Ask Leo! by Leo A. Notenboom

My anti-virus cleared something off my machine. Should I change my passwords?

Search First! Then browse: Categories | Full Archive | By Date | Newsletter

Home » Viruses and Malware » Malware Detection

Summary: When your anti-virus program tells you that it caught something, your next steps depend on what, when and how it was caught. And it depends on prudence.

When I opened Internet Explorer, a message popped up from my anti-virus program (AVG Free) advising that Trojan Horse PSW.Lineage.BKG was detected in a .dll file of a bin file of the Ask Toolbar in Program Files. Two options were offered: "heal" or "move to virus vault." Unclear of what the difference is, I chose "heal" and the Ask file along with a restore point were moved to the AVG virus vault. Several follow up scans in safe and regular mode as well as an online Kaspersky scan showed no malware.

Research yielded no info about PSW.Lineage.BKG, even on the AVG site, but other PSW.Lineage Trojans are mentioned online. It seems that this Trojan attempts to steal passwords, and BKG "may" be an abbreviation for "banking". I do not do online banking but do use my credit card on the Internet. I use Windows firewall and an Actiontek modem/router.

Is it necessary now to change all my online passwords, or can I feel reasonably sure that this has been taken care of?

The short answer is probably not ... but.

The problem is that we don't actually know exactly what happened, and the not knowing means that there's some risk.

When your anti-malware software detects and removes an infection, it can happen at either of two times:

  • Before the malware had a chance to actually execute and infect your machine

  • After the malware had been executed and had infected your machine

The problem is that based on your question, I can't honestly tell which it was. In fact, it's even likely that depending on exactly what your anti-malware software reported, you might not be able to tell which it was either.

"If caught after infection ... well, it may be too late."

The difference, of course, is that if the malware is caught before infection, you're likely quite safe. If caught after infection ... well, it may be too late.

Now, the reason I waffle at all is that most real-time scanners will fall into the former category, catching things as they arrive (in "real time"), and blocking them from ever infecting your machine. Since you indicate that this message has popped up in Internet Explorer, that's typically the result of a real time scanner.

On the other hand, you indicate that it was "detected in a .dll file of a bin file of the Ask Toolbar in Program Files." That typically means that the infection is already in place, since the infected file appears to have been installed into its working location.

Thus we're left not really knowing exactly what happened. And as a result we don't know exactly what the risks are that you've been exposed to.

I think you can guess where I'm headed with this.

In the words of Dirty Harry: "... you've got to ask yourself one question: Do I feel lucky?"

In your shoes ... I'd change my passwords. It's an inconvenience, perhaps, but better safe than sorry.

Related:

Helpful? Get new articles weekly by email in my FREE newsletter!

Your Name:
Your Email:


Why Subscribe?

Article C3627 - January 28, 2009

Recent Comments
5 Comments

I agree. Changing you passwords is a lot less of a hassle than having your identity stolen. I change all of mine every 6 months. I keep them in a spreadsheet which I store on a flash drive in an encryoted file (TrueCrypt) in a safe place. I update my spreadsheet on a computer that is not connected to the internet and that file is never on a harddrive of any computer that is connected. Call me paranoid but I have two friends that have had their identity stolen in the last six months.

Posted by: Michael Burasco at January 28, 2009 1:02 PM

Leo, It could have been a false positive. In which case the danger is that AVG deleted something harmless, or possibly deleted an essential file. All antivirus programs "detect" a certain number of non-existent viruses, particularly if 'heuristic search' is enabled.

Posted by: Coly at February 4, 2009 9:07 AM

I noticed in the question that they stated that they have an "Actiontek" modem/router. MY Actiontek modem is JUST a modem - NOT a router! BEWARE!

Depends on the model. I once had an ActionTek that WAS a router.
- Leo
06-Feb-2009

Posted by: Carl R. Goodwin at February 4, 2009 9:38 AM

I also have an Actiontex model M1424WR amd it IS a router so check before you panic.

Posted by: Nigel Broder at February 4, 2009 4:49 PM

Leo, thank you for the article.

In a situation like this, would it have been possible for a "two-way" firewall, such as Zone Alarm for example, to keep the Trojan from stealing the passwords in the first place?

Best you can say is "maybe". The problem is that once you're infected there's no way to know that the firewall is in fact blocking it.
- Leo
09-Feb-2009
Posted by: Bonita at February 8, 2009 6:19 PM

Post a comment on "My anti-virus cleared something off my machine. Should I change my passwords?":






(Email Address will not be published.)

Remember Me?

By popular demand...
my tip jar
Cuppa Joe
Buy Leo a Latte!

(you may use HTML tags for style)

RSS feed Subscribe to the RSS Feed specifically for comments on this article.

Before commenting, please...

  • Read the article at the top of this page. If your comment shows you didn't, it'll be deleted and ignored.

  • Comment only on this article. Use the Google search box at the top of the page if you have a question about something else.

  • Don't include personal information in the comment. No email addresses. No phone numbers. No physical addresses.

  • Don't spam. Excessive links to unrelated sites within a comment or across multiple comments will cause all such comments to be removed.

  • Don't ask me to recover lost passwords or hacked accounts. I can't, and those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...


Question? Ask Leo!