Maybe some forensic analysis will help you for this case. For example,1) Since you can see it in netstat, check the port which it is using .. then you can use TCP view to check which process is using the port.
http://www.sysinternals.com/ntw2k/utilities.shtml
2) you can also use pstools to check process, trace dlls info on your system.
http://www.sysinternals.com/ntw2k/freeware/pstools.shtml
(more...)
3x, will try