Well, I really don’t know what to suggest…
Did the Windows update finished successfully when you managed to connect? Does the firewall show any incoming connections (or, can you limit them somehow)?

Maybe the worm file isn’t actually transferred (the firewall may prevent it), so you can’t see it on disk - but the initial connection crashes the service… but of course, it shouldn’t happen on a patched system. I don’t know… are you sure the patches are OK (correct version, …)