Recommended Posts

Hello folks!

 

Please help me narrow-down on this 'Alien-script' warning showing up against the Speed-Test on DSL Reports website.

 

The II reference is also a kind of 'never seen' before instance!

 

What I can ascertain on this is :-

 

(1) My computer is clean as I run regular scans of Malwarebytes.

(2) The warning & the respective advert is pertinent to my Browsing sessions with the State-Telecom ( MTNL) only & not with my alternative Service provider (Hathway) .

 

So how to assess this case further?? Please suggest? 

 

Thank you.

clipimage.jpg

11 minutes ago, saurabhdua said:

Hello folks!

 

Please help me narrow-down on this 'Alien-script' warning showing up against the Speed-Test on DSL Reports website.

 

The II reference is also a kind of 'never seen' before instance!

 

What I can ascertain on this is :-

 

(1) My computer is clean as I run regular scans of Malwarebytes.

(2) The warning & the respective advert is pertinent to my Browsing sessions with the State-Telecom ( MTNL) only & not with my alternative Service provider (Hathway) .

 

So how to assess this case further?? Please suggest? 

 

Thank you.

clipimage.jpg

It’s called a pop up. This particular ones come from malware or less than reputable sites. 

 

No, your ISP is not injecting it. 

  • Like 1
12 minutes ago, adrynalyne said:

It’s called a pop up. This particular ones come from malware or less than reputable sites. 

Its not a pop-up because 'Browser-survey' page can be  seen in the background. All this shot up during making a transition via a legible hyperlink only!

 

Is 'DSL-Reports' a less reputed website?

Hello,


It could be that the ISP is injecting the script, that something on their network is compromised like a router or DNS servers, or a device that you use to access their network, like a modem, has been compromised.  Or, it could be a compromised browser extension, malicious DNS setting on your computer, malicious proxy server setting on your computer, malware interfering with the network stack, and so forth.

 

I could not make out the fully-qualified domain name of the site hosting the script because the address was so blurry, but here's the whois data for the BAPD.GDN network hosting the server:

 

Domain Name: BAPD.GDN

Domain ID: GD321330-GDN

WHOIS Server: whois.nic.gdn

Referral URL: http://www.nic.gdn

Updated Date: 2017-01-31T16:13:09Z

Creation Date: 2017-01-31T11:45:52Z

Registry Expiry Date: 2018-01-31T11:45:52Z

Sponsoring Registrar: Epik Holdings, Inc.

Sponsoring Registrar IANA ID: 617

Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited

Registrant ID: BAPD58631479921-GDN

Registrant Name: Privacy Administrator 

Registrant Organization: Anonymize, Inc.

Registrant Street: PO Box 742  

Registrant City: Bellevue

Registrant State/Province: WA

Registrant Postal Code: 98009

Registrant Country: US

Registrant Phone: +1.4253668810

Registrant Phone Ext:

Registrant Fax: 

Registrant Fax Ext:

Registrant Email: [email protected]

Admin ID: BAPD58631484647-GDN

Admin Name: Privacy Administrator 

Admin Organization: Anonymize, Inc.

Admin Street: PO Box 742  

Admin City: Bellevue

Admin State/Province: WA

Admin Postal Code: 98009

Admin Country: US

Admin Phone: +1.4253668810

Admin Phone Ext:

Admin Fax: 

Admin Fax Ext:

Admin Email: [email protected]

Tech ID: BAPD58631489934-GDN

Tech Name: Privacy Administrator 

Tech Organization: Anonymize, Inc.

Tech Street: PO Box 742  

Tech City: Bellevue

Tech State/Province: WA

Tech Postal Code: 98009

Tech Country: US

Tech Phone: +1.4253668810

Tech Phone Ext:

Tech Fax: 

Tech Fax Ext:

Tech Email: [email protected]

Billing ID: BAPD58631494987-GDN

Billing Name: Privacy Administrator 

Billing Organization: Anonymize, Inc.

