I think I’ve finally found the reason for why PC Flank’s quick test reports port 135, 137, 138 and 139 as ‘visible’ and not ‘stealth’.
The reason is because the traffic on those ports is blocked by your ISP. My ISP blocks all traffic on port 135, 137-139, 445 and 1433. By running the advanced scanner with the TCP connect-option, all of them were reported as ‘closed (visible)’ and not ‘stealth’. If I entered another port number, like 80, it was reported as ‘stealth’.
However, using the TCP SYN-option instead shows the blocked ports as ‘stealth’.