That doesn't make sense. He changed the passwords, as well as using Gmail's ability to end all other sessions. Unless he was giving his SO (he never calls her his wife) the password and she was logging in on that computer, there should have been no way for a trojan on it to access the account.
They were probably using the "last chance" form to reset the password. That form checks the IP address; if they had control of the XP machine, they could have been using it to submit the form with a reasonable IP address and get the account again. Once they lost that, no go. At least that's the only thing that I can think of.
Ah, that makes sense. I didn't realize that the form checks IP addresses, though, in retrospect, that's an extremely obvious security feature to have.