Hi,
I found that spammers heavily used "c.php" file to exploit Zenphoto captcha before posting malicious comments. Are you aware of this? I can provide details if not. I have fixed it on my Zenphoto. Bad and quick but it seems to be a efficient fix.
Let me know!