I highly recommend that you install a CAPTCHA system mate - and not something useless that includes the CAPTCHA code in plain text as a hidden variable in the submit form (yes, I know, the mind boggles).
I recently recommended this one for a client I'm consulting to:
Seems to be one of the better ones out there - may be a LITTLE more difficult than most to install - but it's definately more capable than many of the other's you'll find at the JED.
(I have my j-sites most of the time in subdirectorys (with a usefull name)
and have a .htaccess in the root if I see something strange in the logs I use
some of the stuff mentioned here)