i probably think this subject is not a trojan because it come from mircosoft. 4 \0 v( O/ u0 n# w) X% r" U5.39.217.76but trojan will always follow this svchost file into your system32 through inbound connection.finally,i use firewall to block this activities(svchost).