Spam Emails sent from php script on my site - Help!!!!!

I really need some help with this.  I've been trying to find the php "script" that is allowing a spammer/hacker to send numerous emails out from "me".  I am getting tons of email failure notifications.  I have spoken with the Arvixe support and they are telling me that the emails are being sent out from a script.  They have "looked" and cannot find where and suggested that I hire a programmer to find and delete it.

Has anyone else had this problem and if so ... how can I find the script and "fix" it?

Here is a copy of the failure notification that I am getting ... thought it might help someone to help me.

------ This is a copy of the message, including all the headers. ------

Return-path: <maddie@cabofriends.net>
Received: from 46.12.142.53.dsl.dyn.forthnet.gr ([46.12.142.53]:8538
helo=cabofriends.net)
        by peacock.arvixe.com with esmtpsa (TLSv1:AES256-SHA:256)
        (Exim 4.77)
        (envelope-from <maddie@cabofriends.net>)
        id 1SMzJ1-001wWP-N8; Wed, 25 Apr 2012 03:18:40 -0700
Message-ID: <BCE608F8.3EF941D0@cabofriends.net>
Date: Wed, 25 Apr 2012 03:18:36 -0700
Reply-To: "Earthandsky" <maddie@cabofriends.net>
From: "Earthandsky" <maddie@cabofriends.net>
X-Accept-Language: en-us
MIME-Version: 1.0
To: <earthandsky@on.aibn.com>,
        <earp@one.net.au>,
        <earrellano@onebox.com>,
        <earpfamily@optonline.net>,
        <earr@optonline.net>,
        <earroyo54@optonline.net>,
        <earrufat@optonline.net>,
        <ears64@optonline.net>,
        <ears@optonline.net>,
        <earslanian@optonline.net>,
        <earsnoe@optonline.net>,
        <earth1fy@optonline.net>,
        <earth2liz92@optonline.net>,
        <earth2mother@optonline.net>,
        <earthangel2u@optonline.net>,
        <earthangel329@optonline.net>,
        <earthangel@optonline.net>,
        <earthcrone@optonline.net>,
        <earthdances@optonline.net>,
        <earthdragon124401@optonline.net>,
        <earther.white@optonline.net>,
        <earpl@osceola.k12.fl.us>,
        <eartha@outreach.com>,
        <earroyo@pacbell.net>,
        <earsu@pacbell.net>,
        <eart@pacbell.net>,
        <earteaga@pacbell.net>,
        <earth_angel82@pacbell.net>,
        <eartha@pacbell.net>,
        <eartha_kitt@pacbell.net>,
        <earthcub@pacbell.net>,
        <earredondo@padillahomes.com>,
        <earring@peganet.com>,
        <earp2@peoplepc.com>,
        <earpro@peoplepc.com>,
        <earquines@peoplepc.com>,
        <earraj@peoplepc.com>,
        <earrellano@peoplepc.com>,
        <earrenholz@peoplepc.com>,
        <earreola@peoplepc.com>,
        <earrick@peoplepc.com>,
        <earrings@peoplepc.com>,
        <earriola@peoplepc.com>,
        <earrly@peoplepc.com>,
        <earrowsmith@peoplepc.com>,
        <earroyo@peoplepc.com>,
        <ears18@peoplepc.com>,
        <ears@peoplepc.com>,
        <earsthebradford@peoplepc.com>,
        <earsthebradfords@peoplepc.com>,
        <earth-gaia@peoplepc.com>,
        <earth.jallow@peoplepc.com>,
        <earthangel2@peoplepc.com>,
        <earthangel44@peoplepc.com>,
        <earthangel581@peoplepc.com>,
        <earthangel59@peoplepc.com>,
        <earthangel8153@peoplepc.com>,
        <earthangel@peoplepc.com>,
        <earthangles@peoplepc.com>,
        <earthchild75@peoplepc.com>,
        <earthchild@peoplepc.com>,
        <earther@peoplepc.com>,
        <earthfall@peoplepc.com>,
        <earthfire@peoplepc.com>,
        <ears@peoplestel.net>,
        <earpk@person.k12.nc.us>,
        <eartha.brown@pgcps.org>,
        <earthage@pghmail.com>,
        <earrieta@pikecountyschools.com>,
        <earr@pitt.edu>,
        <earst29@pitt.edu>,
        <earthdog@pixi.com>,
        <earth1stdward@planet-save.com>,
        <earthbound66@planetout.com>,
        <earth1angl2001@plantnet.com>,
        <earth1angl@plantnet.com>,
        <earth2@pol.com>,
        <ears2hearministries@popmail.com>,
        <earthaangel1@ppc.com>,
        <earthaangel789@ppc.com>,
        <earthangell47@ppc.com>,
        <earth@prodigy.com>,
        <earthangel@prodigy.net>,
        <earthbase@prodigy.net>,
        <earthbound2@prodigy.net>,
        <ears2u@protectyourhearing.com>,
        <earsu@protectyourhearing.com>,
        <earroyo@ptd.net>,
        <eartha.mckinney@ptd.net>,
        <earthassociates@pwrnet.com>,
        <earp@pwrtc.com>,
        <earthchangesproductions@qc.aibn.com>,
        <earrington@qfsinc.com>,
        <earth@quack.com>,
        <earreola@qwest.net>,
        <earroyo@qwest.net>,
        <earthangel_106@qwest.net>,
        <eartha.dingle@radisson.com>,
        <earsenault@rcbm.org>,
        <earrington12@rcn.com>
Subject: Express LinkedIn Mail
Content-Type: text/html;
        charset="us-ascii"
Content-Transfer-Encoding: 7bit

