Solved. It appears that two machines on my network had Sasser. The reason the connections weren't showing in netstat was because I just wasn't using the right switches. This is my gateway device, and also NATs my private IPs. I needed to issue netstat -M to show masqueraded connections. As soon as I did that, it showed me the internal IPs that were scanning for 445. I patched and cleaned them, and we're back in business. Thanks for your time, everyone.