The paths are
C:\Windows\system32\shadow.exe
and C:\Windows\system32\dllcache\shadow.exe
Now upon more diligent googling I found a site
http://www.spywaredb.com/remove-winshadow/It has two options, one a spyware program that will remove it, and a long format as to how to remove it that seems a bit "scary" to say the least.
But its intro also lets you know how scary having shadow on your puter is in the first place and how easily someone can be monitoring you.
snip
WinShadow is one of Commercial RAT spywares.
Finding it on your computer means that your computer is infected with Commercial RAT and crucial data could be endangered or even lost.
WinShadow description by publisher:
Vendor: ´allows one or more client computers to connect to a host computer, creating a remote control session over the Internet or private WAN/LAN network. The client session is a window displaying the desktop of the host, & via it, the client can access any file & run programs on the host computer. The winShadow Server Manager runs as an icon in the System Tray. Using the winShadow Server Manager, you can: º ´Quick Connect´ to a host. º Run winShadow Neighborhood. º Invite a remote computer to become a client for this computer (useful if this computer is behind a firewall). º Stop & start the winShadow Server. º Configure the host properties for this computer.´
>> Delete WinShadow automatically - Download SpySweeper
snip
So I decided that before I do anything else I would try to locate it in system configuration, wherein SERVICES I find two shadow services being run. . . so I unclicked those two and I am debating on whether to try the long hand self delete contained at the above link or the SpySweeper free download.