Jinxtah: Well that's a bit worrying if that auto login with no credentials required thing is accurate. That means he can just use your account endlessly, and not to forget abuse your credit card info to just buy games through the client (assuming that's possible with stored CC info).
Even though my login details are fairly complex, I really hope we get 2-factor authentication. I don't know why it's not already the standard here on gog.com. Not only does it give peace of mind, it also makes sure stuff like this doesn't happen.
As a side note, I find it really weird that gog.com hasn't plugged the hole or been able to log him out remotely or whatever.
I hope the re-install thing works for you.
I suppose using paypal might be a good idea to a point.