When you got infected, did you find any new programs installed, or was it just your XP's RPC crash and reboot? I think it was the Blaster worm, it had bad coding and couldn't deliver its payload.
Looking at my nlite.ini, my XP ISO removes IIS, NetBios, and for removed services Messenger, Network DDE, Remote Registry, Service Advertising Protocol. I'll send it to you if you'd like to check out all the tweaks such as closing port 445 for TCP/UDP (Microsoft-DS)
because I haven't gotten any worm infections during no AV or firewall.