Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Virus alerts

March 8th, 2010, 14:46 GMT · By

Trojan Discovered in Energizer USB Charger Software

SHARE:

Adjust text size:


Energizer software packed with malware
Enlarge picture
U.S. battery manufacturer Energizer has suspended sales of its "Energizer DUO" product after a computer trojan was located in the software accompanying the product. Security experts suspect the malware has been distributed from the company's website since as far back as 2007.

The Energizer DUO is a USB/AC battery charger supporting a maximum of two (hence the name) AA or AAA NiMH rechargeable batteries. A program called "Energizer UsbCharger," which allows users to monitor the state of the batteries in the Energizer DUO, used to be available for download on the manufacturer’s website.

It is in the Windows version of this software package that the computer trojan was found in the form of a DLL file called Arucer.dll. An advisory concerning the malware was published by the U.S. Computer Emergency Response Team (US-CERT), which credits a user named Ed Schaller with its discovery.

Energizer DUO USB charger
Enlarge picture
In addition to performing its own analysis on the suspicious file, US-CERT sent a copy to U.S. antivirus vendor Symantec for further investigation. "We found that the file was a Trojan that opens a back door on a compromised computer and listens for commands on port 7777," wrote Liam O. Murchu, Symantec's supervisor of security response operations for North America.

The malware, which Symantec dubbed Trojan.Arugizer, installs itself so that it runs at computer restart and is able to download, execute or upload files. The name of its creator could be "Liu hong," a string mentioned several times inside the source code.

"We were interested in finding out how long this file had been available to the public. The compile time for the file is May 10, 2007. It is impossible to say for sure that this Trojan has always been in this software, but from our initial inspection it appears so," explained Mr. Murchu. It also seems that the file was an intended part of the software package since its creation and did not infect it at a later date. This is because the malicious .dll has code that specifically searches for the charger USB device.

Energizer Holdings confirmed the problem and is working with government officials and US-CERT to determine the circumstances that led to this incident. "Energizer has discontinued sale of this product and has removed the site to download the software," the company announced in a press release. Consumers who installed this software are instructed to immediately uninstall and delete the Arucer.dll file from the system32 directory.

TELL US WHAT YOU THINK:

8,729 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Mozilla Retracts Malware Accusations Against Firefox Extension

Hardware Manufacturer Serves Malware-Infected Drivers

Virus Infects Development Environment Delphi

Infected Christmas Presents from Samsung

"Apple iPod" Shipped with Virus

READER COMMENTS:


Comment #1 by: oliver on 08 Mar 2010, 22:19 UTC reply to this comment

I was going to say, "Let me guess where this product was made?", and then you list the name of the likely author of the malware.


Comment #2 by: Blaster on 16 Apr 2010, 18:58 UTC reply to this comment

i has no idea i ran this soft wherfor years untill i re set my pc. i just tryed to dl it for my new pc and i found this when serching googlew after not being able to fined it on the website


Comment #3 by: Martin on 30 Jun 2010, 05:42 UTC reply to this comment

The site to download this is still up and running. When I plugged my charger in today, my computer tried to install the driver, but my AV kicked in, and checking the net led me here.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM