I'm no expert
but you have some specific settings of the AV?
because my eset (setup-heuristic) is not blocked the spoofing in my "virtual-net"?
I only have a notice of "any security of my win7 (fully-update") of unknown origin "file-download" (if the "spooffing-redirection" contains a "file" & i press download!)
I made a proof with ettercap only for "ARP" & dnsspoof for"spoofing-dns" & my eset don't BLOCK-redirection.....