Well, I'm getting mixed reports no matter where I go.

The well known ports list says blackjack.

Others say that ports 1025-1026 are needed to communicate with the domain controller which is using the DNS Client service. (RPC)

Some say (blackhats) that 1025 is used by the AT service. (task scheduler)

Killing any of those services doesn't close port 1025 for me.
(in fact, they were not running on my machine and I still had 1025 listening on 0.0.0.0)
I have NIS and I have that service blocked for that port. Hasn't caused me any harm as of yet. (crosses fingers)

Run a sniffer and see what kind of data its trying to send.