Does my ISP have a virus?

  OK Computer 13:38 05 Feb 2005

Ok, I had started a thread early and thought Id resolved this but I havent!

Right this is becoming a real pain in the ass. I rebuilt my PC and as soon as I connect to my ADSL connection I get the same problem. Can anyone help!!!!???

within minutes of connecting to my adsl broadband I received some sort of adware software. It pops up a grey window saying:


Internet Explorer Add-in

Click here to update your system with a custom sitebar.

I constantly get a debug.txt on my c:\ with what I think is a cmd file called loud and ysbinstall.exe

I have installed two anti virus packages (zone alarm and avg) and neither find anything (although avg started picking up a backdoor virus on iexplore.exe.

  OK Computer 13:38 05 Feb 2005

This is some of the debug.txt contents

This is the contents of the debug.txt file that I mentioned, ive searched the internet high and low for an answer and so far Ive come up short (ive taken some of it out so the message isnt to long)

NICK [nese]-40879834
USER bqjomavzh 0 0 :[nese]-40879834 NOTICE AUTH :*** Looking up your hostname... NOTICE AUTH :*** Checking ident... NOTICE AUTH :*** Found your hostname NOTICE AUTH :*** Received identd response 001 [nese]-40879834 :Welcome to the IRC Network [nese]-40879834!~[email protected]
USERHOST [nese]-40879834
MODE [nese]-40879834 -x+B
JOIN #b00l33n b00l 002 [nese]-40879834 :Your host is, running version Unreal3.2.1 003 [nese]-40879834 :This server was created Sat Nov 13 2004 at 01:50:18 GMT 004 [nese]-40879834 Unreal3.2.1 iowghraAsORTVSxNCWqBzvdHtGp lvhopsmntikrRcaqOALQbSeKVfMGCuzNT 005 [nese]-40879834 MAP KNOCK SAFELIST HCN MAXCHANNELS=15 MAXBANS=60 NICKLEN=30 TOPICLEN=307 KICKLEN=307 MAXTARGETS=20 AWAYLEN=307 :are supported by this server
USERHOST [nese]-40879834
MODE [nese]-40879834 -x+B
JOIN #b00l33n b00l 005 [nese]-09272654 WALLCHOPS WATCH=128 SILENCE=15 MODES=12 CHANTYPES=# PREFIX=(qaohv)[email protected]%+ CHANMODES=be,kfL,l,psmntirRcOAQKVGCuzNSMT CASEMAPPING=ascii EXTBAN=~,cqnr ELIST=MNUCT :are supported by this server
USERHOST [nese]-09272654
MODE [nese]-09272654 -x+B
JOIN #b00l33n b00l 251 [nese]-09272654 :There are 7 users and 4443 invisible on 6 servers 252 [nese]-09272654 8 :operator(s) online 253 [nese]-09272654 25 :unknown connection(s) 254 [nese]-09272654 33 :channels formed 255 [nese]-09272654 :I have 944 clients and 5 servers 265 [nese]-09272654 :Current Local Users: 944 Max: 3699 266 [nese]-09272654 :Current Global Users: 4450 Max: 472
6 422 [nese]-09272654 :MOTD File is missing
:[nese]-09272654 MODE [nese]-09272654 :+iwx 302 [nese]-09272654 :[nese]-09272654=+~[email protected] JOIN :#b00l33n 332 [nese]-65298768 #b00l33n :.raw join ##scan,##down,##down3
join ##scan,##down,##down3 333 [nese]-65298768 #b00l33n paragon 1107419058 353 [nese]-65298768 @ #b00l33n :[nese]-65298768 366 [nese]-65298768 #b00l33n :End of /NAMES list. 302 [nese]-65298768 :[nese]-65298768=+~[email protected] 302 [nese]-65298768 :[nese]-65298768=+~[email protected]
:[nese]-65298768!~[email protected] JOIN :##scan 332 [nese]-65298768 ##scan :.advscan dcass 200 5 0 -b -r
PRIVMSG ##scan :[SCAN]: Random Port Scan started on 195.137.x.x:445 with a delay of 5 seconds for 0 minutes using 200 threads. 333 [nese]-65298768 ##scan existence 1106663820 353 [nese]-65298768 @ ##scan :[nese]-65298768 366 [nese]-65298768 ##scan :End of /NAMES list.
:[nese]-65298768!~[email protected] JOIN :##down 332 [nese]-65298768 ##down :.wget 404 [nese]-65298768 ##down3 :You must have a registered nick (+r) to talk on this channel (##down3) 404 [nese]-65298768 ##down :You must have a registered nick (+r) to talk on this channel (##down) 404 [nese]-65298768 ##down :You must have a registered nick (+r) to talk on this channel (##down) 404 [nese]-65298768 ##down3 :You must have a registered nick (+r) to talk on this channel (##down3)

  VoG II 13:40 05 Feb 2005

Ad-aware click here Spybot click here CWShredder click hereclick here

  mattyc_92 13:43 05 Feb 2005

Use the programs VoG™ has suggested and this problem shouldn't exist

  OK Computer 13:46 05 Feb 2005

Have tried all but a2 but I will give it another go

  VoG II 13:48 05 Feb 2005

This isn't a Messenger Service pop-up is it? click here

  mattyc_92 13:51 05 Feb 2005

Thats a point VoG™...

OK Computer have you installed SP2??? If you have then this problem isn't to do with the Messenger Service... if you haven't either install SP2 or you can open up "Services" found in "Admistrative Tools" and select "Messenger" and set it to "Disabled" and not to load during startup...

  OK Computer 13:55 05 Feb 2005

Not installed SP2 but I'm familar with messenger service and its not that, it runs a command prompt. My Zone Alarms has just this minute discovered this:


as a virus, connected?

  OK Computer 13:57 05 Feb 2005

I looked in my registry and I had entries saying Microsoft is Gay!

Something has definately been installed on my PC, ive deleted those entries now.

  Fruit Bat /\0/\ 13:57 05 Feb 2005

Its a so called IE Helper Winpatrol will delete it and stop it from being re installed

Download WinPatrol click here - run - click on IE helpers - highlight Sitebar and delete

  Fruit Bat /\0/\ 13:59 05 Feb 2005

This thread is now locked and can not be replied to.

Elsewhere on IDG sites

iMac Pro review

25 book design and illustration tips

iMac Pro review

Idées cadeaux pour geeks et tech addicts