When I was updating the exchange server, I found some weird name that was logged on the server. It says NYA, but no full name. There's no suck person named NYA in the office. I disabled the account and found some other weird 3 worded accounts. The accounts are not domain admins, but the exchange server's terminal server manager says there's NYA that was logged on to the server but disconnected.
My guess is that the server is hacked, but how can I find if they put a back door software on the server?