If you have a doubt that your server has been compromised, not only you should change your password, but you should reinstall the server from scratch and known good backups.
My root password is a small word.
Not a good thing... make it a long password with different characters (alpha numeric + special characters).
-- Ghislain Bourgeois --- Linux System administrator