Threat Description





X97M/Jini is an Excel 97 macro virus.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.


You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.

Technical Details


This is a Excel macro virus that infects by copying the contents of workbook and it relies in a password protected module.

When an infected workbook is opened, the virus creates an infected workbook "shn.xls" to the Excel startup directory.

The virus does not infect if the name of the workbook start with "Book".

The payload activates when the system has been infected for thirty days. At this time the virus chages the names of items in the "File" menu to following:

After that the virus starts to show random message boxes at random times. These message boxes contain one of the following texts:

  Is it your birthday
 How old are you
 Shala La La La La, Shala La La La La
 What is the play and what is my part ?
 I wonder if you are attaced by a virus...
 Life is Beautiful
 Take games as your life but do not take life as a game

Variant:Jini.A1 (Jini.corrupted)

This is a corruption (misdisinfection) of the original X97M/Jini.A, that is able to replicate.


F-Secure Anti-Virus detects and disinfects both, X97M/Jini.A and X97M/Jini.A1.

Description Created: F-Secure; November 2000
Technical Details: Katrin Tocheva and Sami Rautiainen


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More