Windows 10 22H2.
No updates or new application installs in the past week, no shady attachments opened or dastardly popups clicked. Windows Defender enabled.
System has been operating just fine but this afternoon I went and had a shower and when I came back there was a dialog on the screen saying “The server 172.234.198.180 is asking for your username and password.” When I cancelled this and went to google what it meant I got the dialog again. When I visited each tab in the browser I got the dialog again. After cancelling each of these dialogs the tabs’ contents were replaced with a variety of “error 407”, or “you do not appear to be online”, or “access denied”. When I went to Settings > Apps to check if some update or app had just been installed I got a similar dialog, this time saying “To access this service you need to log in to the https proxy server 172.234.198.180:3128”. Even itunes, trying to play a track off the local disk, showed the dialog three times before the track played.
Checking Settings > Network > Proxy I saw that the first option was set to “automatically detect settings”, nothing else was filled in on that page. In fact this is the identical config I have on all my other Windows machines, none of which are showing this problem.
Anyway, I can confirm that turning “automatically detect settings” off and rebooting solved my problem.
I then ran several malware scans: malwarebytes, kaspersky KVRT, ESET online scanner; none of them detected any infections.
I am left with several questions:
What might have triggered an apparently invisible change to the proxy settings?
Where does Windows store the address of the proxy server that it thinks you want to connect through (I searched for the 172.234.198.180 address in the registry and couldn’t find it)?
Might I still be at risk of something acquiring/storing/sending out my credentials? This is the machine I do my banking on, for example.
Is there any benefit at all in having the network proxy settings set to automatic detection? (In the meantime I have turned that setting off on all my other machines as well.)
Thanks for any helpful info you can offer
T