Security :: Detect Infected PC In LAN (Sending Packets To Internet)

In my network I have 25 workstations and some serves. Everything working in local LAN with firewall. The problem is that on one machine (I dont know which one) is installed software which sending data to the internet. Actually I dont know what it is. Last time as I remember was trojan which can create new network interfaces in windows and send some data to the internet. The half speed of my network connection is used by this infected machine. How can I detect which machine it is? How can I listen/capture some traffic and analyze from which machine I have more connections.

Please take a look on this time. Instead of 141-150ms should be 4-5ms.

64 bytes from (62.xx.191.74): icmp_seq=1 ttl=249 time=141 ms
64 bytes from (62.xx.191.74): icmp_seq=2 ttl=249 time=135 ms
64 bytes from (62.xx.191.74): icmp_seq=3 ttl=249 time=147 ms
64 bytes from (62.xx.191.74): icmp_seq=4 ttl=249 time=127 ms
64 bytes from (62.xx.191.74): icmp_seq=5 ttl=249 time=156 ms
64 bytes from (62.xx.191.74): icmp_seq=6 ttl=249 time=129 ms
64 bytes from (62.xx.191.74): icmp_seq=7 ttl=249 time=188 ms

How can I detect which machine is infected using only linux and keyboard ?

