thanks guys.. particularly tip on shutdown -a for when i kill svchost.exe !
Seems I must of done some good as don't see any more outbound connections since i used Comodo Firewall Pro 3 and some tracking cookies (probably not the culprit) and removed 2 dll files guard32.dll and pmxgl32.dll which were being called from registry.
i.e.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmxgl32]
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000000
"DLLName"="pmxgl32.dll"
"Startup"=""
Not sure what it is or whether it's the problem as some of the free anti-spyware tools were also introducing fake or false positive virus detections in order for you to buy their removal programs!
So while I seem to have fixed the symptoms, the indentifcation of the actual worm/trojan is still unknown heh