Threat description



WM/Mentes is a Word macro virus. This virus activates when an infected document is opened. Then it infects the global template and every document opened thereafter.


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

When a document is closed, the appends the name and path of the active document, date, time and the contents of the document to a file "C:\Login.sys". The file is created if it does not exist.

Then the virus attempts to connect "\\HS_WORK\COMMON\STUDIENT\TEMP" network resource. If the connection is established, the virus moves the "C:\Logo.sys" file to first logical drive starting from "D:", where it can write. The file is renamed to "Archive.a##", where "##" represents a number between 10 and 50.

The virus replaces the "Tools/Macros" menu with a message box:

Macro function is not installed.


Submit a Sample

Suspect a file or URL was wrongly detected? Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info