Sorry, I forgot to mention this. It is very normal for svchost.exe to run as a process in windows, but if it is in higher case, ie: SVCHOST.EXE then you have a problem. Some other viruses replace the 't' with a '1' to disguise themselves as svchost.exe.
In XP press 'ctrl+alt+delete' and check under processes for the above.
In XP press 'ctrl+alt+delete' and check under processes for the above.