Welcome to the Cumulus Support forum.

Latest Cumulus MX V4 release 4.4.2 (build 4085) - 12 March 2025

Latest Cumulus MX V3 release 3.28.6 (build 3283) - 21 March 2024

Legacy Cumulus 1 release 1.9.4 (build 1099) - 28 November 2014
(a patch is available for 1.9.4 build 1099 that extends the date range of drop-down menus to 2030)

Download the Software (Cumulus MX / Cumulus 1 and other related items) from the Wiki

If you are posting a new Topic about an error or if you need help PLEASE read this first viewtopic.php?p=164080#p164080

Ransonware Potential?

From build 3044 the development baton passed to Mark Crossley. Mark has been responsible for all the Builds since. He has made the code available on GitHub. It is Mark's hope that others will join in this development, but at the very least he welcomes your ideas for future developments (see Cumulus MX Development suggestions).

Moderator: mcrossley

Post Reply
Bernard46
Posts: 15
Joined: Tue 21 Jun 2011 9:16 pm
Weather Station: Oregon Scientific WMR200
Operating System: Win10 Pro
Location: Harbury, Warwickshire

Ransonware Potential?

Post by Bernard46 »

Last night I downloaded CumulusMX and the WeatherCloud software (I was thinking of upgrading my Cumulus to be able to use WeatherCloud) - immediately I received a warning from Windows Defender (I'm running Windows 10 Pro and its bang up to date) about an alleged threat to my system from potentially unwanted software. This threat relates to software which apparently facilitates the insertion of ransomware on my machine

The details provided by Windows Defender were :
Threat Detected: Program:Win32/Wacapew.C!ml
Affected Items: C:\Cumulus\Weathercloud\cumulus-weathercloud\weathercloud.exe

Needless to say I immediately told Windows Defender to quarantine and remove the problem.

I have contacted Weathercloud about this and they immediately came back and said it wasn't their software but rather the add-on from CumulusMX.

I've looked on the web and there are a number of entries (including one on the Microsoft site) relating to Wacapew.C!ml - I'm also particularly suspicious of a file which uses an exclamation mark as one of the letters in its name - this seems to me to be completely unnecessary and the sort of thing that would only be used if someone wanted to deceive people into thinking a file name was something else - a typical malware trick.

What is the CumulusMX developers view on this?
water01
Posts: 3670
Joined: Sat 13 Aug 2011 9:33 am
Weather Station: Ecowitt HP2551
Operating System: Windows 10/11 64bit Synology NAS
Location: Burnham-on-Sea
Contact:

Re: Ransonware Potential?

Post by water01 »

There is no such file in either the CumulusMX release or the Cumulus 1 release. I do not understand why you downloaded software for Weathercloud when CumulusMx just talks to their API when you have signed up for an account on there system.

It would appear that this is some sort of adware program that have you inadvertently downloaded from another site https://howtofix.guide/wacapew-removal/ and from what you have said it suggests the site you got the "WeatherCloud software" from whatever that is.
David
Image
User avatar
PaulMy
Posts: 4355
Joined: Sun 28 Sep 2008 11:54 pm
Weather Station: Davis VP2 Plus 24-Hour FARS
Operating System: Windows8 and Windows10
Location: Komoka, ON Canada
Contact:

Re: Ransonware Potential?

Post by PaulMy »

That program was by Adrian H to allow Cumulus1 to upload to Weathercloud. This is in from the Readme:
"Note: Some antivirus programs may have issue with the language this program is written in (autoit3). If your AV program flags the program as a possible virus please add an exception to your antivirus program. The program is checked clean by my own AV program (Kaspersky)."
And as discussed here viewtopic.php?f=4&t=11998&p=111006&hili ... ud#p111006

I downloaded and installed on more than one occasion, just had to add it to allow in the my virus protection. It is still being used every day on my old Windows8 PC/Cumulus1 setup.

With WC upload built-in CumulusMX this utility is not needed.

Enjoy,
Paul
VP2+
C1 www.komokaweather.com/komokaweather-ca
MX https://komokaweather.com/cumulusmx/index.htm /index.html /index.php
MX https://komokaweather.com/cumulusmxwll/index.htm /index.html /index.php
MX https:// komokaweather.com/cumulusmx4/index.htm
Image
BrunswickWeather
Posts: 87
Joined: Fri 11 Mar 2011 2:04 am
Weather Station: Ecowitt GW1103
Operating System: windows 11 Pro/Raspberry pi 4
Location: Brunswick Australia

Re: Ransonware Potential?

Post by BrunswickWeather »

Every time I update Cumulus MX exe the Microsoft Defender warns me, but I make it ignore the "problem".
sfws
Posts: 1183
Joined: Fri 27 Jul 2012 11:29 am
Weather Station: Chas O, Maplin N96FY, N25FR
Operating System: rPi 3B+ with Buster (full)

Re: Ransonware Potential?

Post by sfws »

BrunswickWeather wrote: Wed 06 May 2020 6:11 am Every time I update Cumulus MX exe the Microsoft Defender warns me
There is no way to know what is in a file that has not been run yet, even if the file you want to run has same name as a file you have run before, the update is not the file you have run before.


Microsoft defender like many other virus checkers will always warn about an updated version of any software, just in case someone has hacked that update to contain something unwanted.
User avatar
HansR
Posts: 6926
Joined: Sat 20 Oct 2012 6:53 am
Weather Station: GW1100 (WS80/WH40)
Operating System: Raspberry OS/Bookworm
Location: Wagenborgen (NL)
Contact:

Re: Ransonware Potential?

Post by HansR »

sfws wrote: Wed 06 May 2020 7:00 am Microsoft defender like many other virus checkers will always warn about an updated version of any software, just in case someone has hacked that update to contain something unwanted.
Is assume there is more intelligence in those checkers that what you are implying now.
Thinking about checksums, pattern checks etc...
Hans

https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
sfws
Posts: 1183
Joined: Fri 27 Jul 2012 11:29 am
Weather Station: Chas O, Maplin N96FY, N25FR
Operating System: rPi 3B+ with Buster (full)

Re: Ransonware Potential?

Post by sfws »

HansR wrote: Wed 06 May 2020 7:13 am Thinking about checksums, pattern checks etc.
Agreed, these exist, and can detect some unsafe modifications, but the checker can't be sure until it has learnt that the new release of MX or whatever with its new checksum and new pattern is safe. MX does generate a web server and update databases, both areas where there is scope for malicious activity.
water01
Posts: 3670
Joined: Sat 13 Aug 2011 9:33 am
Weather Station: Ecowitt HP2551
Operating System: Windows 10/11 64bit Synology NAS
Location: Burnham-on-Sea
Contact:

Re: Ransonware Potential?

Post by water01 »

PaulMy wrote: Tue 05 May 2020 11:21 pm That program was by Adrian H to allow Cumulus1 to upload to Weathercloud. This is in from the Readme:
"Note: Some antivirus programs may have issue with the language this program is written in (autoit3). If your AV program flags the program as a possible virus please add an exception to your antivirus program. The program is checked clean by my own AV program (Kaspersky)."
And as discussed here viewtopic.php?f=4&t=11998&p=111006&hili ... ud#p111006

I downloaded and installed on more than one occasion, just had to add it to allow in the my virus protection. It is still being used every day on my old Windows8 PC/Cumulus1 setup.

With WC upload built-in CumulusMX this utility is not needed.

Enjoy,
Paul
I get that Paul but he says he downloaded CumulusMX so why did he download the other software because as you say it is not needed? Best way to proceed for him if he is using CumulusMX is to delete the Download completely.
David
Image
Post Reply