Energizer Bunny’s Nasty Back Door

- March 8th, 2010

duoeneerg

A downloaded Windows application that allows you to view the status of a battery being charged through Energizer’s Duo USB Battery Charger, Model CHUSB, contains a Trojan horse that creates a backdoor that can leave a Windows PC vulnerable to intrusions.

According to Symantec, the Trojan dubbed Trojan.Arugizer compromises a computer by allowing port 7777 to be left open inviting in potential hackers.

The file “Arucer.dll” created, during the installation process makes this access possible.  It’s added to the registry run key, so every time you boot up the port is left open to possible unauthorized remote access.

Interestingly enough, Symantec suspects that the file may have been there for quite a while – pointing out that the date on  the compile time for the file was May 10, 2007.

Removed from Shelves

Symantec has rated the risk as very low and not everyone who has a charger has the infected file, since the software doesn’t ship with the unit and is needed to be downloaded independently.  The Mac version of the software is also not affected. Regardless, it appears that the company St. Louis, Missouri based Energizer Holdings, Inc., has stopped sales of the product and the software is no longer available on their sites.

Consumers are strongly advised to remove and uninstall  the software from their computers and ensure the Arucer.dll (in the Windows System32 directory) be removed. US-CERT, The  United States Computer Emergency Readiness Team also issued a Vulnerability note VU#154421 on this Trojan.

Tags: , , , , , , , ,

3 comments

  1. Mikey says:

    I read about this the other day and thought I would ask the question….. Why does anybody need software in order to charge their batteries?
    Most chargers have a Red LED that turns Green when the batteries are charged, software, buggy software in this case, is totally pointless!

    USB battery chargers are slow, compared to AC chargers, so why even bother? Besides, Duracell makes better batteries and chargers than Energizer, anyday!

  2. Greg Gazin says:

    Very true. The Software is a monitoring system. And why? probably because they can!

    G

  3. DaveTheA says:

    Hmmm…My Blackberry won’t recharge via the USB cable unless RIM software is installed….

    No ‘Arucer.dll’ installed on my computer, but this is worth checking farther into.

Leave a comment

 characters available