Thanks for the efforts and help!
I've enclosed a copy of open ports when the server I believe is compromised is attached to the internet (via a Linksys router, for now).
I'm not sure about which ports the SME uses for mail, but it seems to me that this is "proof" that there's some kind of unwanted activity going on.
I'm not an expert, so advise here is highly appreciated, once again.
I've used E-smith/SME since 4.1 (or thereabout), but never had any problems. I've installed on a lot of machines and sometimes had to do complete restore for various reasons, but am now very in doubt if it is wise, or any use at all to restore to a "fresh" machine if the "old" machine in fact is compromised.
I only have 10 users, but approx. 8GB worth of email that I really want to transfer somehow, but don't know how to procede ...
Terje
Active tcp connections tcp with external(blue)/local(green) connections highlighted
Local IP:port Foreign IP:port State
192.168.1.195:www 192.168.1.106:3408 ESTABLISHED
192.168.1.195:www 192.168.1.106:3407 TIME_WAIT
192.168.1.195:60091 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60089 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60088 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60086 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60085 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60084 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60083 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60082 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60081 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60080 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60079 64.68.123.249:smtp ESTABLISHED
192.168.1.195:60078 64.68.123.249:smtp ESTABLISHED
192.168.1.195:59802 47.129.25.87:smtp LAST_ACK
192.168.1.195:59803 47.129.25.87:smtp LAST_ACK
192.168.1.195:59801 47.129.25.87:smtp LAST_ACK
192.168.1.195:59790 47.129.25.87:smtp CLOSING
192.168.1.195:60039 64.157.4.78:smtp ESTABLISHED
192.168.1.195:60076 64.157.4.78:smtp FIN_WAIT2
192.168.1.195:60069 64.157.4.78:smtp ESTABLISHED
127.0.0.1:http-admin 127.0.0.1:60090 ESTABLISHED
192.168.1.195:58022 193.17.41.44:smtp ESTABLISHED
192.168.1.195:58074 193.17.41.44:smtp ESTABLISHED
192.168.1.195:60017 210.80.199.74:smtp ESTABLISHED
192.168.1.195:60024 210.80.199.74:smtp FIN_WAIT2
192.168.1.195:60025 210.80.199.74:smtp ESTABLISHED
192.168.1.195:58043 193.17.41.43:smtp ESTABLISHED
192.168.1.195:58041 193.17.41.43:smtp ESTABLISHED
127.0.0.1:60090 127.0.0.1:http-admin ESTABLISHED
127.0.0.1:60087 127.0.0.1:http-admin TIME_WAIT