ESMTP is "extended SMTP"; you can look it up on wiki if you actually care to read through it (basically it's your SMTP daemon);
If you don't allow sending of emails through SMTP on your server, you should give thought to blocking port25 on your server.
BTW, just because it's the only thing you can think of, doesn't mean another script on your server wasn't exploited and a user uploaded script was put in place... It's quite common... and it can even be a system level service that was exploited; so go through and check to make sure your'e running up to date scripts and system services.