A man in the middle attack is causing Everything to report a newer version and possibly download malware.
The issue appears to only occur on hijacked networks.
(in China from what I am hearing)
https://v2ex.com/t/878475http://www.voidtools.com/everything/update.ini The minor version number in this address is 6 (the test return is 4 on Tencent Cloud VPS) and the server field is Server: Microsoft- IIS/5.0
Cause:
Everything is using a insecure connection for checking the latest available version.
I am working on a fix.
Everything 1.4.1.1019 and earlier is using an insecure http connection to open the download page.
Everything 1.4.1.1020 or later will use a https connection to open the download page.
Everything-1.4.1.1021 fixes a security issue with using an insecure HTTP connection to check for new versions.
Solution:
Upgrade to Everything 1.4.1.1021 or later.
-or-
Please make sure Check for updates on startup is disabled:
- In Everything, from the Tools menu, click Options.
- Click the General tab on the left.
- Uncheck Check for updates on startup (unchecked by default)
- Click OK.
Please only download updates from:
https://www.voidtools.com/downloads
Everything 1.4.1.1020 or later will use a https connection to open the download page.
Everything 1.4.1.1021 or later will use a https connection to check for updates.
Avoid downloading updates on hijacked networks from:
http://www.voidtools.com/downloads