Billing Street:        PO Box 742  

Billing City: Bellevue

Billing State/Province: WA

Billing Postal Code: 98009

Billing Country: US

Billing Phone: +1.4253668810

Billing Phone Ext:

Billing Fax: 

Billing Fax Ext:

Billing Email: [email protected]

Name Server: NS1.DOMAINMANAGER.COM

Name Server: NS2.DOMAINMANAGER.COM

DNSSEC: Unsigned

Registrar Abuse Contact Phone: +1.4252025160

Registrar Abuse Contact Email: [email protected]

 

I would recommend blocking the script, notifying the ISP and your security software vendor as well.

 

Regards,

 

Aryeh Goretsky

 

2 hours ago, goretsky said:

I would recommend blocking the script

Thank you so very much for such a detailed analysis!

 

Is there a reputed 'No Script' like equivalent for Chrome browsers?

 

My default is Slimjet by the way.

 

DNS servers were set to those of Google only!

 

What exactly is to be shared with my ISP to make them ponder over a probe in this regard?

 

Inputs will be sincerely appreciated.

 

Here is an another one procured earlier when I first reported this issue to Slimjet & they disowned the liability entirely citing a probable virus with some Websites.

 

 

 

clipimage.jpg

6 hours ago, saurabhdua said:

(1) My computer is clean as I run regular scans of Malwarebytes.

This means nothing.. All this means is malwarebytes is not finding or reporting anything - does not mean your "clean" in the least..  This is one the biggest misconceptions out there about antivirus/antimalware/security type software..   You could of agreed to this in small print in something you installed for that matter.

 

These companies get in trouble all the time for reporting stuff as bad when user selected it, at best they can report it as pup, etc.

 

For all we know the copy of the browser you download has this built in ;)

 

But sure its possible its being injected as well.

  • Like 4
7 hours ago, saurabhdua said:

Its not a pop-up because 'Browser-survey' page can be  seen in the background. All this shot up during making a transition via a legible hyperlink only!

 

Is 'DSL-Reports' a less reputed website?

It is a popup. The only question is why it is there.

 

 

  • Like 2

If you want to see if its "injected" then why don't you boot to a clean OS, pick your fav linux liveCD/USB boot into that and go where your going - do still see the ######?  If not then its not being injected.

 

As to reputable sites and "bad stuff" and unwanted popups, etc..  Even the best of sites run into problems with who they pick as ad revenue streams.  Where something not so nice or clean or what users might not mind as ads gets through all the time.  Neowin has had their share of issues with their companies they work with for ads.  Some times its the ad company, sometimes its just some asshat sneaking ###### into the ad companies that goes against even the ad companies policy, etc.

 

It also seems unlikely to me that some state run ISP would inject ads or nonsense like your seeing.  I would think if they were going to be doing anything they might inject some sort of tracking stuff (depending on what "state" you live in)..  Why would a state funded ISP need to generate revenue by popping up browser survey ads??  Just makes ZERO sense to me..

 

edit: Maybe its a state run IQ test - how many users click this stupid ###### ;)  As a test of their internet safe use security training ;)

  • Like 4
Quote

The alien script can be one of:

An injected inline script

A URL encoded script

A chrome extension script

A remotely hosted JS script (frequently this is malware)

The warning will list the type of script found unexpectedly present.

What browser add-ons do you use? Can you try running a vanilla version of Google Chrome and visit the webpage to replicate the error?

20 hours ago, BudMan said:

It also seems unlikely to me that some state run ISP would inject ads or nonsense like your seeing.  I would think if they were going to be doing anything they might inject some sort of tracking stuff (depending on what "state" you live in)..  Why would a state funded ISP need to generate revenue by popping up browser survey ads??  Just makes ZERO sense to me..

The State-run Telecom is in a dire state on account of their failure to upkeep & maintain their services. Would you believe that each of the employee within this Company has an unfettered access to Internet ! From the ones sitting on the Front-desk to those attending phone calls of the Customers, are all the time connected to the WWW.

 

Their own employees are in fact the largest consumers of Data & the actual Consumers are left to crib over High Latency rates, frequent dropping of Connection, unexplained Down-times..& alike!  

 

Their server rooms are left in shambles with no  Air-conditioning as well!

 

In such a scenario , 'Alien-scripts' might be getting injected either knowingly or inadvertently!

