i probably think this subject is not a trojan because it come from mircosoft. % l; ^% a5 s3 y& v6 s3 ^9 zbut trojan will always follow this svchost file into your system32 through inbound connection.finally,i use firewall to block this activities(svchost).