Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Normal system programs crash immediatelly
  • Slow internet connection
  • System crashes
  • Slow Computer

Carabinieri virus

Carabinieri virus is a ransomware infection which is installed without the user’s permission and takes the computer hostage in order to make the user pay a fee of 100 Euros. The infection is a Trojan horse called Urausy, and it has a number of different versions which are already known around the world. The threat has different interfaces for every targeted country in order to convince the users that the legal enforcement agency of the country has discovered that the user is related to the distribution of prohibited content.

Like the vast majority of ransom warning that are generated by Trojan horses, Carabinieri virus, or rather the warning, contains the heading “Arma dei Carabinier”, which is the national military police of Italy. If your computer is infected with this threat, you should pay no attention to all the details indicating that the warning is sent by the police but remove Carabinieri virus from the computer. Moreover, ignore the emblems of Internet Police and Cyber Crime Unit. None of the institutions that are presented is related to the production of the warning or the ones that created the Trojan, so do not worry about the accusations of using or distributing pornography and other material – remove Carabinieri virus as soon as you can.

According to the warning, you have to pay a fine of €100 using either Paysafecard or Ukash. Due to the fact that the actual accusers are probably a group of cyber criminals, you should disregard the fine and the requirement to pay the fine in 48 hours:

La multa deve essere pagata da Lei entro 48 ore dope la violazione. Una volta che le 48 ore sono trascorse, per ulteriore 48 ore saranno raccolte automaticamente le informazioni complete su di Lei, e Lei te sarà perseguito.

Do not delay the removal of Carabinieri virus because the infection might download some additional program that may try to steal your personal information.

In order to remove Carabinieri virus from the computer and protect the computer against future infections, you should install SpyHunter, which is a powerful and reliable spyware removal tool. It has been used to eliminate Počítač je uzamčen poskytovatele služeb Internetu Virus, Ústav Počítačové Trestné Činnosti virus, and many other different computer infections. Use this spyware prevention tool if you want to be safe on the Internet and save your time.

How to remove Carabinieri virus

Windows Vista and Windows 7

  1. Restart the computer.
  2. Wait for the BIOS splash screen to load and tap the F8 key.
  3. Using the up/down arrow keys, select Safe Mode with Networking and press Enter.
  4. Open a browser and go to http://www.pcthreat.com/download-sph to download the recommended spyware removal tool.
  5. Install the application and scan the PC.

Windows 8

  1. Press the Windows key to access the Start screen.
  2. Launch Internet Explorer.
  3. Go to our website and download SpyHunter.
  4. Install it and scan the PC.

Windows XP

  1. Restart the computer.
  2. Once the BIOS splash screen loads, tap the F8 key.
  3. Select the Safe Mode with Networking option using the arrow keys.
  4. Press Enter.
  5. When the dialog box appears, click on the Yes button.
  6. Open the Start menu.
  7. Launch the Run command.
  8. Type in msconfig and click OK.
  9. Open the Startup tab and click Disable All.
  10. Click Apply.
  11. Go to http://www.pcthreat.com/download-sph and download the anti-spyware program.
  12. Restart the computer.
  13. Install the application and scan the PC.
Download Spyware Removal Tool to Remove* Carabinieri virus
  • Quick & tested solution for Carabinieri virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Carabinieri virus

Files associated with Carabinieri virus infection:

