Threat Description

Virus:​W32/Bursted

Details

Aliases:Virus:​W32/Bursted, Virus.acad.bursted, Trojan.acad.bursted.u
Category:Malware
Type:Virus
Platform:W32

Summary



A malicious program that secretly integrates itself into program or data files. It spreads by integrating itself into more files each time the host program is run.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



Bursted is a virus written for AutoCAD's embedded scripting language, AutoLISP. It replicates in a separate file, "acad.lsp" that is automatically executed by AutoCAD. It does not affect the actual drawing files. The virus arrives in a file "acad.lsp" that is located in the same directory as the AutoCAD drawing files. When the drawing is opened, AutoCAD will automatically load and execute the contents of the "acad.lsp". The virus copies itself to AutoCAD's Support directory as "acadapp.lsp". The virus also appends the load command to the "acad.lsp" in the Support directory, so the virus will be executed every time when AutoCAD is started. After that the virus will copy itself to every directory as "acad.lsp" from where the user opens AutoCAD drawings.

Payload

The virus hooks three AutoCAD internal commands - EXPLODE, XREF and XBIND - effectively disabling them. Additionally the virus will change the existing BURST command so that it will display the following message:



Detection


Detection in F-Secure Anti-Virus was published on December 4th, 2003 in update:
Database: 2003-12-04_05




SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More