"\backs.exe" was your post elsewhere.

Not getting this one nailed down still screams virus/trojan/spy to me.