WEB_CLIENT readme.eml download attempt

 

Code: p1026

Severity: Warning

 

Description: This event is generated when an attempt is made to download a Nimda-infected attachment from a web server.

Impact: Serious. A Nimda-infected web server may have spread the Nimda worm to the web client.

Corrective: Examine the host for signs of infection. Use Anti-Virus tools to clean an infected host. Consider the use of alternative operating systems that are not vulnerable to this kind of attack.