Hello,
First of all, I'm newbie. Server is Debian with Apache, MySQL, SMTP, DHCP (LAN of 15 computer

. I'm trying to look for virus/trojan network activity on a network of Windows clients. Can you tell what I shoud look for? What I know is just how to get to /var/log ...