X97M/Jini is an Excel 97 macro virus.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
More scanning & removal options
More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.
You may also refer to the Knowledge Base on the F-Secure Community site for more information.
This is a Excel macro virus that infects by copying the contents of workbook and it relies in a password protected module.
When an infected workbook is opened, the virus creates an infected workbook "shn.xls" to the Excel startup directory.
The virus does not infect if the name of the workbook start with "Book".
The payload activates when the system has been infected for thirty days. At this time the virus chages the names of items in the "File" menu to following:
After that the virus starts to show random message boxes at random times. These message boxes contain one of the following texts:
Is it your birthday How old are you Shala La La La La, Shala La La La La What is the play and what is my part ? I wonder if you are attaced by a virus... Life is Beautiful Take games as your life but do not take life as a game
This is a corruption (misdisinfection) of the original X97M/Jini.A, that is able to replicate.
F-Secure Anti-Virus detects and disinfects both, X97M/Jini.A and X97M/Jini.A1.
Description Details: F-Secure; November 2000
Technical Details:Katrin Tocheva and Sami Rautiainen