I've just read this entire thread. Twice. Unfortunately it gets a bit hard to follow. I believe you're writing about outgoing spam from your server. Generally that's not a problem with the SpamBlocker exim.conf file. If you're sure the email is going out from PHP, then you need to make sure the headers show the user; see an earlier post to the thread. If you're sure it's coming from an authenticated password then you need to change the password. If you've changed the password and it's still coming from an authenticated user, then you must consider how someone is getting new passwords, since to authenticate a user must be using password for outgoing email, or for incoming email login to set the popb4smtp timer.
I wrote the SpamBlocker files and I believe I can find and fix this, but I'd need to charge for my time. If you're interested then please feel free to contact me at my email address below (PMs are generally not as fast as email).
Jeff