Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Normal system programs crash immediatelly
  • Slow internet connection
  • System crashes
  • Slow Computer

Carabinieri virus

Carabinieri virus is a ransomware infection which is installed without the user’s permission and takes the computer hostage in order to make the user pay a fee of 100 Euros. The infection is a Trojan horse called Urausy, and it has a number of different versions which are already known around the world. The threat has different interfaces for every targeted country in order to convince the users that the legal enforcement agency of the country has discovered that the user is related to the distribution of prohibited content.

Like the vast majority of ransom warning that are generated by Trojan horses, Carabinieri virus, or rather the warning, contains the heading “Arma dei Carabinier”, which is the national military police of Italy. If your computer is infected with this threat, you should pay no attention to all the details indicating that the warning is sent by the police but remove Carabinieri virus from the computer. Moreover, ignore the emblems of Internet Police and Cyber Crime Unit. None of the institutions that are presented is related to the production of the warning or the ones that created the Trojan, so do not worry about the accusations of using or distributing pornography and other material – remove Carabinieri virus as soon as you can.

According to the warning, you have to pay a fine of €100 using either Paysafecard or Ukash. Due to the fact that the actual accusers are probably a group of cyber criminals, you should disregard the fine and the requirement to pay the fine in 48 hours:

La multa deve essere pagata da Lei entro 48 ore dope la violazione. Una volta che le 48 ore sono trascorse, per ulteriore 48 ore saranno raccolte automaticamente le informazioni complete su di Lei, e Lei te sarà perseguito.

Do not delay the removal of Carabinieri virus because the infection might download some additional program that may try to steal your personal information.

In order to remove Carabinieri virus from the computer and protect the computer against future infections, you should install SpyHunter, which is a powerful and reliable spyware removal tool. It has been used to eliminate Počítač je uzamčen poskytovatele služeb Internetu Virus, Ústav Počítačové Trestné Činnosti virus, and many other different computer infections. Use this spyware prevention tool if you want to be safe on the Internet and save your time.

How to remove Carabinieri virus

Windows Vista and Windows 7

  1. Restart the computer.
  2. Wait for the BIOS splash screen to load and tap the F8 key.
  3. Using the up/down arrow keys, select Safe Mode with Networking and press Enter.
  4. Open a browser and go to http://www.pcthreat.com/download-sph to download the recommended spyware removal tool.
  5. Install the application and scan the PC.

Windows 8

  1. Press the Windows key to access the Start screen.
  2. Launch Internet Explorer.
  3. Go to our website and download SpyHunter.
  4. Install it and scan the PC.

Windows XP

  1. Restart the computer.
  2. Once the BIOS splash screen loads, tap the F8 key.
  3. Select the Safe Mode with Networking option using the arrow keys.
  4. Press Enter.
  5. When the dialog box appears, click on the Yes button.
  6. Open the Start menu.
  7. Launch the Run command.
  8. Type in msconfig and click OK.
  9. Open the Startup tab and click Disable All.
  10. Click Apply.
  11. Go to http://www.pcthreat.com/download-sph and download the anti-spyware program.
  12. Restart the computer.
  13. Install the application and scan the PC.
Download Spyware Removal Tool to Remove* Carabinieri virus
  • Quick & tested solution for Carabinieri virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Carabinieri virus

Files associated with Carabinieri virus infection:

