After changing the authentication method, you have to bounce the POP virtual server for the change to take effect. No need to reboot the whole exchange server, just stop / restart the POP3 virtual server and I bet that fixes your problem. Unless you have a cert on there or the smtp server is requiring TLS or something like that.
As for your smtp server showing sessions, there are security settings you can apply to help with that, but they won't do any good if the outside party has compromised a valid password. One thing to look at, verify in those sessions how long they've been connected for one thing - if it's just a few seconds and then they're getting bounced, they're just fishing around and not doing any good. If you see someone connected for 10 min, for example, that is indeed a problem.
But you're right, first thing's first. Lets get your email flowing properly, and then we'll go from there.