don't use passwords such as; password 123456 qwerty etc...chances are your account got cracked by some 12 year old kid randomly running a yahoo cracker if you used an easy password. However, if you pw was something like h3ll0a11 then you got infected with something dirty.
Ouch... this looks bad... Get a friend of yours to log into paypal and change the password. That's quicker then finding the thing on your pc that he's using to get your passwords Let your friend get your cash back and then start dealing with the hacker...