Watch Ransomware πŸ” (. Watch File) β€” Removal Guide

Watch virus: what is known so far?

The pattern of renaming is the following: id-xxxxx.[contact_email].watch. After the encryption, a file named, for instance, β€œreport.docx” will be changed to β€œreport.docx.id-9ECFA84E.[].watch”.

In each directory containing the encrypted files, a info.txt file will be found. It is a ransom money note. It contains information about the ways of paying the ransom and some other remarks. The ransom note usually contains a description of how to buy the decryption tool from the ransomware developers. You can obtain this decryptor after contacting through email. That is it.

NameWatch Virus
Ransomware family1Dharma ransomware
Extension.watch
Ransomware noteinfo.txt
Contact
Detection2Ransom:Win32/StopCrypt.PCG!MTB, Ransom:Win32/StopCrypt.SLO!MTB, Backdoor:Win32/Turla.W!dha
SymptomsYour files (photos, videos, documents) get a .watch extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Watch virus

The info.txt document coming in package with the Watch ransomware provides the following discouraging information:

all your data has been locked us
You want to return?
write email  or 

In the picture below, you can see what a directory with files encrypted by the Watch looks like. Each filename has the β€œ.watch” extension appended to it.

An example of encrypted .watch files.

How did my machine catch Watch ransomware?

Nowadays, there are three most exploited ways for malefactors to have the Watch virus planted in your system. These are email spam, Trojan infiltration and peer-to-peer file transfer.

If you open your mailbox and see emails that look like familiar notifications from utility services providers, delivery agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, be wary of opening those letters. They are most likely to have a viral item enclosed in them. Thus it is even riskier to open any attachments that come with letters like these.

Another thing the hackers might try is a Trojan virus model3. A Trojan is a program that infiltrates into your machine pretending to be something else. For instance, you download an installer for some program you want or an update for some software. But what is unpacked turns out to be a harmful program that encodes your data. As the update file can have any title and any icon, you’d better be sure that you can trust the resource of the stuff you’re downloading. The optimal thing is to trust the software companies’ official websites.

As for the peer-to-peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is reasonable to scan the folder containing the downloaded items with the antivirus as soon as the downloading is finished.

Sarah Jenkins

Sarah Jenkins

Senior Technology Editor & AI Specialist

Sarah Jenkins is a veteran tech journalist with over 12 years of experience covering artificial intelligence, mobile innovations, and digital ethics. Her insights have appeared in leading technology publications worldwide.

Share this article
Twitter Facebook Pinterest