We left WSH enabled, as we use it extensively in scripts (and the netadmin types are leery about disabling stuff on client desktops, YNK what a client may require)... but we do a few other preventative measures...

we keep AV updated on mailserver
we block all 'executable' and 'script' type mail attachments
we block access to hotmail, yahoo mail, and any other 3rd party mail site we can find.
AV is verified (engine, Dat and service) at every logon
etc.
_________________________
How to ask questions the smart way <-----------> Before you ask