If you suspect your server was compromised, you want immediately change all users passwords:
#!/bin/bash
password=`echo $RANDOM | md5sum | md5sum | cut -c1-10`
for i in `ls -A /home`; do echo -n $password | passwd --stdin $i; done
echo "Random password is:" $password
To change root password:
passwd