Authors of WinLock2 target Czech-speaking Call of Duty WWII players

WinLock2 is a ransomware virus that has features of the screenlocker. Researchers have noticed it spreading as a fake Call of Duty WWII game[1] and targeting Czech[2] computer users. The scam tells that victims broke the law and now have to pay 1000 Czech koruna to get back encrypted files.
The lock screen message delivered by the WinLock2 ransomware has an excerpt from the legal documents that talk about possible penalties for breaking the law. Scammers want to make victims believe that they are accused of:
- downloading music or videos illegally;
- using cracked software;
- visited forbidden websites.
Authors of WinLock2 virus threaten to delete all the data if people don’t pay the ransom. Victims are asked to pay 1000 Check koruna in order to get a PIN code that unlocks the screen. Once criminals receive the money, they should provide a code that victims are supposed to enter into the provided form.
However, security specialists do not recommend doing this.[3] Criminals may never give you a code or might blackmail you into paying more money. Therefore, you should bypass the lock screen and remove WinLock2 from the computer as soon as possible.
However, the scam might look credible for inexperienced computer users. It uses the clean design, Czech police credentials, and logos of other organizations, such as Europol. However, you should never forget that legal institutions do not lock computer’s screen, as well as do not demand to pay the ransom in order to avoid punishment.
If your computer was hacked by this malware, you should immediately run WinLock2 removal with FortectIntego or another malware removal program. However, if you have problems with the elimination, you should check the guide below.

Malware spreads as Call of Duty WWII crack
The ransomware that targets Czech computer users spread as a crack for a popular game – Call of Duty WWII. The name of the malicious file – Call_of_Duty_WWII_SKIDROWcracked.exe. Once it is dropped on the system, it is executed and launches ransomware on the device.
Additionally, researchers found another sample of malware that spreads as an obfuscated WinLock2.exe file. This file might be spread using other methods, such as:
- malicious spam emails,
- other illegal games or software downloads,
- fake software updates,
- malware-laden ads.
Detailed guide on how to get rid of WinLock2 ransomware virus
The virus operates as a screenlocker and ransomware. Thus, you have to unlock computer’s screen in order to remove WinLock2 entirely. Follow these steps:
- Enter the PIN of the 16 random characters, for instance, “0123456789abcdefand” and click the button called “Zaplatt.”
- You will receive a prompt window saying:
Platba proběhla úspěšně! Počítač bude odblokován. - Click OK.
- You will see another prompt that tells to reboot your computer which you should ignore:
Nyní restartujte svůj počítač.
However, instead of rebooting the computer, you have to run FortectIntego, MalwarebytesMalwarebytes or another anti-malware software to delete WinLock2 from the computer. Do not try to locate and eliminate malicious components manually. It’s a complicated cyber threat that may have affected critical system processes. Thus, you do not want to damage them.
However, if you cannot run security software, you may need to restart your PC in Safe Mode with Networking as shown below. This should help to perform the automatic WinLock2 removal.
Did this guide help?
Be the first to comment