The Energizer Bunny infects PCs with backdoor malware, the Department of Homeland Security’s US-CERT said friday.
According to researchers at US-CERT, software that accompanies the Energizer DUO USB battery charger contains a Trojan Horse that gives the hackers total access to the Windows PC. So far, the Energizer DUO has been discontinued. The company has not said how the Trojan made its way into the software, however. “Energizer is currently working with both CERT and U.S. government officials to understand how the code was inserted in the software,” Energizer said in a statement.
The Windows software included with the charger is designed to show battery-charging status. When the software is installed, it creates the file “Arucer.dll,” which is actually a Trojan that listens for commands on TCP port 7777. Upon instructions, the Trojan can download and execute files, transmit files stolen from the PC, or tweak the Windows registry. The Trojan automatically executes each time the PC is turned on, and remains active, even if the Energizer charger is not connected to the machine.
US-CERT urged users who had installed the Energizer software to uninstall it, which disables the automatic execution of the Trojan. Alternately, users can remove the Arucer.dll from Windows’ “system32″ directory, then reboot the machine.