Today at work we are having problems with "Viruses/spyware/stuff" and I am wondering what I could setup in linux to say passive/active scanning a network for viruses/spyware/stuff. And stuff that looks for viruses/spyware/stuff trying to connect to ports it shouldn't be. A packet sniffer would probably be one thing, my I don't know enough about tcp/ip/udp/stuff to work it and understand what it is showing me. I guess I might have to start reading up on packet sniffing. So tools I think might be good ethereal, snort, nmap.
Thanks,
JtotheO