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html><head>
<title></title>
</head>
<body>

<!-- START MESSAGE CONTENT -->

<div style="font-family:sans-serif">
<table style="max-width: 550px; border-top: 4px solid rgb(51, 153, 204);
font: 12px arial,sans-serif; margin: 0pt auto;" width="550" border="0"
cellpadding="0" cellspacing="0"><tbody><tr><td>  
  <h1 style="color: #000; font: bold 23px arial; margin:5px
0;">LinkedIn</h1>


    
<h2 style="margin:0; padding:0; font:17px arial;
color:#069;">REMINDERS</h2>
    <p style="margin: 5px 0;font-size:12px"><strong>Invitation
reminders:</strong></p>
  
                <span style="color:#999999;">&#8226;</span>&nbsp;
                <a href="http://gillansinn.com.br/4QD2zw7Y/index.html"
style="color: rgb(0, 102, 204);"> From <strong>Scott Burwell</strong> </a>
                  <span style="color:#666666;">(CEO at Costco)</span>
        <br>


<br>

<div style="border-bottom: 3px solid #ddd; line-height:3px">&nbsp;</div>

<br>

    <h2 style="margin:0; padding:0; font:17px arial; color:#069;">PENDING
MESSAGES</h2>
    <p style="margin:0 0 15px 0;">
      <span style="color:#999999;">&#8226;</span> There are a total of 36
messages awaiting your response. <a
href="http://kwp-hbh2011.org/x1HvtC5x/index.html" style="color: rgb(0, 102,
204);"><strong>Visit your InBox now.</strong></a>
    </p>
    <div style="border-top: 3px solid #ddd; line-height:3px">&nbsp;</div>
  
  <p style="margin: 10px 0;">Don't want to receive email notifications? <a
href="http://habituseventos.com.ar/gT2ebszP/index.html" style="color: rgb(0,
102, 204);">Adjust your message settings.</a></p>
  <p style="color:#999999; font-size:11px;">LinkedIn values your 
privacy. At no time has LinkedIn made your email address available to 
any other LinkedIn user without your permission. ? 2012, LinkedIn 
Corporation.</p>  

<!-- END MESSAGE CONTENT -->

                        </td>
                </tr>
        </tbody>
</table>
</div></td></tr></tbody></table></body></html>

I would truly appreciate any suggestions.  Thank you.

Quote · 27 Apr 2012

Sorry. But i think Arvixe is wrong on that one. I believe based on that email that your domain is cabofriends.net

If so the ip address of your server is 174.122.104.67

However the email was received by Arvixies mail server from the ip address of 46.12.142.53

Full dns name 46.12.142.53.dsl.dyn.forthnet.gr

It appears to be coming from a computer on a DSL connection. In other words i suspect your own computer

fourthnet.gr in Greece.

I would suggest you do a full virus and malware scan of your own computer. I do not believe your server is sending this out. But i could be wrong as i do not believe you are in greece so the ip could be spoofed.

Also ask Arvixe to take a closer look at the IP address these emails are originating from to make sure my suspicions are correct.

Something is fishy with the ip addresses and Arvixie should take a closer look at that.




https://www.deanbassett.com
Quote · 27 Apr 2012

I believe Deano is correct, if 46.12.142.53 is your home IP address then they are coming from your computer.

 

For future reference if you post an email header you might want to censor our your email address (and all those other poor people who are already being spammed) ... email harvister bots will pick them up and they will be added to every spam list on the internet.

BoonEx Certified Host: Zarconia.net - Fully Supported Shared and Dedicated for Dolphin
Quote · 27 Apr 2012

Thank you both, I will contact Arvixe again.  I am not in Greece, I am in the US. 

 

I do know that the emails are being sent from my site/server.  I saw them listed as being sent from my email account with the information on whether they were accepted or not ... now I can't remember where I found this.

 

Thanks again.

And yes, I did not realize that "bots" would be all over the emails in the post ... I don't know if this topic can be deleted or edited.  I will keep this in mind with any future postings.

Quote · 27 Apr 2012
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.