ok
i mean if you were infected????/
just check your logs and see where the subseven cgi is sending the information . then open the url in your browser and send there some false information.the url seems like this http://domain/subseven.cgi?ip=is your ip &.........
send the false information and wait to see which ip is interesed in the port number that you gave .then you have who is hacking you . or make a program calling that url in infinit messing up the database .They usually use Prohosting.

But first if you have the URL THEN email the owner of the page and tell them that they are infected too.

I HOPE THIS HELPS