On occasion I have seen a CMD box flash briefly, and I managed to see it - UsoClient.exe
Anyhow, I just got an alert for this UsoClient.exe a short time ago, which I allowed as per an extract of ReHIPS log, as follows:
18/09/2017 13:38:36 PM: Program C:\Windows\System32\UsoClient.exe with PID 1208 executing program C:\Windows\System32\conhost.exe with PID 3744 - allowed with children inspection (alert)
18/09/2017 13:38:36 PM: Program C:\Windows\System32\conhost.exe with PID 3744 execution - allowed (rule)
18/09/2017 13:38:36 PM: Program C:\Windows\System32\services.exe with PID 1052 executing program C:\Windows\System32\svchost.exe with PID 12416 - allowed (rule)
18/09/2017 13:38:36 PM: Program C:\Windows\System32\UsoClient.exe with PID 1208 terminated
18/09/2017 13:38:37 PM: Program C:\Windows\System32\conhost.exe with PID 3744 terminated
18/09/2017 13:38:37 PM: Program C:\Windows\System32\services.exe with PID 1052 executing program C:\Windows\System32\svchost.exe with PID 10600 - allowed (rule)
18/09/2017 13:38:40 PM: Program C:\Windows\System32\svchost.exe with PID 1260 executing program C:\Windows\System32\dllhost.exe with PID 10888 - allowed with children inspection (rule)
18/09/2017 13:38:40 PM: Program C:\Windows\System32\dllhost.exe with PID 10888 execution - allowed (rule)
18/09/2017 13:38:45 PM: Program C:\Windows\System32\dllhost.exe with PID 10888 terminated
18/09/2017 13:38:51 PM: Program C:\Windows\System32\svchost.exe with PID 1260 executing program C:\Windows\System32\dllhost.exe with PID 1512 - allowed with children inspection (rule)
18/09/2017 13:38:51 PM: Program C:\Windows\System32\dllhost.exe with PID 1512 execution - allowed (rule)
18/09/2017 13:38:56 PM: Program C:\Windows\System32\dllhost.exe with PID 1512 terminated
18/09/2017 13:38:56 PM: Program C:\Windows\System32\svchost.exe with PID 12416 executing program C:\Windows\System32\wermgr.exe with PID 6852 - allowed with children inspection (rule)
18/09/2017 13:38:56 PM: Program C:\Windows\System32\wermgr.exe with PID 6852 execution - allowed (rule)
18/09/2017 13:38:57 PM: Program C:\Windows\System32\wermgr.exe with PID 6852 terminated
18/09/2017 13:39:37 PM: Program C:\Windows\System32\svchost.exe with PID 10600 terminated
18/09/2017 13:39:45 PM: Program C:\Windows\System32\svchost.exe with PID 1064 terminated
I hope that I did the right thing in allowing it, because there was another popup, and it looks like I have created a rule. I don't understand why this is/was necessary, or may be I should have disallowed.