I conformed that Internet mail provider is doing the newsgroup reading with Thunderbird and then looking at my Sygate firewall traffic log.
AshMaiSv.exe is getting a log entry to remote client TCP port 119.
To have a more firm confirmation, you can open the Customize window and tick the checkbox 'Insert note into the clean inbound news' in the NNTP-tab.
Something like this will be written to the new messages:
---
avast! Antivirus: Inbound message clean.
Virus Database (VPS): 0510-0, 08.03.2005
Tested on: 11.3.2005 10:35:18
avast! - copyright (c) 1988-2005 ALWIL Software.
http://www.avast.com