Well nothing unusual there either.
Strange that they stopped as that would only normally happen after some form of cleaning.
This is the whois of the IP address (see image, click to expand) and it doesn’t seen your usual malicious site, does this ISPrime ring any bells to you (but still strange for this connection by rundll32.dll) ?
I will try and get someone to take a look at the OTS log.