If you find something on your system, either in your logs or running that is suspicious/definite. The best thing to do is immediately remove the system from the network and get the word out. The reason for this is that if a singe machine is affected on the network, it becomes the perfect bouncing off point to attack other machines. Things like mail which will deny many services to off campus use will no longer matter; but if the machine is not one the network all is well.
Here come some links and examples of logs etc...
A concatenation of logs with attempted imap attacks, portscans, pop attacks, telnet and rlogins.
Lots of concatenated telnet requests from some moron.
Sentry, a portscan scanner
ssh
Other cool toys
Rootshell, script kiddie land