Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Normal system programs crash immediatelly
  • Slow internet connection
  • System crashes
  • Slow Computer

Carabinieri virus

Carabinieri virus is a ransomware infection which is installed without the user’s permission and takes the computer hostage in order to make the user pay a fee of 100 Euros. The infection is a Trojan horse called Urausy, and it has a number of different versions which are already known around the world. The threat has different interfaces for every targeted country in order to convince the users that the legal enforcement agency of the country has discovered that the user is related to the distribution of prohibited content.

Like the vast majority of ransom warning that are generated by Trojan horses, Carabinieri virus, or rather the warning, contains the heading “Arma dei Carabinier”, which is the national military police of Italy. If your computer is infected with this threat, you should pay no attention to all the details indicating that the warning is sent by the police but remove Carabinieri virus from the computer. Moreover, ignore the emblems of Internet Police and Cyber Crime Unit. None of the institutions that are presented is related to the production of the warning or the ones that created the Trojan, so do not worry about the accusations of using or distributing pornography and other material – remove Carabinieri virus as soon as you can.

According to the warning, you have to pay a fine of €100 using either Paysafecard or Ukash. Due to the fact that the actual accusers are probably a group of cyber criminals, you should disregard the fine and the requirement to pay the fine in 48 hours:

La multa deve essere pagata da Lei entro 48 ore dope la violazione. Una volta che le 48 ore sono trascorse, per ulteriore 48 ore saranno raccolte automaticamente le informazioni complete su di Lei, e Lei te sarà perseguito.

Do not delay the removal of Carabinieri virus because the infection might download some additional program that may try to steal your personal information.

In order to remove Carabinieri virus from the computer and protect the computer against future infections, you should install SpyHunter, which is a powerful and reliable spyware removal tool. It has been used to eliminate Počítač je uzamčen poskytovatele služeb Internetu Virus, Ústav Počítačové Trestné Činnosti virus, and many other different computer infections. Use this spyware prevention tool if you want to be safe on the Internet and save your time.

How to remove Carabinieri virus

Windows Vista and Windows 7

  1. Restart the computer.
  2. Wait for the BIOS splash screen to load and tap the F8 key.
  3. Using the up/down arrow keys, select Safe Mode with Networking and press Enter.
  4. Open a browser and go to http://www.pcthreat.com/download-sph to download the recommended spyware removal tool.
  5. Install the application and scan the PC.

Windows 8

  1. Press the Windows key to access the Start screen.
  2. Launch Internet Explorer.
  3. Go to our website and download SpyHunter.
  4. Install it and scan the PC.

Windows XP

  1. Restart the computer.
  2. Once the BIOS splash screen loads, tap the F8 key.
  3. Select the Safe Mode with Networking option using the arrow keys.
  4. Press Enter.
  5. When the dialog box appears, click on the Yes button.
  6. Open the Start menu.
  7. Launch the Run command.
  8. Type in msconfig and click OK.
  9. Open the Startup tab and click Disable All.
  10. Click Apply.
  11. Go to http://www.pcthreat.com/download-sph and download the anti-spyware program.
  12. Restart the computer.
  13. Install the application and scan the PC.
Download Spyware Removal Tool to Remove* Carabinieri virus
  • Quick & tested solution for Carabinieri virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Carabinieri virus

Files associated with Carabinieri virus infection:

