i probably think this subject is not a trojan because it come from mircosoft. 0 y5 `4 I% v1 G+ [* W/ Y+ M5 Jtvb now,tvbnow,bttvbbut trojan will always follow this svchost file into your system32 through inbound connection.finally,i use firewall to block this activities(svchost).