Virus Sending out Spam
Posted on 2010-09-21
I've got a client that may have a virus on one of their PC's sending out Spam. They have an off-site Spam filtering service that generates reports and shows Spam outgoing every night from about 11:00 PM to 8:00 AM. All their log shows is it coming from their Outside interface not specifically which PC. It does block the outgoing Spam but we're concerned it may be a virus. I've run their Trend Antivirus and Malwarebytes scans on all PC's and didn't find anything.
I had this same problem with another client but they had a Watch Guard Firewall that had a realttime log you could watch and refresh and I just watched it for a few minutes and saw traffic on port 25 from a specific IP address that wasn't their mail server and was able to find the PC that way.
This client doesn't have that. I waswondering if there is some simple program out there I could install that would monitor their network for SMTP traffic and generate some sort of log. I've looked at programs like PRTG but I don't have 3 weeks to learn how to interepret the data it appears to generate. I just want to isolate which PC is sending out email traffic in the middle of the night. Is there anything like that available?