I'm not sure resetting PWs is the best advice. If systems have been compromised then going in and changing the PW is effectively giving the new one to the miscreants. Quirt a lot of sites use irreversable PW encryption anyway so they PW cannot be read by anyone after it is created. If fact all sites should be forced to go down that route.