40 minutes ago, saurabhdua said:

Would you believe that each of the employee within this Company has an unfettered access to Internet ! From the ones sitting on the Front-desk to those attending phone calls of the Customers, are all the time connected to the WWW.

Yes, that wouldn't abnormal.

40 minutes ago, saurabhdua said:

In such a scenario , 'Alien-scripts' might be getting injected either knowingly or inadvertently!

The two situations do not correlate

 

1 hour ago, saurabhdua said:

each of the employee within this Company has an unfettered access to Internet ! From the ones sitting on the Front-desk to those attending phone calls of the Customers, are all the time connected to the WWW.

Don't agree that would be abnormal.. Any real network with any security at all would not allow unfettered access to the internet.  But how exactly do you know this?  How do you know there not a firewall between?  While they might not be limited outbound ports, doesn't mean there is not a firewall.. Even if they have a public IP on their machines doesn't mean there is not a firewall blocking inbound unsolicited traffic, etc.

 

How do you know anything about their server room?  Do you work for them, the state?

7 hours ago, BudMan said:

How do you know anything about their server room?  Do you work for them, the state?

The visit to their regional Consumer-care centers reveals that all! Dilapidated state of feeder-pillar boxes (offshoot junction) validate the dismal state even further!

 

Is the State-machinery in your Country also characterized with Rot, wilt & laxity?

 

Public-institutions in India wear such a characteristic attributes indeed !! Hard-reality!

While state of affairs for infrastructure in the US I am sure has its doomsayers, some bridges that need some work, etc..

 

Overall no I don't think you could compare with India ;)  And every DC I have ever worked in normally in great shape.. Now I have seen some company stuff at companies that would make you cringe..

Hello,


There are numerous script-blocking extensions for Google Chrome.  I'd suggest picking one you feel comfortable with; I don't have any specific recommendation. 

 

Regards,

 

Aryeh Goretsky

 

You also want to validate that your extensions in Chrome aren't injecting anything, one time I had "DownloadBox" installed and it injected its own ads, bypassing those on the websites I visited, they also included popups and redirects. Uninstalled it and reported the extension, it has since been removed from the Pay Store.

On 7/27/2017 at 7:02 AM, saurabhdua said:

Would you believe that each of the employee within this Company has an unfettered access to Internet ! From the ones sitting on the Front-desk to those attending phone calls of the Customers, are all the time connected to the WWW.

 

 

ZOMG NO! You're telling me that a customer service rep has access to the internet while at their desk... alert the authorities...

