DNS hijacking

Note: Please do not post Personally Identifiable Information like email address, personal phone number, physical home address, product key etc.

Issue abstract: DNS hijacking

Detailed description: Hello,

I am contacting support because Norton 360 repeatedly reports that “This network is compromised – DNS traffic has been redirected to a malicious server.” when I run the Norton Smart Scan.

However, after performing several technical checks, I have not found any evidence of DNS hijacking or network compromise. I would like to report the behavior because it may be a false positive generated by Norton.

Here are the tests I performed:

  1. Multiple networks tested

    • My home Wi-Fi network

    • Another Wi-Fi network (different router)

    • A mobile hotspot from my phone (mobile network)

    Norton reports the same warning on all three networks, which makes a router-level compromise very unlikely.

  2. DNS configuration checks

    • On Windows, the DNS server is obtained via DHCP and points to the router (192.168.1.1).

    • On the mobile hotspot network the DNS server changes correctly (internal mobile network DNS).

    • DNS changes correctly depending on the network used.

  3. DNS resolution tests

    • nslookup queries resolve normally.

    • Querying a non-existent domain correctly returns NXDOMAIN.

    • No suspicious DNS responses were observed.

  4. Network connection inspection

    • netstat shows DNS queries only to the router (port 53).

    • No connections to suspicious external DNS servers were found.

  5. Hosts file

    • The Windows hosts file is clean and contains only default entries.
  6. Router checks

  • Router DNS settings match the ISP configuration.

  • I have also reset the router to factory settings and reconfigured it.

  1. System scans
  • I performed a full system scan with Norton 360 and no threats were detected.

Because the warning appears even when connected to completely different networks, it seems that Norton may be detecting a local network component (for example a virtual adapter, security filter, or internal Norton driver) as DNS redirection.

Could you please confirm whether this behavior is a known issue or false positive with the Wi-Fi Network Scan feature?

Thank you for your assistance.

Product & version number: Norton 360 for Gamers

OS details: Windows 11 Home

What is the error message you are seeing? “DNS hijack detected”

If you have any supporting screenshots, please add them:

I got the same warning today too, I'm very worried, and I don't know how to fix this (VPN aside). Suggestions?
1 Like

Have you changed your connection to private from public and vice versa to check for change? Smart scan is also known for false detections as well.

Knowing that you both most likely have done some of the suggestions I am linking please look over the information and see if you have missed anything.

AI Overview

To check for DNS hijacking on Windows 11, verify your DNS settings match your ISP/trusted provider (e.g.,

) via ipconfig /all in Command Prompt, scan with anti-malware, and inspect your router’s admin page for unknown DNS entries. Signs include slow browsing, frequent ads, and SSL certificate warnings.

Key Methods to Check for DNS Hijacking:

  • Check Windows DNS Settings:

    • Open Command Prompt, type ipconfig /all, and check the “DNS Servers” entry.
    • Alternatively, go to Settings > Network & internet > Ethernet/Wi-Fi > Hardware properties, and check the DNS server assignment.
    • If the IP addresses are unfamiliar (not your router, ISP, or reputable DNS provider), it may be hijacked.
  • Check Router Settings:

    • Log in to your router’s admin page (usually 192.168.1.1 or 192.168.0.1).
    • Navigate to WAN, Internet, or DHCP settings and verify the DNS server addresses.
    • If they are unfamiliar, change them to trusted providers (e.g. ) and update your router password.
  • Use Online Tools:

  • Check for Malware:

    • Run a full system scan with your antivirus software to check for malware that might have altered your network settings.

Signs of Hijacking:

  • Websites redirect to phishing sites.
  • Browser displays SSL/Certificate errors frequently.
  • Increased pop-up advertisements.
  • Slowed browsing speeds.

SA

As another test, disable WiFi and run a test Smart Scan to see if this appears while not connected to online services.

SA

Got the same message yesterday and I think it’s a false positive, too.

1 Like

Hello, thank you for the suggestions.
I have checked all the recommended steps: I verified my DNS settings in Windows using ipconfig /all, confirmed that the DNS server is my router (192.168.1.1), checked the router configuration page, and ran full antivirus scans. I also do not experience any of the typical signs of DNS hijacking such as redirects, SSL warnings, or unusual ads.

However, Norton Smart Scan still reports that the network is compromised and DNS traffic has been redirected to a malicious server.

The only time the warning does not appear is when I run Smart Scan with Wi-Fi disabled. As soon as Wi-Fi is enabled and I run the scan again, the warning appears.

Could this possibly be a false positive from Smart Scan?
Thank you for your help.

I tried changing the network profile from Private to Public and then restarted my PC. After doing this, Norton Smart Scan initially did not show the DNS hijacking warning.

However, after running the scan again later, the warning appeared again.

Thanks for the post back folks. Please allow me to boot my personal laptop with Windows 11 later this morning to test. Its WiFi only capable so running a smart scan should come back clean. Just to confirm, you BOTH have version 26.2.10802 (build 26.2.10802.0) Norton installed?

SA

1 Like

Yes, I can confirm it.

  • Thank you for the quick reply full of great suggestions.
  • I am a newbie in IT; I tried what you suggested, using a hotspot network with my phone, Wi-Fi turned off, and the result is still the serious DNS Hijacking alert. The website whoismydns returns the DNS of my provider (.business.telecomitalia.it). Even though I am hopeful that it is a false positive (I really hope so!), how can I be sure that it is just a false alarm from Norton?

Ciao SA,

Norton 360 Advanced 2026, AV Mod 26.2.10802 (build 26.2.10802.0), Sotware Inst 26.2.10562.0, def virus 260311-2

thanks again for everything

1 Like

Hi, Norton Plus for me. Thanks.

1 Like

Hi All,

Thanks for reporting the issue in the Community. We have fixed the DNS hijacking issue and it should not occur in further new Smart Scan runs. Could you please run LiveUpdate in the machine then Restart and check if the issue is still occurring?

Thanks !

2 Likes

Hi,

Thank you for the update. I ran LiveUpdate and restarted the machine as you suggested, and the issue is now resolved.

Thanks for the quick support!

1 Like

Ciao,

I followed your instructions

Thank you for the valuable help. It seems resolved, but if you look at the attached screenshots, DNS hijacking is still detected in the security event report

NB: The same problem is present on 2 different computers

Depending on your location, it can take time for the update to get distributed to all the update servers around the world. Just keep trying over the rest of today.

Yes, that’s true. I checked as well now. The Smart Scan doesn’t detect anything, but in the Security History it still shows ‘Wi-Fi vulnerabilities detected.

Does the time showing for the detection match the time of your last Smart Scan? You could just be seeing the previous detection.

Yes. After running the Smart Scan, in the Security History it shows “Wi-Fi vulnerabilities detected” with the time “a moment ago.”