I would format the computer that Steam was solely installed on, it's unlikely anything more advanced than some kind of keylogger was on that computer. I assume your password on Steam was fairly strong as this would obviously also help in protecting yourself. It's also a good idea to keep your Steam_ID on a fairly low profile and not use it in various places on the internet.
As you say 4 digit ID accounts have considerable value (I've never understood this obsession) but makes the account a higher target for someone possibly looking to sell the account on. Google it, see if it crops up anywhere on the web?
With regard to vigilante revenge missions, I doubt there is much you can do unless you can prove the guy who did it has another Steam account, by which you could possibly get his account disabled.