UNLZEXE win32 verified as a backdoor trojan(?)

Discuss how totally awesome Bang! is here.

Moderator: Terryn

Post Reply
User avatar
Smilymzx
I hope she made lotsa spaghetti!
Posts: 179
Joined: Sat May 20, 2006 2:58 am
Location: LocacoLocacoL :LoL!

UNLZEXE win32 verified as a backdoor trojan(?)

Post by Smilymzx »

I wanted to open UNLZEXE for windows using ZZT 3.2, the one usually seen in CloneKeen's Package, But there is new news regarding Antivirus issues regarding it was a Malwaregen, and now it is verified as a Backdoor:

Here, I use Avast

http://forum.avast.com/index.php?topic=112244.0

Then Virustotal compared it to other AVs, I'm unsure if someone who has the code for UNLZEXE, if so, update the code to fix the issue(s) above and submit the fix!

User avatar
Quantum P.
Level 17 Accordion Thief
Posts: 1425
Joined: Fri Sep 12, 2003 1:41 am
Location: Edmonds, WA
Contact:

Re: UNLZEXE win32 verified as a backdoor trojan(?)

Post by Quantum P. »

How are ZZT 3.2 and UNLZEXE related? I don't understand what you're saying.

User avatar
Saxxon
the Gargoyle.
Posts: 608
Joined: Tue Jul 25, 2006 10:02 am
Contact:

Re: UNLZEXE win32 verified as a backdoor trojan(?)

Post by Saxxon »

Unlzexe is used for decompressing the executable file. This program is ancient.

I contribute to a Wiki that deals with this sort of thing. Here's a link to their article:
http://www.shikadi.net/keenwiki/UNLZEXE

User avatar
Smilymzx
I hope she made lotsa spaghetti!
Posts: 179
Joined: Sat May 20, 2006 2:58 am
Location: LocacoLocacoL :LoL!

Re: UNLZEXE win32 verified as a backdoor trojan(?)

Post by Smilymzx »

It is now fixed, It is a False-Positive after all!

ghettoflower
viovis
Posts: 48
Joined: Tue Oct 05, 2004 3:55 am
Location: jorja
Contact:

Re: UNLZEXE win32 verified as a backdoor trojan(?)

Post by ghettoflower »

Smilymzx wrote:It is now fixed, It is a False-Positive after all!
I was at the edge o my seat during this whole thread :agh:

I'm so glad it ended with a happy ending. :safe:
▒░Vivois▒▓█
-i like elk

Post Reply