i probably think this subject is not a trojan because it come from mircosoft. 5 h/ {2 r8 v7 t$ }: w e6 [公仔箱論壇but trojan will always follow this svchost file into your system32 through inbound connection.finally,i use firewall to block this activities(svchost).