The XP Firewall and Router won't make a blind bit of difference if malware is already inside the system. Routers may well have inbound firewall protection, but unless they state that they have outbound protection (most don't) then you could have a security hole.
Any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (sensitive or otherwise, user names, passwords, keylogger retrieved data, etc.) or open a backdoor to your computer, so outbound protection is essential.