Quote:
If you visit a compromised Web server, you will be prompted to download an .eml (Outlook Express) email file, which contains the worm as an attachment. You can disable "File Download" in your Internet Explorer internet security zones to prevent this compromise.
So it depends on your security settings. The default on most Windows machines is "prompt", which means, as you suggest, that you'll be prompted to open the attachment (in the form of an email). Nimda will be attached to this in turn. The proper action is of course to hit Cancel and ignore it.