Proprietary ·

Energizer charger software installed Arucer

Energizer DUO USB battery charger software for Windows installed a backdoor DLL named Arucer.dll from the official charger-monitoring software path. CERT/CC disclosed the issue on March 5, 2010.

Energizer DUO made a small promise: plug a USB battery charger into a Windows PC and watch the charge status. The optional vendor software carried more than that. Its installer placed UsbCharger.dll beside the application and Arucer.dll into system32, then the legitimate charger DLL started the second one through rundll32.exe.

The payload was not a stray toolbar or noisy adware. CERT/CC described Arucer.dll as a backdoor listening on 7777/tcp, with commands to list directories, send and receive files, and execute programs under the logged-on user's privileges. If the user allowed the Windows Firewall prompt for "Run DLL as an App," rundll32.exe itself could be added to the firewall exceptions list.

The compromise was striking because the product was mundane. A charger status utility had no obvious reason to expose a network service or persist through the Windows Run key, yet the installer arrived from the product support path a customer would naturally trust.

Energizer removed the download site, discontinued sale of the DUO Charger model CHUSB, and told Windows users to uninstall the software and delete the remaining DLL, saying that doing so "will eliminate the vulnerability." CERT/CC disagreed on that point: the backdoor keeps running until the machine is restarted, and the firewall exclusion survives the uninstall. CERT/CC also recorded that it had received no statement from the vendor, despite the same-day press release. The Arucer file carried a May 10, 2007 timestamp, but public reporting treated that as a clue, not proof of the full exposure window.

Appendix · Affected releases

  • CERT/CC recorded the Arucer.dll resource language as 0x0804, Chinese (PRC).
  • CERT/CC listed the Arucer.dll file version as 1.0.0.1 with a 2007-05-10 file date; public sources did not prove the complete distribution window.
  • Removing the Energizer UsbCharger software removed startup execution, but CERT/CC said Arucer.dll could remain in system32 and might require a restart before deletion.

References

  1. Energizer DUO USB battery charger software allows unauthorized remote system accesskb.cert.org
  2. Energizer Duo software suffers backdoor Trojan bothertheregister.com
  3. CVE-2010-0103 Detailnvd.nist.gov
  4. Energizer Announces DUO Charger and USB Charger Software Problemprnewswire.com

Source record: proprietary/energizer-duo/meta.yaml