WIN 7 x64, NAV 2012
My first question is why is ccsvchst.exe using own DNS UDP port 53 versus using svchost.exe DNS?
Next, I have been experimenting with various WIN 7 third party firewalls and outbound extentions to the WIN 7 firewall. All show dial-outs from ccsvchst.exe using UDP port 53. Given that there is some internal reason NAV requires this, why are the dial-outs to OpenDNS, Cisco, and the like servers? I do not use OpenDNS and have no Cicso hardware.
2012-02-12 16:49:56 DROP UDP 192.168.1.1 208.67.220.220 50061 53 0 - - - - - - - SEND
2012-02-12 16:49:57 DROP UDP 192.168.1.1 208.67.220.220 50061 53 0 - - - - - - - SEND
2012-02-12 16:49:58 DROP UDP 192.168.1.1 208.67.220.220 50061 53 0 - - - - - - - SEND
2012-02-12 16:50:01 DROP UDP 192.168.1.1 208.67.220.220 50061 53 0 - - - - - - - SEND
2012-02-12 16:50:05 DROP UDP 192.168.1.1 208.67.220.220 50061 53 0 - - - - - - - SEND
2012-02-12 16:50:09 DROP UDP 192.168.1.1 64.102.255.44 53515 53 0 - - - - - - - SEND
2012-02-12 16:50:10 DROP UDP 192.168.1.1 64.102.255.44 53515 53 0 - - - - - - - SEND
2012-02-12 16:50:11 DROP UDP 192.168.1.1 64.102.255.44 53515 53 0 - - - - - - - SEND
2012-02-12 16:50:13 DROP UDP 192.168.1.1 64.102.255.44 53515 53 0 - - - - - - - SEND
2012-02-12 16:50:17 DROP UDP 192.168.1.1 64.102.255.44 53515 53 0 - - - - - - - SEND
2012-02-12 16:50:21 DROP UDP 192.168.1.1 208.67.222.222 49434 53 0 - - - - - - - SEND
2012-02-12 16:50:22 DROP UDP 192.168.1.1 208.67.222.222 49434 53 0 - - - - - - - SEND
2012-02-12 16:50:23 DROP UDP 192.168.1.1 208.67.222.222 49434 53 0 - - - - - - - SEND
2012-02-12 16:50:25 DROP UDP 192.168.1.1 208.67.222.222 49434 53 0 - - - - - - - SEND
2012-02-12 16:50:29 DROP UDP 192.168.1.1 208.67.222.222 49434 53 0 - - - - - - - SEND