Just today I noticed that my computer kept repetitively running and terminating - almost cyclically - a dllhost process.
Doing some digging with Process Explorer from Sysinternals, I noticed it was part of the Dcomlaunch svchost process. Tracing the GUID the /ProcessId flag sends to DLLhost, it seems linked to the WinInetBrokerServer DCOM Component Service, which I can't find anything specific on, but is apparently part of Windows.
While this process is doing its thing, I notice there's a steady, small burst of outbound traffic (not too large, usually around 90-200 detected by COMODO firewall every few seconds. Suspending the process in Process Explorer before it self-terminates and respawns stops this traffic.
I don't know what to make of it. Neither MalwareBytes nor MSE pick up anything being updated to their latest definitions, nothing seems out of place in a HiJackThis log, Spybot 2 doesn't see anything out of the ordinary, and I only received one alert from COMODO which may have just been a misclick on my part. It doesn't seem malicious (it's not impacted any performance on my computer), but it just makes me jittery. I did just recently do a Windows Update, so was that perhaps a change in how Windows does things?