[Warning] Malicious file masqueraded as a picture of Kim Jong Il's sister

1. Information

December 21, 2011, INCA Internet's Emergency Response Team detected malicious file related Kim Jong Il's death.
Due to the time difference, our team is fortifying our emergency monitoring for overseas spreading.
In the midst of this atmosphere, we detected malicious file disguised as his sister(Kim Kyung Hee)'s picture.
Therefore, users need to be careful on using internet.

This malicious file is also showing Kim Kyung Hee picture, and it installs additional malicious file secretly. With the death of Kim Jong Il, various types of malicious files is continuously emerging.

INCA Internet Security Response Center's Emergency Response Team has detected various variants, and based on our analysis, attackers seemed to try to bypass against Anti-Virus Software.

Not only the picture of her, we found another malicious file disguised as a PDF file with the death of Kim Jong Il on December 22, 2011.

The biggest feature of this case is using social engineering and social psychology. If infected by this kind of malicious file, victim's PC can be controlled by attacker.

[Warning] Additional malicious file disguised as the pic of Kim Jong Il (Update #1)

[Warning] Kim Jong Il Malicious scam is spreading(Update #3)

[Caution]Malicious file is spreading via a Korean entertainer's porn video file.

With continuous appearances of Kim and his family related malicious files, general users need to be careful not to be seduced about those files including phishing, attachment of e-mail, unofficial news, suspicious link, or Shorten SNS URL.

It was on December 20, 2011.

Especially, be careful on attachments such as PDF, DOC, HWP, PPT, ZIP, EXE, or SCR.

2. Malicious file with a picture of Kim Kyung Hee

Our team detected additional another malicious file disguised as Kim Jong Il's sister on our monitoring.
When this malicious file "Kim Kyung-hee.scr" is executed, it will create Kim Kyung-hee.jpg and msrt.exe on Temp folder and will execute.

msrt.exe is self-extractable RAR file, which will extract wship6.tmp, server.exe on Local Settings folder. And it will change server.exe to chksrv.exe.

As user just can see the following image, victim can't notice of being infected.

3. How to prevent

To use PC safely from security threats of these malicious attachments, we recommend you download latest security updates and obey following "Security management tips" for general users.

Security management tips

1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.

INCA Internet (Security Response Center / Emergency Response Team) runs responding system against various security threats.


  1. I think I will try this guide soon. I want to save my PC and prevent these problems.

  2. APK Uncle is your best download answer for Android Apps and Mobile Software. Peruse the most recent news about Technology, Android APKs, and Gadget News just on apkuncle.com


  3. Download Updated versions of all types of Apks like App store APKs, Messaging APKs, Popular APKs, Software APKs, and Streaming APKs from Apkmist.
    Apkmist Download
    WhatsApp Plus APK Download
    YOWhatsApp APK Download
    WhatsApp Business APK Download
    GBWhatsApp APK Download
    OGWhatsApp APK Download
    FMWhatsApp APK Download

  4. If you are in search of best writers team those who take complete responsibility of your assignment help needs. All you need to do only is to reach out to our IdealAssignmentHelp. Here you will get all types of academic writing service experts and avail the best of assistance at affordable prices. Our professional writer experts are available every minutes to help you with whole assistance related to your educational and My Assignment Help! Scroll now for more details!

  5. This comment has been removed by the author.

  6. Thanks for sharing the article. It is really valuable Information and I am impressed by your article. Keep doing such great work.
    Visit : marriage delay mantra | divorce problem solution astrologer

  7. It's nice to see your writing, which is exactly what I need, it's very detailed

  8. There are many theology & religion coursework writing services and Religious Research Writing Services to choose from for those stuck with their religion assignment writing services and theology essay writing help services.

  9. Public relations research writing services are very difficult to complete and many students are always searching for Public Relations Writing Services to help them complete their public relations coursework services and public relations research writing services.

  10. This is really very interesting . I have got this warning of malicious file a few time ago and I was very afraid of formatting my system and I then forget to do the assignment help which was the important thing to do at that time.. Well, everything is normal now under assignment help Sydney as well as very admiring Assignment Help Brisbane at afforsdbale price.s

  11. Wales publications are well-known publishing solution providers in various disciplines in the UK, Wales Publications serving to scientific organizations worldwide. Contact us for further information and know our best services and deals to achieve your goal.The fast submission process includes rapid publication research in UK that includes unique rapid process, inhouse peer review and 100% acceptance guarantee.

  12. If you found any minor or major issue in Quickbooks software, you can download QB Tool which is the combination of all essential tools in single application. Rather than download individual tool, you can use this tool to save your time.
    Quickbooks tools hub

  13. This comment has been removed by the author.

  14. Many college and university students in the USA and UK are looking for top and essay helper free. We offer the preeminent academic writing company for pupils who want to surpass in their educational career. We are well-appointed with specialized experts who will write remarkable academic projects for you which will give you certain approvals from your tutors. We will always supply your essay assignments on time. We have 24/7 customer assistance that will benefit you anytime you requirement help.

  15. Very interesting post. I am visiting this site for the first time. I found so many interesting stuff in your blog especially on the comments side. Thank you for sharing this informative post.
    Once the QuickBooks user clicks the OK button on the error message window, the system displays “Could not print to printer. Check your printer selection. Printing may have been cancelled from another program”. With QuickBook Customer Service, you will be able to know QuickBooks error code 20 causing factors and its troubleshooting method.

  16. Remember that bad credit personal loans guaranteed approval are aimed to be used for one or two weeks only till you get your monthly income. You are recommended to stick to the responsible borrowing and apply for the amount you will be able to pay back within the short same day cash advance guaranteed period of time not to have any additional fees.

  17. موقع تحميل واتساب بلس ضد الحظر whatsapp plus تنزيل تحديث واتس اب بلاس جميع نسخ تطبيق واتس اب بلس الذهبي gold. تطبيق واتساب عمر باذيب obwhatsapp نسخة ذهبي المطور ابو عرب. والازرق للمطور ابو صدام الرفاعي gbwhatsapp.

  18. Quickbooks file doctor is a company file issue detecting tool that is also capable of rectifying the said issue. Quickbooks file doctor scans the company file in which you are facing the issue and then repairs the company file.
    If you want to Download Quickbooks file Doctor follow the link given above.

  19. You are very articulate and explain your ideas and opinions clearly leaving no room for miscommunication.
    Akshi Engineers Pvt. Ltd. Company offer a wide range of Automatic Bending Machine Manufacturers in India. These are highly appreciated for automatic control part, stable property, high precision, cost effective and reliable performance. Our wide range of machine is especially designed for high volume production and produces wrinkle free, clean and repetitive bend pipes.

  20. I appreciate you spending some time and energy to put this content together. I once again find myself personally spending a significant amount of time both reading and commenting.
    I am Bella Brownz From Las Vegas and I am working in an NGO for many years. If anyone looking for Assisted Living Homes Colorado so then suggests you The Gardens Care Homes as per your requirement. This Organization assists citizens of Colorado in better comprehending adult daycare, assisted living, and home care costs throughout the state.

  21. You are very articulate and explain your ideas and opinions clearly leaving no room for miscommunication.
    Akshi Engineers Pvt. Ltd. Company offers a wide range of HOT ROLLING MILL Manufacturers in India. These are highly appreciated for automatic control parts, stable property, high precision, cost-effective and reliable performance. Our wide range of machines is specially designed for high volume production and produces wrinkle-free, clean, and repetitive bend pipes.
    Hot Rolling Mill Manufacturer in India
    Mill Stand
    Gear Boxes Manufacturer in India
    Flying Shear
    Drives & Automation Manufacturers