1- analyze ur /etc/passwd for new users
2- analyze the same file for a root backdoor by making a copy of the ID of root to another user.
3- check ur net traffic.
4- check for unusual file...