I work abuse@some.isp so perhaps i can give you some help.
first of all, you need to obtain the complete headers of the email. there are several clues that will help you locate the originating system, but those require experience and practice in tracking mail. Also know that spammers are notorious for trying ( rather badly might i say) to add "fake headers" to confuse the hell out of tracker programs.
Just locate the reception point, and follow the mail ( check dates and times. they help).
EX : Received by X from Y. Received by Y from z. Received from Z from D. Received by c from b.
In this case for example, originating point might be from D. Also check the MESSAGEID field, since you're probably gonna get something like "Q!@@#$!BHSYHXZJAnHXC7612r761235457@system". Also, careful with hostnames, since spammer machines are notorious for adopting an "ip address-like" hostname that does not reflect the real IP it is connected to ( all the more to ofuscate their track).
_____________________________
when someone asks for your username and password, and much *clickely clickely* is happening in the background, know enough that you should be worried.