Last night I downloaded CumulusMX and the WeatherCloud software (I was thinking of upgrading my Cumulus to be able to use WeatherCloud) - immediately I received a warning from Windows Defender (I'm running Windows 10 Pro and its bang up to date) about an alleged threat to my system from potentially unwanted software. This threat relates to software which apparently facilitates the insertion of ransomware on my machine
The details provided by Windows Defender were :
Threat Detected: Program:Win32/Wacapew.C!ml
Affected Items: C:\Cumulus\Weathercloud\cumulus-weathercloud\weathercloud.exe
Needless to say I immediately told Windows Defender to quarantine and remove the problem.
I have contacted Weathercloud about this and they immediately came back and said it wasn't their software but rather the add-on from CumulusMX.
I've looked on the web and there are a number of entries (including one on the Microsoft site) relating to Wacapew.C!ml - I'm also particularly suspicious of a file which uses an exclamation mark as one of the letters in its name - this seems to me to be completely unnecessary and the sort of thing that would only be used if someone wanted to deceive people into thinking a file name was something else - a typical malware trick.
What is the CumulusMX developers view on this?
Welcome to the Cumulus Support forum.
Latest Cumulus MX V4 release 4.4.2 (build 4085) - 12 March 2025
Latest Cumulus MX V3 release 3.28.6 (build 3283) - 21 March 2024
Legacy Cumulus 1 release 1.9.4 (build 1099) - 28 November 2014
(a patch is available for 1.9.4 build 1099 that extends the date range of drop-down menus to 2030)
Download the Software (Cumulus MX / Cumulus 1 and other related items) from the Wiki
If you are posting a new Topic about an error or if you need help PLEASE read this first viewtopic.php?p=164080#p164080
Latest Cumulus MX V4 release 4.4.2 (build 4085) - 12 March 2025
Latest Cumulus MX V3 release 3.28.6 (build 3283) - 21 March 2024
Legacy Cumulus 1 release 1.9.4 (build 1099) - 28 November 2014
(a patch is available for 1.9.4 build 1099 that extends the date range of drop-down menus to 2030)
Download the Software (Cumulus MX / Cumulus 1 and other related items) from the Wiki
If you are posting a new Topic about an error or if you need help PLEASE read this first viewtopic.php?p=164080#p164080
Ransonware Potential?
Moderator: mcrossley
-
water01
- Posts: 3670
- Joined: Sat 13 Aug 2011 9:33 am
- Weather Station: Ecowitt HP2551
- Operating System: Windows 10/11 64bit Synology NAS
- Location: Burnham-on-Sea
- Contact:
Re: Ransonware Potential?
There is no such file in either the CumulusMX release or the Cumulus 1 release. I do not understand why you downloaded software for Weathercloud when CumulusMx just talks to their API when you have signed up for an account on there system.
It would appear that this is some sort of adware program that have you inadvertently downloaded from another site https://howtofix.guide/wacapew-removal/ and from what you have said it suggests the site you got the "WeatherCloud software" from whatever that is.
It would appear that this is some sort of adware program that have you inadvertently downloaded from another site https://howtofix.guide/wacapew-removal/ and from what you have said it suggests the site you got the "WeatherCloud software" from whatever that is.
- PaulMy
- Posts: 4355
- Joined: Sun 28 Sep 2008 11:54 pm
- Weather Station: Davis VP2 Plus 24-Hour FARS
- Operating System: Windows8 and Windows10
- Location: Komoka, ON Canada
- Contact:
Re: Ransonware Potential?
That program was by Adrian H to allow Cumulus1 to upload to Weathercloud. This is in from the Readme:
"Note: Some antivirus programs may have issue with the language this program is written in (autoit3). If your AV program flags the program as a possible virus please add an exception to your antivirus program. The program is checked clean by my own AV program (Kaspersky)."
And as discussed here viewtopic.php?f=4&t=11998&p=111006&hili ... ud#p111006
I downloaded and installed on more than one occasion, just had to add it to allow in the my virus protection. It is still being used every day on my old Windows8 PC/Cumulus1 setup.
With WC upload built-in CumulusMX this utility is not needed.
Enjoy,
Paul
"Note: Some antivirus programs may have issue with the language this program is written in (autoit3). If your AV program flags the program as a possible virus please add an exception to your antivirus program. The program is checked clean by my own AV program (Kaspersky)."
