Since you say you had 2FA active, they bypassed that likely by snatching your token somehow.
Changing your password will invalidate all active tokens and thus they'll be booted out. Use mobile since presumably they compromised the computer to grab the token. Scan, possibly reinstall? Bleh, sucks.