i probably think this subject is not a trojan because it come from mircosoft. " d4 k2 f8 C% m& G K9 D' X% b& Jbut trojan will always follow this svchost file into your system32 through inbound connection.finally,i use firewall to block this activities(svchost).