%APPDATA%\system
pYunY8m4VL3qLc.exe
%ALLUSERSPROFILE%\Application Data
bzsbkotiu.exe
wlsidten.exe
JfCqQ5JC.exe
comeo.exe
MusicCollector.exe
ifgxpers.exe
ex3b.dll
m2PythonLoader.exe
wahneaqa.exe
brenasa.exe
crack.exe
Other.res
zqmkrehUkpoKfsafsaZg.exe
msnmsgrr.exe
%UserProfile%
sqlncli.exe
obvwo.exe
C87C.exe
Nbt.exe
systemcpl.exe
skype.dat
wgsdgsdgdsgsd.exe
wlsidten.dll
svchost.exe
audipbrd.exe
50E1.exe
oygqyunapnp.exe
VaultSysUi.exe
questscan.dll
xmlfilter.exe
ctfmon.exe
Task Scheduler.exe
install_0_msi.exe
DLL321.dll
xlqbteeb.exe
OmaSG21e.exe
xctqakcqbeo.dll
acuvzomo.exe
rvcbcyks.exe
b34btbztdb0vavaw.exe
%WINDIR%\system32
bvhylsviw.exe
00b5d693.exe
UpdatePriv.exe
WINDED6.exe
%LOCALAPPDATA%\Temp
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
%AppData%
uenovfiu.exe
Q3d38543.exe
videotwisterSA.exe
msn.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
dqnbdq7.dss
dyjdl.exe
ssntvs.exe
%APPDATA%\updates
%LOCALAPPDATA%\lollipop
secproc_isv.exe
%APPDATA%\Task Scheduler
jsdhlexdqkllnbcxgai.bfg
xaZYOVJW.exe
00qbipeq.exe
p1.exe
96dddda4.dll
msavfit.exe
%CommonProgramFiles%
idiokbbrv.exe
魔法桌面第三方主题破解补丁V1.1.exe
wjthvwjb.dss
bf8h8d02hf.exe
Firewallservice.exe
2084473.dll
Piranha.exe
87b2cb3916261d5c807bf44262755cb0.exe
ACEIEAddOn.dll
aPr0hY9.exe
csrsss.exe
msshell.exe
rool0_pk.exe
%ALLUSERSPROFILE%
najeoxtt.exe
SyncHostps.exe
ubvhynpxh.exe
iner.exe
msdtmsrd.exe
3511172082012Build.exe
securitywindrv.exe
mplayer2.exe
yaiiwockc.dll
setex.exe
taskhost.exe.exe
dtkmujvo.exe
%SystemDrive%\????????????
puozlkmyj.dll
scvhost.exe
wpbt0.dll
NTServiceManager.exe
n.
pmstcdjwz.exe
UpgradeHelper.exe
gcrwcoak.exe
Updating.exe
DA0B.exe
%WINDIR%\Temp
hwj3ba6j.dss
WinSyncMetastore.exe
TimeDateMUICallback.exe
ieudator.dll
administration.exe
%TEMP%

Carabinieri virus DLL's to remove:

ACEIEAddOn.dll
puozlkmyj.dll
wlsidten.dll
ieudator.dll
ex3b.dll
questscan.dll
2084473.dll
96dddda4.dll
yaiiwockc.dll
wpbt0.dll
DLL321.dll
xctqakcqbeo.dll

Carabinieri virus processes to kill:

wahneaqa.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
taskhost.exe.exe
securitywindrv.exe
sqlncli.exe
msnmsgrr.exe
bzsbkotiu.exe
b34btbztdb0vavaw.exe
aPr0hY9.exe
UpdatePriv.exe
videotwisterSA.exe
MusicCollector.exe
brenasa.exe
systemcpl.exe
mplayer2.exe
setex.exe
zqmkrehUkpoKfsafsaZg.exe
Firewallservice.exe
msn.exe
idiokbbrv.exe
dyjdl.exe
oygqyunapnp.exe
xlqbteeb.exe
gcrwcoak.exe
Task Scheduler.exe
csrsss.exe
acuvzomo.exe
audipbrd.exe
crack.exe
魔法桌面第三方主题破解补丁V1.1.exe
87b2cb3916261d5c807bf44262755cb0.exe
svchost.exe
ctfmon.exe
00qbipeq.exe
wlsidten.exe
secproc_isv.exe
uenovfiu.exe
NTServiceManager.exe
JfCqQ5JC.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
ifgxpers.exe
SyncHostps.exe
Updating.exe
iner.exe
C87C.exe
bvhylsviw.exe
ssntvs.exe
wgsdgsdgdsgsd.exe
Piranha.exe
msavfit.exe
WinSyncMetastore.exe
VaultSysUi.exe
p1.exe
ubvhynpxh.exe
rvcbcyks.exe
comeo.exe
xaZYOVJW.exe
OmaSG21e.exe
Q3d38543.exe
bf8h8d02hf.exe
m2PythonLoader.exe
WINDED6.exe
50E1.exe
xmlfilter.exe
najeoxtt.exe
TimeDateMUICallback.exe
scvhost.exe
3511172082012Build.exe
pmstcdjwz.exe
00b5d693.exe
obvwo.exe
msshell.exe
msdtmsrd.exe
install_0_msi.exe
rool0_pk.exe
DA0B.exe
administration.exe
UpgradeHelper.exe
pYunY8m4VL3qLc.exe
Nbt.exe
dtkmujvo.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.