X97M/Jini is an Excel 97 macro virus.
Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.
More scanning & removal options
More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.
You may also refer to the Knowledge Base on the F-Secure Community site for more information.
This is a Excel macro virus that infects by copying the contents of workbook and it relies in a password protected module.
When an infected workbook is opened, the virus creates an infected workbook "shn.xls" to the Excel startup directory.
The virus does not infect if the name of the workbook start with "Book".
The payload activates when the system has been infected for thirty days. At this time the virus chages the names of items in the "File" menu to following:
After that the virus starts to show random message boxes at random times. These message boxes contain one of the following texts:
Is it your birthday How old are you Shala La La La La, Shala La La La La What is the play and what is my part ? I wonder if you are attaced by a virus... Life is Beautiful Take games as your life but do not take life as a game
This is a corruption (misdisinfection) of the original X97M/Jini.A, that is able to replicate.
F-Secure Anti-Virus detects and disinfects both, X97M/Jini.A and X97M/Jini.A1.
Description Details: F-Secure; November 2000
Technical Details: Katrin Tocheva and Sami Rautiainen