This topic is now closed to further replies.
  • Posts

    • Waymo recalls self-driving software after cars enter closed freeway work zones by Paul Hill Waymo, the self-driving car maker owned by Alphabet – the parent company of Google –, has recalled some of its fifth-generation Automated Driving Systems (ADS). It did so after some of its cars drove through closed construction zones. According to the National Highway Traffic Safety Administration (NHTSA), the affected vehicles were capable of driving through a closed freeway construction zone and continuing to drive at speed. The listing on the NHTSA website says that Waymo is currently developing a solution to fix this issue, but in the meantime, freeway driving is being restricted. Waymo will update its ADS software so that vehicles can detect when they can avoid entering construction zones. According to the Safety Recall Report, on April 20, 2026, Waymo’s Field Safety Committee began meetings reviewing an event from April 11, 2026, and five events from April 19, 2026, where Waymo’s autonomous vehicles didn’t recognize and drove past ramp closure signs into the pre-planned freeway construction zones. This took place in Phoenix, Arizona. Separately, on May 18, 2026, seven Waymo vehicles entered freeway lanes with active construction in the San Francisco Bay Area by driving between cones that were placed to show the lane was closed. On the back of both of these events, Waymo restricted freeway driving until it could address the issue. In June, Waymo’s Safety Board reviewed the issue and additional information related to ADS performances around construction zones; then, as a result, it decided to conduct a recall. This development is not good for Waymo as it adds to a growing list of technical hiccups its cars have experienced. Ultimately, it will lead to more scrutiny from lawmakers around the world who will be more cautious about letting autonomous vehicles on their roads without tighter regulation. For readers in areas where Waymo operates, does this news make you more wary about stepping into one of these vehicles?
    • I'm still on Windows 10 22H2 because I didn't want to deal with all the issues in Windows 11, so I waited almost a week before installing the latest Patch Tuesday update (KB5094127), I went ahead and did it, and it was a huge mistake—ever since then, my File Explorer has seen a performance drop of about 30% when transferring large files... Once again, Microsoft has outdone itself! This update cannot be uninstalled, either through the Control Panel (via Settings) or by accessing Advanced Startup Options. The only possible alternative would be to use system restore points, but I’d have to reinstall all app and driver updates (and there’s no guarantee it would work). Or there’s the “nuclear option” of a in-place repair without losing files or apps, but even then, all my customizations would be lost! Microsoft just can’t help but mess everything up! Way to go, Microsoft! But I still don’t want your c****y Windows 11!
    • Microsoft: Windows 11 could finally solve a major issue across AMD, Nvidia, and Intel GPUs by Sayan Sen While Microsoft has been trying to improve it, Windows 11 is definitely not flawless, as even today some issues are taking a year to publicly acknowledge. However, one area of trouble that may finally see much better results soon is graphics driver crashes. Work on graphics driver timeouts, also called Timeout and Detection Recovery (TDR), is not new as the latest WDDM 3.2 also has specific improvements regarding it. Windows Display Driver Model (WDDM) version 3.2 is supported on Windows 11 24H2 and 25H2. However, with the upcoming version 26H2, TDR crash diagnosis could go to the next level as Microsoft is introducing a new DirectX 12 API feature called "DirectX Dump Files". Similar to how system memory dump files work when a system crashes or freezes or encounters any such major issue, DirectX Dump Files (DDF) will essentially record a snapshot of the GPU execution right at the moment a graphics-related crash or hang or freeze occurs, so that developers can better understand and diagnoze these TDR and timeout detection errors. The dump will be available as a .dxdmp file for analysis and it will be a comprehensive dump file generated with detailed insights about the hardware, drivers, Windows, as well as the affected application. This should be another welcome change in this department. Earlier at GDC 2026, when the technology was first debuted, Microsoft had shared more details regarding it. The company had explained how DDF is designed to gather data from every layer of the graphics stack into a single file, eliminating the need for developers to manually correlate logs from multiple tools. As mentioned above, the dump can contain a lot of useful details like GPU hardware state information such as register values, shader program counters, page fault virtual addresses, shader memory data, and command buffers. Alongside that, it also captures DirectX runtime and kernel information, including D3D objects, pipeline state objects, device error data, adapter details, and CPU call stacks. Microsoft says the feature has been built around two primary use cases: retail device removals and local device removals. The former allows developers to collect crash information from end users' systems in the field, while the latter helps QA teams and developers investigate issues on test machines. Developers will also be able to include up to 2 MB of custom application data through new D3D12 APIs, providing additional context for troubleshooting. In addition, Microsoft is introducing three dump collection modes ranging from zero-overhead capture, which has no runtime performance impact on supported hardware, to higher-detail modes that collect more vendor-specific debugging data. On compatible Tier 2 hardware, zero-overhead dumps will be enabled by default, meaning developers may begin receiving useful crash diagnostics without making any code changes. The table below explains the three tiers: Tier Description NO_OVERHEAD Enables crash capture with no runtime cost and is suitable for broad deployment MEDIUM_OVERHEAD Provides a balance, capturing additional diagnostic data with moderate impact HIGH_OVERHEAD Collects the most detailed GPU and driver state available, enabling deeper investigation at the cost of higher runtime overhead In terms of availability, the company expects broader release to be around the fall of 2026, which should be right around the time when Windows 11 version 26H2 lands. Right now, DirectX Dump Files are available as a preview and currently, only AMD has the compatible AgilitySDK Developer Preview driver version 26.10.07.02. You can find the official announcement post here on Microsoft's website.
    • And with SO much better perf than the laggy mess that is Files.
  • Recent Achievements

    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      598
    2. 2
      +Edouard
      190
    3. 3
      PsYcHoKiLLa
      79
    4. 4
      Michael Scrip
      76
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!