It is a little too late to write on the blog, but there are no English information, so I’d like to write about it.
The developer of UnLha.dll is stopping to develop unlha.dll and s/he recommend not to use lha (lzh) format. The announcement is here. (Japanese)
Lha is one of compressed file format and it is very popular in Japan.
But many anti-virus software doesn’t check the contents in lha archive.
Some of you know that many of anti-virus software didn’t check contents of compressed files and security organizations complained about it. (Report of CERT.FI / CVE) Now, most of anti-virus software scan the content of most of compressed files, but still doesn’t scan lha compressed file contents.
And IPA, Japanese governmental organization for IT, and JPCERT/CC, Japanese local CERT, decided not to treat it as a vlunerability and security software vendors won’t address this problem.