicked on it and it is indeed an Acronis file. Why is this on my computer? Should it have been removed in the manual uninstall? (This file was not listed in the instructions.) Should I just leave it alone? (It doesn't seem to be causing any problems that I know of...) Any help is appreciated -- thanks!