@master: what symcbean is saying is that you most likely have a hole in your web code: be it cgi, php, perl or some bundled package, such as phpmyadmin, mysql, or other popular control panels/software tools. while restoring your data onto a clean system is a good thing, you should be looking for holes in your code that the attacker may have used to gain access to your system in the first place, or