Use ethereal, nmap, router logs. This way you can know exactly what its doing where its connecting. Also remove the virus from startup registry keys and find the executable and use ollydbg to see whats inside =D