Yup, random port scan by the worm. Check out blaster and Sasser, they would infect that machine you speak of, giving that it isn't updated. They exploit services that open ports, and gain privledges...