Karl,
- How often does Avast look for updates when it detects an online connection? I notice that the update check starts within a few seconds after the internet connection is available. When will the next check occur?
The next check will occur in 4 hours, by default. In other words, if you're permanently connected to the Internet, the updating period is set to 4 hours.
- Are the incremental updates merged into the main 400.vps? (I cannot find any other database files in the data subdir...)
Yes, you're right. 400.vps is the avast virus database (the one and only), and all virus database updates are therefore written to this file.
- Why does Avast open port 135 and 1025 as a listening connection?
First of all, I should clearly state that these ports are open for
local connections only, i.e. only connections established on the very same machine (under which you have full control). This is an extremely important point - NO ports are open for foreign hosts.
As for RPC: it's the fact that avast! internally uses RPC to do its job (namely it uses it for communication between its components). But
RPC is a fully documented and supported interface and we believe there is absolutely nothing wrong with avast! using it. The fact that the Windows RPC subsystem opens the RPC net port even if the communication is taking place only on the local machine is unfortunate, but there is really nothing we can do about it (except for stoping using it), but I am confident that the mere fact that the port is open doesn't really mean any security risk...
As for port 1025, I wasn't sure about this one, so tried google and got a lot of matches. Most of the discussion sounded like this:
Port 1025 is the first dynamic port that Windows opens when it needs a
connection. There is usually something that needs to create a connection
or listen for something, so most of the time Win2K Pro has something
active on port 1025.
The second connection uses 1026, the third 1027, etc. If only 1026 is
open, that just means that the first connection was closed.
So, I don't really know...
Hope this helps,
Vlk