Based on my somewhat limited experience with removing feature codes, I think to re-load a feature after xftest would require a re-install of the VM. I also think that if you did change the feature codes to the lower level- they would all change, which would probably not do much good since whoever is changing the password now, would most likely be able to figure out how to do it then. He would see that his new method of accessing his mailbox was f911 for example, then just work his way up until he got the display of the VM DN.
Have you checked the VM logs/ reports? I believe that a change of the admin password would show up, along with the DN it was initiated from. If the culprit is changing it from his own phone each time it may help in identifying him.