There are significant improvements to flow antivirus in FortiOS 5.2 and it is as good (or nearly so) than proxy antivirus now.
To answer your questions:
1. Technically, yes you can, but not on the same rule.
2. At least on FortiOS 5.2, the default is the extended DB and yes it is supported with flow mode
3. From the FortiOS Handbook: In most circumstances, the regular virus database provides sufficient protection. Viruses known to be active are included in the regular virus database. The extended database includes signatures of the viruses that have become rare within the last year in addition to those in the normal database. The extreme database includes legacy viruses that have not been seen in the wild in a long time in addition to those in the extended database.
Now while you *can* have proxy and flow profiles on different rules in the same policy, it is best practice not to mix flow and proxy profiles. In 5.0 the decision was harder but in 5.2 my solid recommendation for most environments is to use flow mode. Flow mode takes far less resources on the box and not having to use proxy means fewer moving parts (less chance for things to go wrong) and also you no longer have to worry about size limitations of the file to be scanned.
Hope this helps.
Cheers!
--
Sean Toomey, CISSP FCNSP
Consulting Security Engineer (CSE)
FORTINET— High Performance Network Security