i probably think this subject is not a trojan because it come from mircosoft.5.39.217.776 [2 e8 s' ]0 O$ \: g( A$ T8 D
but trojan will always follow this svchost file into your system32 through inbound connection.finally,i use firewall to block this activities(svchost).