You'd trust a compromised machine to report on the traffic that some known malware is sending out?  I have this great deal on Florida swampland for you.... :-)  Also, Jim wanted to do the monitoring from the Linux side.  But if you're stuck on a Doze box, sysinternals is a reasonable substitute for standard tools.

--
Matt G / Dances With Crows

'ZACKLY! 

Much better to monitor it from outside the infection.

:)

Jim