carbheatcold,
XP's built-in firewall only stops attemps by external attacks on your computer. If you get a trojan or one of the many email viruses that initiate a connection from your computer, it will do nothing. This is why it is better to use Zone Alarm, Norton Firewall (properly configured) or another third party firewall.
Microsoft is strengthing the firewall in the XP Service Pack 2 release coming out this summer, but it remains to be seen exactly how far they take it.
goates