depends.
if they installed some software that "phones home" before the firewall was turned on.
When the firewall is turned on it would stop new connections/hacker attempts getting at the machine, the software that the cracker installed could contact the hacker going out from the machine and they would still have access to the computer.
if the software needs to be connected via an incoming connection then the firewall could stop that connection, dependant on the rule base.