Yeah, worms are virus-ish infections that spread from computer to computer without you actually being involved. If you plug a "raw" Windows installation into a broadband Internet modem without any firewall to keep the computer from "talking to strangers," eventually a random worm-infected computer somewhere out on your broadband connection will stumble across your computer's IP address, probe it, get a reply, and go "hey kid, want some candy? :evil:" and your computer will take the bait and get itself infected with the Sasser or Blaster or Nachi worms, or maybe several... whether you ever fired up a browser or not.
So a firewall, either the software kind or the hardware kind, is the best single countermeasure when you've got a "raw" computer to protect. It regulates what computers your computer is allowed to talk to, and what types of data traffic it should or shouldn't acknowledge or accept. It's like a security guard at a building... it doesn't search your bags, it just verifies that you're a person who should be allowed into the building.
If you can pre-download the whole Service Pack 2 installer for WinXP, that includes an acceptable software firewall plus it fixes the holes that the worms are trying to exploit in the first place. If you do have broadband, then adding a hardware firewall (a router like a Netgear RP614 or Linksys BEFSR41) is a nice "outer" firewall to supplement your WindowsXP SP2 software firewall.
If you're stuck on plain dial-up like me, then use just a software firewall. If you don't have enough bandwidth to go get the whole Service Pack 2 installer, get free basic ZoneAlarm and maybe that Update Rollup 1 patch kit I have a link to. That will give you good firewall protection and also patches the important holes that the worms are looking for, as a starting point. Also, if you're on dial-up, you can order a Service Pack 2 CD-ROM from Microsoft at no charge, mine arrived in about three days
Hope that helps
