1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar







WM/Mentes is a Word macro virus. This virus activates when an infected document is opened. Then it infects the global template and every document opened thereafter.

Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.

Technical Details

When a document is closed, the appends the name and path of the active document, date, time and the contents of the document to a file "C:\Login.sys". The file is created if it does not exist.

Then the virus attempts to connect "\\HS_WORK\COMMON\STUDIENT\TEMP" network resource. If the connection is established, the virus moves the "C:\Logo.sys" file to first logical drive starting from "D:", where it can write. The file is renamed to "Archive.a##", where "##" represents a number between 10 and 50.

The virus replaces the "Tools/Macros" menu with a message box:

Macro function is not installed. 

Technical Details: Sami Rautiainen, F-Secure

Submit a sample

Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Scan and clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free