If you use a software firewall you need an explicit rule for port 135 but if it works is a second...
If you use a firewall and filtering your traffic, u need to block the svchost and some other services from accessing the internet else your port 135 will remain open.
You also can block all internet traffic but when doing that you cannot use internet at all...
Sygate or ZoneAlarm PRO(!!!) are good firewalls... (I prefer Sygate above ZoneAlarm pro)...