The Zero-Day Bug Part II

The good news is that this virus, also known as Exploit-WMF is detected by most major antivirus software with the latest updates. McAfee’s 4661 update, released yesterday, detects and blocks the flaw. Symantec says that there software detects and reports the issue, but does not specifically say if it blocks it. Computer Associates does not yet appear to have a response for this. TrendMicro says that they will have one available soon.

There are a few other workarounds for this. One is to unregister the Windows Picture and Fax Viewer by doing the following:

1. Go to the Start menu and choose “Run”

2. Type the following in the run line:

regsvr32 -u %windir%\system32\shimgvw.dll

(In this case “%windir” refers to your Windows directory, usually C:\Windows. So you would want to type regsvr32 -u C:\Windows\system32\shimgvw.dll)

3. Hit the “Enter” key

This disables the Windows Picture and Fax Viewer, so if you use this method you should expect that it will not work until you re-register it.

The best option is to make sure you have antivirus software protecting all you computers and that they are always using the latest virus definition updates.

Leave a Reply

You must be logged in to post a comment.