Internet & modems

DNS settings changed unexpectedly (possible malware)

If your device or router's DNS settings were changed to unfamiliar addresses without your knowledge, it can be a sign of malware or a compromised router, redirecting your browsing to unintended servers, and should be corrected and followed by a security check.

Difficulty
Moderate
Time
30–60 minutes
DIY cost
$0
Pro cost
$0–$150

Symptoms

  • Browser redirects to unexpected websites or ads frequently
  • DNS server addresses in network settings show unfamiliar numbers you didn't enter
  • Router's DNS setting was changed and you don't recall doing it
  • Security software flags a DNS hijack or suspicious redirect

Likely causes

  • CommonMalware on a computer or phone that modified DNS settingsSome malware changes DNS settings specifically to redirect traffic through malicious servers for ads or phishing.
  • CommonRouter compromised through a weak or default admin passwordAttackers can access poorly secured routers over the internet and change DNS settings to affect every device on the network.
  • PossibleA legitimate app or browser extension that changed DNS settings without clear disclosureSome ad-blocking or 'security' tools alter DNS settings as part of their normal function, which can be mistaken for malicious activity.

What to do

  1. On the affected device, go to network settings and change DNS back to 'automatic' or to a known public DNS like 8.8.8.8, removing any unfamiliar entries.
  2. Log into the router's admin page and check its DNS settings under WAN or internet settings, reverting any unrecognized custom DNS entries back to automatic or a trusted public DNS.
  3. Change the router's admin password immediately to a strong, unique one, since a compromised router is often due to a weak or default password.
  4. Run a full malware/antivirus scan on the affected computer or phone using reputable security software.
  5. Check for and remove any recently installed, unfamiliar browser extensions or apps around the time the issue started.
  6. Update the router's firmware to the latest version, since attackers sometimes exploit known vulnerabilities in outdated firmware.
  7. After cleaning up, monitor for a few days to confirm the DNS settings stay correct and browsing behaves normally; if it recurs, consider a full factory reset of the router with a fresh, strong password.

Tools and parts

  • Antivirus/security software

When to call a pro

If malware or a router compromise is confirmed and you're not comfortable fully remediating it yourself, a computer security professional can do a thorough cleanup and help secure your network.

Safety

Generally low risk

Generally low risk for a careful person. Stop if anything looks different from what this guide describes.

Related guides

Operator provides AI-generated troubleshooting information. It can be wrong. For safety-critical, electrical, gas, structural, medical, automotive safety, or other high-risk problems, consult a qualified professional.