It seems your firewall is open for incoming on 9001 , it should be closed, its only required at the AIM server level
This is exactly what happend to me, a foreign IP address in Iran was making periodic connections on port 9000. Becuase it was intermittent it was hard to make the discovery. But when I kept refreshing netstat (like watching paint dry) the scum bags were exposed.
The problem here is AIM will not reconnect if the port was hijacked for a brief moment by something else . This bug should be sorted out