I will run the event logs. I (strongly) doubt that it is some malware, but it could be an IDS (we're pretty locked down

Wireshark and proxy not playing well together? Here at work we use a proxy system. Works OK. I light up Wireshark, and