There are some nasty people running around exploiting a security hole in My_eGallery http://lottasophie.sourceforge.net/ . All those running phpNuke sites should check for this and disable it IMMEDIATELY until it can be updated to a non-exploitable version. This has been around for a while, but just starting to see it more and more. To search for installations of My_eGallery: locate My_eGallary If you find it, disable the directory with: chmod 000 /path/to/site/modules/My_eGallery/ Then check your /tmp directory for "friends".