Well I would have hoped that the win7 firewall would have got a look in first, I don’t know if there is any way to ensure that it does. But essentially avast’s network shield is only monitoring those ports that are commonly used for exploits and not a full firewall.

I don’t know if you have restarted avast or the network shield as that would effectively zero the counts. If you are looking at the physical log file, C:\ProgramData\AVAST Software\Avast\report\NetworkShield.txt ?
That has been a bone of contention for some time as there doesn’t seem to be much in there other than the start Date Time Group.