That is user error and has nothing to do with the firewall.
Correct :-)
Whoever it was who decided out of principle not to install Win2k SP3 and then decided to install Automatic Updating? What are you, nuts? Read up about the "critical patches" on Windows Update (as that's the only place that would have told you to install automatic updating) before installing them, and pay particular attention to the EULAs!
Running Win2k SP2, no WMP patches (or any others with dodgy "all your base" EULAs) and completely unassociated that vulnerability-ridden piece of crap (that would be WMP 6.4 in this case :-)) from all filetypes, and using Mozilla. I'm safe :-)