Yes, you may need to initiate a connection from the internal network/PCs. However NAT routers may also have running services that can exploited (remote administration/ftp). They may also forward ports to services on the client PC that may be exploited.
Have a look at http://honeyclient.org/trac/wiki/VMHardeningGuide to further reassure you. Although, I would imagine you are ok as it is. The AV on the virtual machine may not let you run malware on it. I usually dont have one for my malware lab.
It should work in C:\Documents and Settings\username\data.txt on XP. Linux would be /home/username/data.txt
Give that a try and report back. If you want to run it against some malicious sites. Just go to google and locate some of the malicious ones are there. Quite a few!
I also use Malware Domain List.... Ensure you are in VM though and hardening has been applied.
Yes, I second that. You will roughly have the character length and possible variations. You obviously entered the pass twice to change it, so you cant be that far wrong. With this in mind you can significantly reduce the required searchable keyspace. So stick with it...
You could also try having a few more beers and trying again. Might get lucky... or unlucky