You need to block port 135 inbound (both UDP and TCP).
However, since your firewall setup doesn't seem to be doing its job, I would
put it back to its default setting of blocking everything and start again.
A NAT router will provide more protection. However, it only provides
protection from connections coming inbound. If you download (conciously or
uncounciously) a pice of dodgy code (via an ActiveX control on the web or by
opening an infected e-mail, for example) you wont have protection. For a
home network, such a router along with a software firewall is about as good
as it gets. Proper hardware firewalls are not cheap.
However, software firewalls are only as good as their configuration and
yours doesn't seem to be configured correctly at the moment.
Regards
Oli