1: You definitely, under all circumstances need a hardware firewall. Most routers do include one, that's fine - software firewalls are not enough.
2: Do not mess with your firewall. No eMule, no bittorrent, no IRC, never open any ports permanently.
3: Given that you have a fine working hardware firewall you don't need a software one. Waste of resources.
4: The only three websites that you let perform ActiveX commands on your machine is the windows update server, the kaspersky free virus check and the TrendMicro free spyware scan. For anything else Internet Explorer/ ActiveX is OFF LIMITS. Two browsers are safe: Opera and firefox, if you install NoScript.
5: Microsoft Outlook is off limits. Use Thunderbird.
6: Deactivate autoplay for inserted disks. (Remember the Sony rootkit?)
How to:
www.xp-antispy.org
7: Deactivate services that enable remote control of your machine.
How to:
http://www.z123.org/techsupport/xpservices.htm
8: Have a look at
www.diamondcs.com.au/
9: Always open downloaded/ unknown files with a right-click: "open with"
That should be safe enough. I'm not even having anti-virus installed in the moment. If you have the power and RAM, get the latest kaspersky. On the other hand, if you're using IB you better not, because TWS is using the command interface and that will give you permanent security alarms.