• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to block WMF exploit

Myantispyware team December 29, 2005    

For this WMF exploit: Until Microsoft patches this thing or your AV provider has updated defs, here are some tips

1. Unregister SHIMGVW.DLL.

This is your best workaround for the time being (realizing that nothing is perfect).
From the command prompt, type REGSVR32 /U SHIMGVW.DLL. A reboot is recommended. (It works post reboot as well. It is a permanent workaround).
You can also do this by going to Start, Run and then pasting in the above command.
This effectively disables your ability to view images using the Windows picture and fax viewer via IE.
However, it is not the most elegant fix. You’re probably going to have all kinds of problems viewing images.
But, no biggie: Once the exploit is patched, you can simply type “REGSVR32 SHIMGVW.DLL” to bring back the functionality.
And, it is a preventative measure. If you are already infected, it will not help.
Works for IE, should work fine for Firefox users as well.

2. Change file associations for WMF files.

Note that if a WMF file was spoofed to look like it was a different type of file (like GIF), this fix wouldn’t do anything. So it’s a pretty weak workaround. At any rate, here it is:
a) Go to My documents, Tools, Folder Options, File Types.
b) Change WMF Image to notepad and select Always Open with this.
Your WMF files will open in Notepad. Ugly and not as effective as unregistering SHIMGVW.DLL.

3. Run IESPYAD.

IESpyad is a free tool that puts block lists into IE’s restricted sites zone. It’s managed by Eric Howes, who works as a consultant for Sunbelt. Sunbelt regularly update him with the latest URLs. Click here for read more.

thanks to sunbeltblog

Exploits & Vulnerabilities Tips Tutorials - HowTo

 Previous Post

New exploit blows by fully patched Windows XP systems

Next Post 

More info about WMF Exploit

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

Leave a Reply Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

This setting is enforced by your administrator (Removal guide)
Files encrypted by ransomware become useless
How To Recover Encrypted Files (Ransomware file recovery)
Malwarebytes won’t install, run or update – How to fix it
Managed by your organization chrome virus
Chrome Managed by your organization malware removal guide
How to remove pop-up ads [Chrome, Firefox, IE, Opera, Edge]

Recent Guides

New exploit blows by fully patched Windows XP systems
Fake MS Messenger 8 beta
EULAlyzer – Analyze license agreements for interesting words and phrases.
How to remove Winhound
The Adblock project

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.