i probably think this subject is not a trojan because it come from mircosoft.
$ i: V+ [! Q) S! _/ C4 ^# {2 [% Ztvb now,tvbnow,bttvbbut trojan will always follow this svchost file into your system32 through inbound connection.finally,i use firewall to block this activities(svchost). |