I think you need to pin-point where on your network this traffic is coming from? Specifically you need a MAC and what port on your switch the traffic is coming through. If you truly have that computer physically disconnected from the network, then it would not be coming from that computer. You said you're seeing traffic from the computer about every two hours, well are you leaving the computer completely disconnected long enough to know 100% it wasn't being logged when you reconnect it?
Without being able to see the firewall logs and some wireshark captures, then it's pretty hard to say. Based off the little we know, it does sound a little like a spoof of sorts, but I would not say that for certain as there could be a lot more going on than what you're explaining.
Your first post made it kind of sound like a physical setup, but I better ask. Is this a virtual machine and VM-firewall setup or physical systems?