Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Normal system programs crash immediatelly
  • Slow internet connection
  • System crashes
  • Slow Computer

Carabinieri virus

Carabinieri virus is a ransomware infection which is installed without the user’s permission and takes the computer hostage in order to make the user pay a fee of 100 Euros. The infection is a Trojan horse called Urausy, and it has a number of different versions which are already known around the world. The threat has different interfaces for every targeted country in order to convince the users that the legal enforcement agency of the country has discovered that the user is related to the distribution of prohibited content.

Like the vast majority of ransom warning that are generated by Trojan horses, Carabinieri virus, or rather the warning, contains the heading “Arma dei Carabinier”, which is the national military police of Italy. If your computer is infected with this threat, you should pay no attention to all the details indicating that the warning is sent by the police but remove Carabinieri virus from the computer. Moreover, ignore the emblems of Internet Police and Cyber Crime Unit. None of the institutions that are presented is related to the production of the warning or the ones that created the Trojan, so do not worry about the accusations of using or distributing pornography and other material – remove Carabinieri virus as soon as you can.

According to the warning, you have to pay a fine of €100 using either Paysafecard or Ukash. Due to the fact that the actual accusers are probably a group of cyber criminals, you should disregard the fine and the requirement to pay the fine in 48 hours:

La multa deve essere pagata da Lei entro 48 ore dope la violazione. Una volta che le 48 ore sono trascorse, per ulteriore 48 ore saranno raccolte automaticamente le informazioni complete su di Lei, e Lei te sarà perseguito.

Do not delay the removal of Carabinieri virus because the infection might download some additional program that may try to steal your personal information.

In order to remove Carabinieri virus from the computer and protect the computer against future infections, you should install SpyHunter, which is a powerful and reliable spyware removal tool. It has been used to eliminate Počítač je uzamčen poskytovatele služeb Internetu Virus, Ústav Počítačové Trestné Činnosti virus, and many other different computer infections. Use this spyware prevention tool if you want to be safe on the Internet and save your time.

How to remove Carabinieri virus

Windows Vista and Windows 7

  1. Restart the computer.
  2. Wait for the BIOS splash screen to load and tap the F8 key.
  3. Using the up/down arrow keys, select Safe Mode with Networking and press Enter.
  4. Open a browser and go to http://www.pcthreat.com/download-sph to download the recommended spyware removal tool.
  5. Install the application and scan the PC.

Windows 8

  1. Press the Windows key to access the Start screen.
  2. Launch Internet Explorer.
  3. Go to our website and download SpyHunter.
  4. Install it and scan the PC.

Windows XP

  1. Restart the computer.
  2. Once the BIOS splash screen loads, tap the F8 key.
  3. Select the Safe Mode with Networking option using the arrow keys.
  4. Press Enter.
  5. When the dialog box appears, click on the Yes button.
  6. Open the Start menu.
  7. Launch the Run command.
  8. Type in msconfig and click OK.
  9. Open the Startup tab and click Disable All.
  10. Click Apply.
  11. Go to http://www.pcthreat.com/download-sph and download the anti-spyware program.
  12. Restart the computer.
  13. Install the application and scan the PC.
Download Spyware Removal Tool to Remove* Carabinieri virus
  • Quick & tested solution for Carabinieri virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Carabinieri virus

Files associated with Carabinieri virus infection:

87b2cb3916261d5c807bf44262755cb0.exe
puozlkmyj.dll
UpdatePriv.exe
%WINDIR%\Temp
%WINDIR%\system32
ctfmon.exe
WinSyncMetastore.exe
scvhost.exe
%LOCALAPPDATA%\lollipop
xaZYOVJW.exe
Piranha.exe
obvwo.exe
SyncHostps.exe
p1.exe
rool0_pk.exe
ieudator.dll
videotwisterSA.exe
systemcpl.exe
wpbt0.dll
Q3d38543.exe
OmaSG21e.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
sqlncli.exe
uenovfiu.exe
mplayer2.exe
魔法桌面第三方主题破解补丁V1.1.exe
UpgradeHelper.exe
rvcbcyks.exe
%APPDATA%\system
%UserProfile%
3511172082012Build.exe
wahneaqa.exe
secproc_isv.exe
msdtmsrd.exe
ssntvs.exe
xmlfilter.exe
xctqakcqbeo.dll
m2PythonLoader.exe
taskhost.exe.exe
%ALLUSERSPROFILE%\Application Data
ubvhynpxh.exe
C87C.exe
setex.exe
msn.exe
VaultSysUi.exe
Nbt.exe
%SystemDrive%\????????????
zqmkrehUkpoKfsafsaZg.exe
bvhylsviw.exe
ACEIEAddOn.dll
yaiiwockc.dll
oygqyunapnp.exe
Firewallservice.exe
install_0_msi.exe
bzsbkotiu.exe
96dddda4.dll
50E1.exe
bf8h8d02hf.exe
msshell.exe
wlsidten.dll
questscan.dll
dtkmujvo.exe
MusicCollector.exe
wlsidten.exe
2084473.dll
Other.res
comeo.exe
acuvzomo.exe
%APPDATA%\updates
DA0B.exe
dqnbdq7.dss
Updating.exe
00qbipeq.exe
csrsss.exe
wjthvwjb.dss
hwj3ba6j.dss
iner.exe
00b5d693.exe
ifgxpers.exe
crack.exe
administration.exe
NTServiceManager.exe
b34btbztdb0vavaw.exe
msnmsgrr.exe
ex3b.dll
idiokbbrv.exe
aPr0hY9.exe
gcrwcoak.exe
%CommonProgramFiles%
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
%APPDATA%\Task Scheduler
brenasa.exe
jsdhlexdqkllnbcxgai.bfg
WINDED6.exe
DLL321.dll
Task Scheduler.exe
JfCqQ5JC.exe
pmstcdjwz.exe
dyjdl.exe
skype.dat
%TEMP%
securitywindrv.exe
xlqbteeb.exe
%AppData%
pYunY8m4VL3qLc.exe
%ALLUSERSPROFILE%
wgsdgsdgdsgsd.exe
svchost.exe
msavfit.exe
audipbrd.exe
TimeDateMUICallback.exe
n.
%LOCALAPPDATA%\Temp
najeoxtt.exe

Carabinieri virus DLL's to remove:

DLL321.dll
puozlkmyj.dll
96dddda4.dll
yaiiwockc.dll
wpbt0.dll
ex3b.dll
2084473.dll
wlsidten.dll
ieudator.dll
ACEIEAddOn.dll
xctqakcqbeo.dll
questscan.dll

Carabinieri virus processes to kill:

acuvzomo.exe
brenasa.exe
install_0_msi.exe
msshell.exe
MusicCollector.exe
JfCqQ5JC.exe
mplayer2.exe
Q3d38543.exe
00qbipeq.exe
ubvhynpxh.exe
crack.exe
ssntvs.exe
WinSyncMetastore.exe
gcrwcoak.exe
aPr0hY9.exe
Updating.exe
sqlncli.exe
msdtmsrd.exe
xaZYOVJW.exe
bf8h8d02hf.exe
p1.exe
setex.exe
msavfit.exe
UpgradeHelper.exe
audipbrd.exe
dyjdl.exe
UpdatePriv.exe
idiokbbrv.exe
Task Scheduler.exe
VaultSysUi.exe
rvcbcyks.exe
videotwisterSA.exe
50E1.exe
Piranha.exe
comeo.exe
wahneaqa.exe
SyncHostps.exe
TimeDateMUICallback.exe
najeoxtt.exe
scvhost.exe
secproc_isv.exe
wlsidten.exe
pmstcdjwz.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
csrsss.exe
DA0B.exe
OmaSG21e.exe
pYunY8m4VL3qLc.exe
b34btbztdb0vavaw.exe
msnmsgrr.exe
bzsbkotiu.exe
xlqbteeb.exe
obvwo.exe
iner.exe
wgsdgsdgdsgsd.exe
bvhylsviw.exe
ctfmon.exe
Nbt.exe
NTServiceManager.exe
uenovfiu.exe
securitywindrv.exe
oygqyunapnp.exe
taskhost.exe.exe
zqmkrehUkpoKfsafsaZg.exe
WINDED6.exe
rool0_pk.exe
systemcpl.exe
xmlfilter.exe
3511172082012Build.exe
m2PythonLoader.exe
87b2cb3916261d5c807bf44262755cb0.exe
C87C.exe
Firewallservice.exe
00b5d693.exe
ifgxpers.exe
dtkmujvo.exe
svchost.exe
魔法桌面第三方主题破解补丁V1.1.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
administration.exe
msn.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.