#11 - June 30, 2010, 7:19 a.m.
Indeed, it sounds like the source of this is still active. Changing your password won't keep them out for long if they can still obtain the new one.
Your email itself may also be compromised, that's not all that uncommon in these cases. Not only would I change THAT password from a known secure system, also check and make sure they haven't put a forwarding on it to ship them new information.
When you run your scans, make sure to have the launcher open with a bit of gibberish in the fields. Some infections don't 'wake up' till the launcher is active.
Adding an authenticator as an additional layer of protection is an excellent choice as well.