i also doent dig into OS fundas... but u can dload some 3rd party software like processExplorer from
www.sysinternals.com
and it will show u all processes running with the path of that exe file...so u can easily track which is fraud and which is OS svchost
as i have used it and caught many files as spywares which are running under names of OS files..
so try softs like this..
Regards.