I just installed RH Linux 7.2 a week or two ago, so I'm fairly new. In the initial setup, i set my firewall to the "medium" level. Yesterday, I booted up into linux, logged in as root, then left the house for a few hours. I think I had the wu-ftp server running (i think it started automatically on boot-up) and I did not have Apache running. When I came back, i did some command (can't remember) and it said I had mail, so i typed "mail" and read the first message.. it was long, and had various error-type messages in it, and said the final-destination address was "hack3ru@yahoo.com".. i thought that was weird. I then went into my "/Root" (i think) directory, and there was a new folder called "cool" which I hadn't ever created. I opened it up, and there were various files, including a few c source files, and I believe their compiled counterparts. I think one was called pscan, or sscan, or something like that. In the /Root directory, there was a "aw.tgz" file, and a file simply called "a"..... BTW, i opened up some of the source files, and they had various printf's with messages like "back door successful" and "error, possible firewall" and stuff like that. My root password was changed, and I think they were using my computer to access other computers, because my cable modem was blinking like crazy. Now I can't log in as root, and even if I could, I would worry that someone could easily access my computer through those, or possibly other hidden files on my computer. Should I format and re-install linux? I don't want to set it up as a server only to have some hidden back-door thing going on. ANY help would be appreciated, I'm not that knowledgable with Linux yet. Thanks,
-Ryen
-Ryen