> My messages file shows "telnetd[21882]: ttloop:  peer died: Invalid or
> incomplete multibyte or wide character" and my tcpdump file shows the
> consistent IP outside intruder as  What exactly
> happened?  Is my system infected, affected, or what?

At this point, without my being able to verify directly, it would seem that
your system is not infected, only being attempted. The very next thing I would
do (as in right now) would be the following steps:

edit /etc/inetd.conf
Comment out the line which mentions telnetd (ie: put a # as the first
character in the line).
Find the process id of inetd (ps aux | grep inetd).
Issue 'kill -HUP psid'

That will shut down that attack, at least. Second thing to do, would be to run
'netstat -a', and see if you don't recognize any of the ports listed. If any
of them are unfamiliar, you MIGHT have been cracked. Only further research
will tell.

I'm going to post my personal firewall ruleset in the very near future, in two
separate versions (one with ipmasq enabled, one without). In the meantime, I
would recommend reading various HOWTO documents (http://www.linuxdoc.org and
http://www.linuxlookup.com), and use the information to beef up your security
tremendously. Having hte telnet port open, and having it enabled, tells me
that your site is incredibly insecure right now, and very easily attacked. I
don't say this to be insulting, only to help you understand that your machine
IS vulnerable right now, and without prompt action, may be cracked very soon
(if it's not already).

Final note for you: Your cracker might be related to another one mentioned by
D. Stimitz(sp?). He also had an oriental origin. Your guy is using a unicode
character set during his attack, which means that he is using (extremely
likely, anyway) an oriental character set.

