I'm having the exact same issue. The following 4 services are in french, same version of WinXP.
Mise a jour automatique = Automatic Updates
Centre de securite = Windows Security Center service (wscsvc.dll).
Pare-feu Windows / Partage de connexion Internet = Windows Firewall / Internet Connection Sharing
Service de transfert intelligent en arricre-plan = Background Intelligent Transfer Service
One difference is that in my registry, Control Set 001 is correct and the others are in french. Also, I was noticing that my internet connection seemed to be lagging and found out Windows Firewall re-enabled itself even though it was disabled, and I was using two firewalls simultaneously. I have not used Windows Firewall in over a decade and have been using Comodo Firewall for about 8-9 years now. I do not use Windows Update/Automatic Updates either.(disabled)
I was poking around Event Viewer and I found this in the Security tab:
Event Type: Success Audit
Event Source: Security
Event Category: Policy Change
Event ID: 849
Time: 8:20:09 PM
User: NT AUTHORITY\SYSTEM
An application was listed as an exception when the Windows Firewall started.
Policy origin: Local Policy
Profile used: Standard
Name: Logiciel de transfert de fichiers
Scope: All subnets
Notice how the name (Logiciel de transfert de fichiers) is in French? In The system32 folder, the ftp.exe program is the correct English version. I wonder if this is some sort of backdoor way of installing malware via the ftp ports? In my Comodo firewall log, I see IP addresses trying to access port 21. Fortunately, these IP addresses were blocked.
I would disable the 4 services if you haven't, until we can find a solution. Have you tried System Restore yet? I have, and all my restore points fail.