Does my ISP have a virus?

  OK Computer 13:38 05 Feb 05
Locked

Ok, I had started a thread early and thought Id resolved this but I havent!

Right this is becoming a real pain in the ass. I rebuilt my PC and as soon as I connect to my ADSL connection I get the same problem. Can anyone help!!!!???

within minutes of connecting to my adsl broadband I received some sort of adware software. It pops up a grey window saying:

SITEBAR!

Internet Explorer Add-in

Click here to update your system with a custom sitebar.

I constantly get a debug.txt on my c:\ with what I think is a cmd file called loud and ysbinstall.exe

I have installed two anti virus packages (zone alarm and avg) and neither find anything (although avg started picking up a backdoor virus on iexplore.exe.

  OK Computer 13:38 05 Feb 05

This is some of the debug.txt contents

This is the contents of the debug.txt file that I mentioned, ive searched the internet high and low for an answer and so far Ive come up short (ive taken some of it out so the message isnt to long)

NICK [nese]-40879834
USER bqjomavzh 0 0 :[nese]-40879834
:server4.rightupyours.com NOTICE AUTH :*** Looking up your hostname...
:server4.rightupyours.com NOTICE AUTH :*** Checking ident...
:server4.rightupyours.com NOTICE AUTH :*** Found your hostname
:server4.rightupyours.com NOTICE AUTH :*** Received identd response
:server4.rightupyours.com 001 [nese]-40879834 :Welcome to the rightupyours.com IRC Network [nese]-40879834!~[email protected]
USERHOST [nese]-40879834
MODE [nese]-40879834 -x+B
JOIN #b00l33n b00l
:server4.rightupyours.com 002 [nese]-40879834 :Your host is server4.rightupyours.com, running version Unreal3.2.1
:server4.rightupyours.com 003 [nese]-40879834 :This server was created Sat Nov 13 2004 at 01:50:18 GMT
:server4.rightupyours.com 004 [nese]-40879834 server4.rightupyours.com Unreal3.2.1 iowghraAsORTVSxNCWqBzvdHtGp lvhopsmntikrRcaqOALQbSeKVfMGCuzNT
:server4.rightupyours.com 005 [nese]-40879834 MAP KNOCK SAFELIST HCN MAXCHANNELS=15 MAXBANS=60 NICKLEN=30 TOPICLEN=307 KICKLEN=307 MAXTARGETS=20 AWAYLEN=307 :are supported by this server
USERHOST [nese]-40879834
MODE [nese]-40879834 -x+B
JOIN #b00l33n b00l
:hub.rightupyours.com 005 [nese]-09272654 WALLCHOPS WATCH=128 SILENCE=15 MODES=12 CHANTYPES=# PREFIX=(qaohv)~&@%+ CHANMODES=be,kfL,l,psmntirRcOAQKVGCuzNSMT NETWORK=rightupyours.com CASEMAPPING=ascii EXTBAN=~,cqnr ELIST=MNUCT :are supported by this server
USERHOST [nese]-09272654
MODE [nese]-09272654 -x+B
JOIN #b00l33n b00l
:hub.rightupyours.com 251 [nese]-09272654 :There are 7 users and 4443 invisible on 6 servers
:hub.rightupyours.com 252 [nese]-09272654 8 :operator(s) online
:hub.rightupyours.com 253 [nese]-09272654 25 :unknown connection(s)
:hub.rightupyours.com 254 [nese]-09272654 33 :channels formed
:hub.rightupyours.com 255 [nese]-09272654 :I have 944 clients and 5 servers
:hub.rightupyours.com 265 [nese]-09272654 :Current Local Users: 944 Max: 3699
:hub.rightupyours.com 266 [nese]-09272654 :Current Global Users: 4450 Max: 472
6
:hub.rightupyours.com 422 [nese]-09272654 :MOTD File is missing
:[nese]-09272654 MODE [nese]-09272654 :+iwx
:hub.rightupyours.com 302 [nese]-09272654 :[nese]-09272654=+~[email protected]
222.freedom2surf.net JOIN :#b00l33n
:server1.rightupyours.com 332 [nese]-65298768 #b00l33n :.raw join ##scan,##down,##down3
join ##scan,##down,##down3
:server1.rightupyours.com 333 [nese]-65298768 #b00l33n paragon 1107419058
:server1.rightupyours.com 353 [nese]-65298768 @ #b00l33n :[nese]-65298768
:server1.rightupyours.com 366 [nese]-65298768 #b00l33n :End of /NAMES list.
:server1.rightupyours.com 302 [nese]-65298768 :[nese]-65298768=+~[email protected]
:server1.rightupyours.com 302 [nese]-65298768 :[nese]-65298768=+~[email protected]
:[nese]-65298768!~[email protected] JOIN :##scan
:server1.rightupyours.com 332 [nese]-65298768 ##scan :.advscan dcass 200 5 0 -b -r
PRIVMSG ##scan :[SCAN]: Random Port Scan started on 195.137.x.x:445 with a delay of 5 seconds for 0 minutes using 200 threads.
:server1.rightupyours.com 333 [nese]-65298768 ##scan existence 1106663820
:server1.rightupyours.com 353 [nese]-65298768 @ ##scan :[nese]-65298768
:server1.rightupyours.com 366 [nese]-65298768 ##scan :End of /NAMES list.
:[nese]-65298768!~[email protected] JOIN :##down
:server1.rightupyours.com 332 [nese]-65298768 ##down :.wget
:server1.rightupyours.com 404 [nese]-65298768 ##down3 :You must have a registered nick (+r) to talk on this channel (##down3)
:server1.rightupyours.com 404 [nese]-65298768 ##down :You must have a registered nick (+r) to talk on this channel (##down)
:server1.rightupyours.com 404 [nese]-65298768 ##down :You must have a registered nick (+r) to talk on this channel (##down)
:server1.rightupyours.com 404 [nese]-65298768 ##down3 :You must have a registered nick (+r) to talk on this channel (##down3)
PING :server1.rightupyours.com
PONG :server1.rightupyours.com
PING :server1.rightupyours.com
PONG :server1.rightupyours.com

