Hi...
everyday it's a different user.

I have seen two type of spammer caused for a vírus:

1 - The user start sending spam from the server from smtp
2 - The e-mail information go to a database and spam start like an attack from zumbis

Both of cases they are making spam from the user e-mail authentication.

I can only catch it when server is overload, /var partition is 100% (from thousend of messages that stay on there becouse hour limit)

My question is.. how is the best way to detect and block thouse spam attacks?