msshell.exe
%APPDATA%\system
ssntvs.exe
SyncHostps.exe
JfCqQ5JC.exe
%ALLUSERSPROFILE%\Application Data
50E1.exe
%TEMP%
Firewallservice.exe
rool0_pk.exe
%WINDIR%\Temp
pYunY8m4VL3qLc.exe
%WINDIR%\system32
xmlfilter.exe
Q3d38543.exe
OmaSG21e.exe
n.
MusicCollector.exe
iner.exe
csrsss.exe
gcrwcoak.exe
securitywindrv.exe
wpbt0.dll
install_0_msi.exe
%UserProfile%
msdtmsrd.exe
Other.res
bzsbkotiu.exe
%LOCALAPPDATA%\lollipop
skype.dat
najeoxtt.exe
%APPDATA%\Task Scheduler
videotwisterSA.exe
mplayer2.exe
wgsdgsdgdsgsd.exe
%ALLUSERSPROFILE%
ieudator.dll
ifgxpers.exe
Nbt.exe
hwj3ba6j.dss
%APPDATA%\updates
00qbipeq.exe
xaZYOVJW.exe
ctfmon.exe
dyjdl.exe
oygqyunapnp.exe
C87C.exe
pmstcdjwz.exe
taskhost.exe.exe
wjthvwjb.dss
aPr0hY9.exe
msn.exe
DLL321.dll
%SystemDrive%\????????????
3511172082012Build.exe
xctqakcqbeo.dll
zqmkrehUkpoKfsafsaZg.exe
WINDED6.exe
msavfit.exe
TimeDateMUICallback.exe
NTServiceManager.exe
UpdatePriv.exe
secproc_isv.exe
uenovfiu.exe
b34btbztdb0vavaw.exe
魔法桌面第三方主题破解补丁V1.1.exe
WinSyncMetastore.exe
UpgradeHelper.exe
systemcpl.exe
ubvhynpxh.exe
idiokbbrv.exe
jsdhlexdqkllnbcxgai.bfg
dqnbdq7.dss
obvwo.exe
svchost.exe
acuvzomo.exe
00b5d693.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
administration.exe
scvhost.exe
m2PythonLoader.exe
xlqbteeb.exe
%CommonProgramFiles%
puozlkmyj.dll
ACEIEAddOn.dll
ex3b.dll
brenasa.exe
crack.exe
bf8h8d02hf.exe
bvhylsviw.exe
wahneaqa.exe
Piranha.exe
audipbrd.exe
yaiiwockc.dll
87b2cb3916261d5c807bf44262755cb0.exe
VaultSysUi.exe
Task Scheduler.exe
dtkmujvo.exe
p1.exe
rvcbcyks.exe
%LOCALAPPDATA%\Temp
setex.exe
questscan.dll
wlsidten.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
sqlncli.exe
%AppData%
msnmsgrr.exe
DA0B.exe
2084473.dll
Updating.exe
comeo.exe
wlsidten.dll
96dddda4.dll

Carabinieri virus DLL's to remove:

ACEIEAddOn.dll
ieudator.dll
xctqakcqbeo.dll
DLL321.dll
wpbt0.dll
puozlkmyj.dll
96dddda4.dll
2084473.dll
ex3b.dll
wlsidten.dll
yaiiwockc.dll
questscan.dll

Carabinieri virus processes to kill:

SyncHostps.exe
svchost.exe
WinSyncMetastore.exe
scvhost.exe
administration.exe
Firewallservice.exe
systemcpl.exe
pYunY8m4VL3qLc.exe
securitywindrv.exe
魔法桌面第三方主题破解补丁V1.1.exe
wlsidten.exe
sqlncli.exe
OmaSG21e.exe
dyjdl.exe
ssntvs.exe
mplayer2.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
Nbt.exe
JfCqQ5JC.exe
msavfit.exe
NTServiceManager.exe
comeo.exe
brenasa.exe
TimeDateMUICallback.exe
wahneaqa.exe
videotwisterSA.exe
audipbrd.exe
00qbipeq.exe
87b2cb3916261d5c807bf44262755cb0.exe
aPr0hY9.exe
iner.exe
WINDED6.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
msdtmsrd.exe
setex.exe
ctfmon.exe
xmlfilter.exe
taskhost.exe.exe
csrsss.exe
UpdatePriv.exe
50E1.exe
m2PythonLoader.exe
00b5d693.exe
xlqbteeb.exe
bvhylsviw.exe
dtkmujvo.exe
msnmsgrr.exe
ifgxpers.exe
gcrwcoak.exe
Task Scheduler.exe
p1.exe
ubvhynpxh.exe
3511172082012Build.exe
msshell.exe
idiokbbrv.exe
Piranha.exe
wgsdgsdgdsgsd.exe
MusicCollector.exe
msn.exe
bzsbkotiu.exe
oygqyunapnp.exe
zqmkrehUkpoKfsafsaZg.exe
xaZYOVJW.exe
b34btbztdb0vavaw.exe
rool0_pk.exe
najeoxtt.exe
bf8h8d02hf.exe
uenovfiu.exe
obvwo.exe
pmstcdjwz.exe
rvcbcyks.exe
install_0_msi.exe
Q3d38543.exe
secproc_isv.exe
C87C.exe
UpgradeHelper.exe
crack.exe
DA0B.exe
VaultSysUi.exe
acuvzomo.exe
Updating.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.