ssntvs.exe
systemcpl.exe
n.
dtkmujvo.exe
hwj3ba6j.dss
ACEIEAddOn.dll
Firewallservice.exe
50E1.exe
idiokbbrv.exe
xaZYOVJW.exe
%APPDATA%\updates
%TEMP%
DLL321.dll
msavfit.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
rool0_pk.exe
install_0_msi.exe
crack.exe
aPr0hY9.exe
3511172082012Build.exe
%SystemDrive%\????????????
%AppData%
comeo.exe
SyncHostps.exe
oygqyunapnp.exe
uenovfiu.exe
xmlfilter.exe
pYunY8m4VL3qLc.exe
NTServiceManager.exe
sqlncli.exe
WINDED6.exe
questscan.dll
scvhost.exe
00qbipeq.exe
%WINDIR%\system32
ex3b.dll
魔法桌面第三方主题破解补丁V1.1.exe
secproc_isv.exe
WinSyncMetastore.exe
securitywindrv.exe
wjthvwjb.dss
ubvhynpxh.exe
msn.exe
%CommonProgramFiles%
TimeDateMUICallback.exe
wgsdgsdgdsgsd.exe
obvwo.exe
UpdatePriv.exe
bzsbkotiu.exe
96dddda4.dll
%APPDATA%\system
xctqakcqbeo.dll
setex.exe
ctfmon.exe
iner.exe
p1.exe
wlsidten.exe
gcrwcoak.exe
00b5d693.exe
%ALLUSERSPROFILE%\Application Data
acuvzomo.exe
msdtmsrd.exe
dqnbdq7.dss
bf8h8d02hf.exe
%WINDIR%\Temp
taskhost.exe.exe
xlqbteeb.exe
87b2cb3916261d5c807bf44262755cb0.exe
%LOCALAPPDATA%\lollipop
najeoxtt.exe
JfCqQ5JC.exe
Other.res
jsdhlexdqkllnbcxgai.bfg
administration.exe
%UserProfile%
skype.dat
%LOCALAPPDATA%\Temp
OmaSG21e.exe
Task Scheduler.exe
brenasa.exe
msshell.exe
DA0B.exe
VaultSysUi.exe
csrsss.exe
Nbt.exe
dyjdl.exe
b34btbztdb0vavaw.exe
wahneaqa.exe
svchost.exe
wpbt0.dll
Q3d38543.exe
Updating.exe
yaiiwockc.dll
2084473.dll
mplayer2.exe
zqmkrehUkpoKfsafsaZg.exe
UpgradeHelper.exe
m2PythonLoader.exe
ifgxpers.exe
msnmsgrr.exe
%ALLUSERSPROFILE%
wlsidten.dll
bvhylsviw.exe
%APPDATA%\Task Scheduler
videotwisterSA.exe
rvcbcyks.exe
puozlkmyj.dll
C87C.exe
ieudator.dll
MusicCollector.exe
pmstcdjwz.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
Piranha.exe
audipbrd.exe

Carabinieri virus DLL's to remove:

ACEIEAddOn.dll
xctqakcqbeo.dll
questscan.dll
wpbt0.dll
DLL321.dll
96dddda4.dll
puozlkmyj.dll
wlsidten.dll
2084473.dll
ex3b.dll
yaiiwockc.dll
ieudator.dll

Carabinieri virus processes to kill:

najeoxtt.exe
87b2cb3916261d5c807bf44262755cb0.exe
svchost.exe
msavfit.exe
bf8h8d02hf.exe
install_0_msi.exe
TimeDateMUICallback.exe
WINDED6.exe
uenovfiu.exe
JfCqQ5JC.exe
Piranha.exe
00qbipeq.exe
ctfmon.exe
sqlncli.exe
msn.exe
secproc_isv.exe
wgsdgsdgdsgsd.exe
Firewallservice.exe
Updating.exe
msnmsgrr.exe
wahneaqa.exe
Nbt.exe
00b5d693.exe
xmlfilter.exe
brenasa.exe
MusicCollector.exe
idiokbbrv.exe
rvcbcyks.exe
pmstcdjwz.exe
NTServiceManager.exe
ifgxpers.exe
csrsss.exe
xlqbteeb.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
OmaSG21e.exe
obvwo.exe
aPr0hY9.exe
Q3d38543.exe
m2PythonLoader.exe
mplayer2.exe
bzsbkotiu.exe
ubvhynpxh.exe
gcrwcoak.exe
VaultSysUi.exe
dtkmujvo.exe
audipbrd.exe
administration.exe
xaZYOVJW.exe
scvhost.exe
bvhylsviw.exe
iner.exe
DA0B.exe
msdtmsrd.exe
acuvzomo.exe
comeo.exe
setex.exe
zqmkrehUkpoKfsafsaZg.exe
UpdatePriv.exe
SyncHostps.exe
videotwisterSA.exe
b34btbztdb0vavaw.exe
3511172082012Build.exe
p1.exe
Task Scheduler.exe
oygqyunapnp.exe
pYunY8m4VL3qLc.exe
msshell.exe
ssntvs.exe
securitywindrv.exe
taskhost.exe.exe
50E1.exe
C87C.exe
魔法桌面第三方主题破解补丁V1.1.exe
dyjdl.exe
rool0_pk.exe
systemcpl.exe
UpgradeHelper.exe
wlsidten.exe
crack.exe
WinSyncMetastore.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.