If you have not already done so, you might want to try installing rkhunter (Rootkit Hunter). It scans for rootkits, backdoors and possible local exploits. It does this by comparing SHA-1 hashes of important files with known good ones in online databases, searching for default directories (of rootkits), wrong permissions, hidden files and suspicious strings in kernel modules.
Maybe installing Jailkit to chroot SSH users might plug a hole for you too. This is a set of utilities to limit user accounts to specific files using chroot() and or specific commands. It is used to secure cvs, sftp, shell or daemon processes. You can give your users shell access without having to fear that they can see your whole system. Your users will be jailed in a specific directory which they will not be able to break out of.
As a future potential preventative, you might want to think about installing fail2ban. It is an intrusion prevention framework. It blocks selected IP addresses for hosts that are trying to breach the system's security by monitoring log files and will ban any host IP that makes too many login attempts or performs any other unwanted action within a time frame defined by the administrator.
These are for Linux, and I’m not an expert with them, so I can’t really walk you through installing or using them, but you might want to look into them and see if they might help you.
If this "Security" stuff is not your cup of tea, these guys might be able to help:
http://www.serverwizards.com/
I have never used them, but have come across a few of their happy "Security" customers in tech forums in the past. I keep them in my contact list just in case.