Energizer Removes Infected Battery Monitoring Software - InformationWeek
Infrastructure // PC & Servers
04:09 PM
Connect Directly
Moving UEBA Beyond the Ground Floor
Sep 20, 2017
This webinar will provide the details you need about UEBA so you can make the decisions on how bes ...Read More>>

Energizer Removes Infected Battery Monitoring Software

The company says that it is working with U.S.-CERT to determine how the software on its servers became infected.

Energizer Holdings, Inc. on Friday said that it had been notified by the U.S.-CERT Coordination Center that Windows software it had been offering for download contained a vulnerability.

The company said that the software, designed to complement its DUO USB battery charger by allowing users to view battery power levels on a connected computer, has been removed from Energizer's Web site and that the company has discontinued the sale of the charger.

Unlike past incidents in which malware has been distributed with a consumer product, like the infected digital picture frames sold by Best Buy in early 2008, the Energizer DUO USB battery charger does not ship with infected software.

Instead, the product's manual directs users to download the malware from Energizer's Web site.

"Energizer is currently working with both CERT and U.S. government officials to understand how the code was inserted in the software," the company said in a statement.

Energizer is advising its Windows-using customers to uninstall the software, which may require the manual removal of a file, Arucer.dll, which resides in the Window system32 directory.

The company also offers an version of this software that's compatible with Apple's Mac OS X. That version, however, does not contain any known vulnerability.

According to a U.S.-CERT advisory published on Friday, "Arucer.dll is a backdoor that allows unauthorized remote system access via accepting connections on 7777/tcp. Its capabilities include the ability to list directories, send and receive files, and execute programs."

Symantec security researcher Liam O Murchu on Friday published a technical analysis of what Symantec is calling Trojan.Arugizer.

He notes that the name "Liu hong" was found in the code and speculates that this could be the name of the Trojan's creator.

He also says that the Trojan will operate with or without the DUO USB charger plugged in.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
IT Strategies to Conquer the Cloud
Chances are your organization is adopting cloud computing in one way or another -- or in multiple ways. Understanding the skills you need and how cloud affects IT operations and networking will help you adapt.
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll