Mentes

Threat description

Details

Category:
Platform: W32

Summary

WM/Mentes is a Word macro virus. This virus activates when an infected document is opened. Then it infects the global template and every document opened thereafter.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details

When a document is closed, the appends the name and path of the active document, date, time and the contents of the document to a file "C:\Login.sys". The file is created if it does not exist.

Then the virus attempts to connect "\\HS_WORK\COMMON\STUDIENT\TEMP" network resource. If the connection is established, the virus moves the "C:\Logo.sys" file to first logical drive starting from "D:", where it can write. The file is renamed to "Archive.a##", where "##" represents a number between 10 and 50.

The virus replaces the "Tools/Macros" menu with a message box:

Macro function is not installed.         




Technical Details: Sami Rautiainen, F-Secure


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More