We are having reports of traffic coming from the public address of our BM
box to port 445 on various address. Looks like a host here has a worm on
but as far as I can see we have no exceptions to let traffic out to 445.

Is there any way to trace from the BM box to the originating (private)
address ?

Plus, is there a quick way I can check outgoing to port 445 ?