Infected machines setups a backdoor on port 1034 so scan your systems/networks and firewall logs for this. You could also scan firewall logs for excessive SMTP sends from a particular host (non-mail server).