  VoG II 13:40 05 Feb 05

Ad-aware click here Spybot click here CWShredder click hereclick here

  mattyc_92 13:43 05 Feb 05

Use the programs VoG™ has suggested and this problem shouldn't exist

  OK Computer 13:46 05 Feb 05

Have tried all but a2 but I will give it another go

  VoG II 13:48 05 Feb 05

This isn't a Messenger Service pop-up is it? click here

  mattyc_92 13:51 05 Feb 05

Thats a point VoG™...

OK Computer have you installed SP2??? If you have then this problem isn't to do with the Messenger Service... if you haven't either install SP2 or you can open up "Services" found in "Admistrative Tools" and select "Messenger" and set it to "Disabled" and not to load during startup...

  OK Computer 13:55 05 Feb 05

Not installed SP2 but I'm familar with messenger service and its not that, it runs a command prompt. My Zone Alarms has just this minute discovered this:

Rbot.ADO

as a virus, connected?

  OK Computer 13:57 05 Feb 05

I looked in my registry and I had entries saying Microsoft is Gay!

Something has definately been installed on my PC, ive deleted those entries now.

  Fruit Bat /\0/\ 13:57 05 Feb 05

Its a so called IE Helper Winpatrol will delete it and stop it from being re installed

Download WinPatrol click here - run - click on IE helpers - highlight Sitebar and delete

  Fruit Bat /\0/\ 13:59 05 Feb 05

This thread is now locked and can not be replied to.

What is Amazon Go and will it come to the UK? The store without checkouts or queues

1995-2015: How technology has changed the world in 20 years

Hands-on with the Star Wars fighting drones you can fly yourself

15 macOS Sierra tips | How to use macOS Sierra: Secret tricks and best new features in Apple's new…