Thank you Gavin.
The only things I might add is that "use a different password" isn't limited to exchanges, but applies to forums, emails, and even pools

, and that some antivirus heuristics seem to hate anything that has mining code in it and isn't explicitly whitelisted.
Yeah, you are right, these things are too scary... I am trying to imagine how those people felt in this terrible situation. Poor guys