28
Now that you know they are using a valid email address, you should (as Vaughn suggested) complain to Google Mail. Although if Google do decide to take action against the account holder they would have to be quick. I would imagine that dynamic IP addresses make it impossible for Google to block future registrations and the hackers may set up a different g-mail account every week.
If your web root is compromised, it may actually be the host's fault, not yours. An exploit utilising PhpBB was the source of widespread hacks on shared servers a couple of years ago. You didn't need to be running PhpBB on your site to get hacked.
@moderator
Can someone trim the wide code in one of the above posts so this thread is more readable.
A thread is for life. Not just for Christmas.