Hi guys,
I've got a Network that has been infected with some Spyware and it's using port 25 on a user PC so send lots of spam across the net. The user has clicked an Angelina Jolie e-mail (I would have done the same if it wasn't for the fact that it's obviously Spyware and the link ends in .avi.exe

). I managed to capture this traffic coming from his IP through a NAT setting on the router.
The users use the router as their default gateway for direct internet access rather than going through a Server, otherwise I would have set up Network monitor to filter out port 25 traffic. I have tried installing FileMon on this users PC to see if I can see the exe using port :25 but to no avail..
Once his PC was taken off the Network, the flood of random IP addresses with port 25 dissapeared from the router so I can only assume it was this PC, OR maybe the Spyware was relaying through his machine, hense it would be great if somebody could point me in the right direction of tracking down all :25 traffic going around the Network.
Regards,
Luke