Virus:W32/Bursted

Classification

Malware

Virus

ACAD

Bursted, Virus:W32/Bursted, Virus.acad.bursted, Trojan.acad.bursted, Win32.acad.bursted, Trojan.Lisp.Bursted

Summary

A malicious program that secretly integrates itself into program or data files. It spreads by integrating itself into more files each time the host program is run.

Removal

Automatic action

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

Bursted is a virus written for AutoCAD's embedded scripting language, AutoLISP. It replicates in a separate file, "acad.lsp" that is automatically executed by AutoCAD. It does not affect the actual drawing files.

The virus arrives in a file "acad.lsp" that is located in the same directory as the AutoCAD drawing files. When the drawing is opened, AutoCAD will automatically load and execute the contents of the "acad.lsp". The virus copies itself to AutoCAD's Support directory as "acadapp.lsp".

The virus also appends the load command to the "acad.lsp" in the Support directory, so the virus will be executed every time when AutoCAD is started. After that the virus will copy itself to every directory as "acad.lsp" from where the user opens AutoCAD drawings.

Payload

The virus hooks three AutoCAD internal commands - EXPLODE, XREF and XBIND - effectively disabling them. Additionally the virus will change the existing BURST command so that it will display the following message:

Date Created: -

Date Last Modified: -