Worms are most likely not criminal activity on behalf of the host connecting to your HTTP server. They probably don't even realize their server is infected.
Nowadays I just ignore the IIS worm crap that hits my servers. There's just no right way to handle them.
"There are finer fish in the sea than have ever been caught." -- Irish proverb