I was scanning through the RAS logs and I saw an attempt to logon by a user who is no longer with the company. I talked to the person whose user ID it was and she says that it wasn’t her, futhermore doing a WHOIS on the IP address shows that it is coming from out of state. I was wondering how I can investigate to see if my system was compromised and if I should report these failed logon attempts to the authorities? Any suggestions would be appreciated.