Edit: This is a post of the phantom forum. It provides various solutions. Please take a look at the solution.
In view of the rampant wmf horse and phishing methods, Microsoft has not provided any patches, and now provides a temporary solution.
1.regsvr32.exe/u shimgvw. dll
Run the command to prohibit wmfexecution. Generally, regsvr32.exe is under system32. If not, search for it by yourself.
2. The above method can only prevent the vulnerability from being triggered by calling the Image Viewer via IE, which can be used in the same way as other methods.
I provide my temporary solution
Kill SFC first, and try to solve this problem.
Open gdi32.dll with Uedit32 and search for 53 57 ff d0 85 c0
Change to 33 c0 90 90 85 c0 and restart
Windows 2003 SP1 is successfully tested.
3. The simplest way is to install ACDSEE. It is simple and effective... Haha
4. Official solution:
Html> http://www.enet.com.cn/article/2005...230488781.shtml