And as discussed here viewtopic.php?f=4&t=11998&p=111006&hili ... ud#p111006
I downloaded and installed on more than one occasion, just had to add it to allow in the my virus protection. It is still being used every day on my old Windows8 PC/Cumulus1 setup.
With WC upload built-in CumulusMX this utility is not needed.
Enjoy,
Paul
VP2+
C1 www.komokaweather.com/komokaweather-ca
MX https://komokaweather.com/cumulusmx/index.htm /index.html /index.php
MX https://komokaweather.com/cumulusmxwll/index.htm /index.html /index.php
MX https:// komokaweather.com/cumulusmx4/index.htm

C1 www.komokaweather.com/komokaweather-ca
MX https://komokaweather.com/cumulusmx/index.htm /index.html /index.php
MX https://komokaweather.com/cumulusmxwll/index.htm /index.html /index.php
MX https:// komokaweather.com/cumulusmx4/index.htm
-
BrunswickWeather
- Posts: 87
- Joined: Fri 11 Mar 2011 2:04 am
- Weather Station: Ecowitt GW1103
- Operating System: windows 11 Pro/Raspberry pi 4
- Location: Brunswick Australia
Re: Ransonware Potential?
Every time I update Cumulus MX exe the Microsoft Defender warns me, but I make it ignore the "problem".
-
sfws
- Posts: 1183
- Joined: Fri 27 Jul 2012 11:29 am
- Weather Station: Chas O, Maplin N96FY, N25FR
- Operating System: rPi 3B+ with Buster (full)
Re: Ransonware Potential?
There is no way to know what is in a file that has not been run yet, even if the file you want to run has same name as a file you have run before, the update is not the file you have run before.BrunswickWeather wrote: ↑Wed 06 May 2020 6:11 am Every time I update Cumulus MX exe the Microsoft Defender warns me
Microsoft defender like many other virus checkers will always warn about an updated version of any software, just in case someone has hacked that update to contain something unwanted.
- HansR
- Posts: 6926
- Joined: Sat 20 Oct 2012 6:53 am
- Weather Station: GW1100 (WS80/WH40)
- Operating System: Raspberry OS/Bookworm
- Location: Wagenborgen (NL)
- Contact:
Re: Ransonware Potential?
Is assume there is more intelligence in those checkers that what you are implying now.
Thinking about checksums, pattern checks etc...
Hans
https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
https://meteo-wagenborgen.nl
CMX build 4070+ ● RPi 4B ● Linux 6.6.62+rpt-rpi-v8 aarch64 (bookworm) ● dotnet 8.0.1
BlueSky: https://bsky.app/profile/wagenborgenwx.bsky.social
-
sfws
- Posts: 1183
- Joined: Fri 27 Jul 2012 11:29 am
- Weather Station: Chas O, Maplin N96FY, N25FR
- Operating System: rPi 3B+ with Buster (full)
Re: Ransonware Potential?
Agreed, these exist, and can detect some unsafe modifications, but the checker can't be sure until it has learnt that the new release of MX or whatever with its new checksum and new pattern is safe. MX does generate a web server and update databases, both areas where there is scope for malicious activity.
-
water01
- Posts: 3670
- Joined: Sat 13 Aug 2011 9:33 am
- Weather Station: Ecowitt HP2551
- Operating System: Windows 10/11 64bit Synology NAS
- Location: Burnham-on-Sea
- Contact:
Re: Ransonware Potential?
I get that Paul but he says he downloaded CumulusMX so why did he download the other software because as you say it is not needed? Best way to proceed for him if he is using CumulusMX is to delete the Download completely.PaulMy wrote: ↑Tue 05 May 2020 11:21 pm That program was by Adrian H to allow Cumulus1 to upload to Weathercloud. This is in from the Readme:
"Note: Some antivirus programs may have issue with the language this program is written in (autoit3). If your AV program flags the program as a possible virus please add an exception to your antivirus program. The program is checked clean by my own AV program (Kaspersky)."
And as discussed here viewtopic.php?f=4&t=11998&p=111006&hili ... ud#p111006
I downloaded and installed on more than one occasion, just had to add it to allow in the my virus protection. It is still being used every day on my old Windows8 PC/Cumulus1 setup.
With WC upload built-in CumulusMX this utility is not needed.
Enjoy,
Paul