Svchost is essential a process that can be used to run multiple services. You can find out the current arrangement for all svchost processes by viewing the registry key HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Svchost
You can also, as you note, use the task list /svc command. This command provides the PID. (You can also find the PID if you add the PID column (from the View menu) to the task manager applet)
(For Windows 2000 the command is tlist /s, the tlist tool is available from the Windows installation CD-ROM support folder.)
More information on the processes within svchost can be found by setting process tracking auditing in the auditing section of group policy. Be aware, however, that many events may be generated. It typically is not a good idea to enable this type of auditing unless you are seeking specific information.
Dig Deeper on Network intrusion detection and prevention and malware removal
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.