Quote:
Like i said, the easiest way to tell if the svchost processes are legit is to try ending them. Windows won't let u end the proper ones, but the blaster ones that I've seen throw a wobbly and reboot your pc.
All the SVCHost's can be ended,
There are a couple of windows services that run under SVCHost that if you stop that particular SVCHost it will put the system on a 60 sec countdown and force the PC to restart, this is not the work of a virus, it is how those services are set, but if MSBlaster is on the system that causes these particular services to crash again causing the 60 sec countdown and restart,
I used to work at one of the UK's top ISP's at the time that MSBlaster was at it's worst, we had to talk the users through how to stop the MSBlaster virus crashing the service and restarting the PC, so that could download the fixes for it.