Maybe some forensic analysis will help you for this case. For example,
所在版块:技术の宅 发贴时间:2004-06-16 07:52  评分:

高亮: 今天贴 X 昨天贴 X 前天贴 X 
1) Since you can see it in netstat, check the port which it is using .. then you can use TCP view to check which process is using the port.

2) you can also use pstools to check process, trace dlls info on your system.

 相关帖子 我要回复↙ ↗回到正文
很郁闷的中了一项t很神奇的病毒 快快跑   (716 bytes , 322reads )
which navscanner32 Flying   (0 bytes , 214reads )
BTW, 'which' is assuming cygwin. Flying   (126 bytes , 226reads )
Maybe some forensic analysis will help you for this case. For example, Rick   (497 bytes , 332reads )
3x, will try 快快跑   (0 bytes , 198reads )