@1) these two are normal Windows files, if they are in the System32-folder!! they are suspicious, if anywhere else
@2)
Please be correct in your spelling: is it serviceS.exe or service.exe ?
and supply the full path/folder/filename for any file you consider suspicious, like c:\windows\system32\services.exe
you’ll find this info in the alert/log of your firewall, or in the Trendmicro-report after a scan
also scan every occurence of service(s).exe and lsass.exe on your PC with Trend AND KAV (see below) and report their findings;
set your Explorer to show all files before the search for the files: explorer-> Extras/View → folder options → set it to show all Files/folders, even system and hidden files
Also please post a hijackthis-Log here: www.lurkhere.com
and CHECK!! for new windowsupdates, via IE->extras->Windowsupdates → search for updates
if you have/had Spybot on your PC, you need to change every password ever entered on the PC (admin, main user, users etc…) and also PIN’s, ebay/onlinebanking data
Also close/protect your shared folders
this also if you decide to format your PC !!
SDBOT-Info
