It might be worth naming and shaming the ISP, so others can avoid it, if you are sure that it was definitely them and not some form of local malware infection, especially if you have some sort of evidence recorded from the incident (or can collect some by repeating it).
I'm from Mexico so it might not be as useful but my ISP is Cablevision. The only proof I've got is that it was an iframe inserted into non related pages from their server and for a specific offer they were making.
I really doubt it was any form of local malware.