Energizer charger software installed Arucer
Energizer DUO USB battery charger software for Windows installed a backdoor DLL named Arucer.dll from the official charger-monitoring software path. CERT/CC disclosed the issue on March 5, 2010.
Story
Energizer DUO made a small promise: plug a USB battery charger into a Windows PC and watch the charge status. The optional vendor software carried more than that. Its installer placed UsbCharger.dll beside the application and Arucer.dll into system32, then the legitimate charger DLL started the second one through rundll32.exe.
The payload was not a stray toolbar or noisy adware. CERT/CC described Arucer.dll as a backdoor listening on 7777/tcp, with commands to list directories, send and receive files, and execute programs under the logged-on user's privileges. If the user allowed the Windows Firewall prompt for "Run DLL as an App," rundll32.exe itself could be added to the firewall exceptions list.
The compromise was striking because the product was mundane. A charger status utility had no obvious reason to expose a network service or persist through the Windows Run key, yet the installer arrived from the product support path a customer would naturally trust.
Energizer removed the download site, discontinued sale of the DUO Charger model CHUSB, and told Windows users to uninstall the software and delete the remaining DLL. The Arucer file carried a May 10, 2007 timestamp, but public reporting treated that as a clue, not proof of the full exposure window.
Affected Artifacts
- Observed
- 2010-03-05
- Compromised Versions
- Unknown
- Fixed
- Not listed
- Hashes
-
- md5:1070be3e60a1868d2cd62fc90d76c861
- sha1:d102b1d2538d8771be85403272e5a22a4b3f81ad
- Evidence
- distribution: energizer.com/usbcharger, distribution: energizerrecharge.eu/en/range/chargers/usb, mirror: kb.cert.org/vuls/id/154421, cve: CVE-2010-0103 , +8 more
- CERT/CC listed the Arucer.dll file version as 1.0.0.1 with a 2007-05-10 file date; public sources did not prove the complete distribution window.
- Removing the Energizer UsbCharger software removed startup execution, but CERT/CC said Arucer.dll could remain in system32 and might require a restart before deletion.
Incident Context
- Motive
- Remote Access
- Cause
- Compromised Installer
- Transitive
- No
External References
Source record: proprietary/energizer-duo/meta.yaml