SVCHOST = GOOD
SCVHOST = BAD..
I hope this gets around.
scvhost is tricky, to say the least. I'm quite familiar with the registry and if you are too, you'll notice shell, load, run.. all missing.
or are they?
They aren't, the scvhost.exe actually HIDES the keys in the registry editor. open up regedit (search about online to re-enable it) and search for svchost.exe - it'll popup all over, but you can't ever see it. It says its there, but its not.
Export that key and look at it. You'll see, sure enough, it is there . What you have to do is boot into safe mode, and remove all instances of scvhost.exe.
Good luck.
Jonathan R, February 2007