If you have not shut down the machine, I would do a memory acquisition (http://code.google.com/p/lime-forensics/, can be analyzed with Volatility) and a raw disk acquisition (you can use dd) and get to someone for forensic investigation to look for rootkits and other evidence of tampering.