A friend once installed a remote-access Trojan on my laptop as a joke. It reportedly ran in the background, connected to a webhook, and allowed remote interaction through bot commands. I was told it was written in C# and Python.
Since then, I've reset the laptop many times using USB installation media, local recovery, cloud recovery, and the option intended to prepare the device for a new owner. Security scans have not found anything, but I'm unsure whether they would detect a program written in C# or Python.
I'm worried that the malware could survive a reset and still give someone access to my email, banking, or other accounts. If I completely erase the system and reinstall Windows from known-clean USB media, can a RAT survive? Is there anything else I should check to verify that the laptop is clean without repeatedly resetting it?
2 Answers
Keep in mind that a Windows “reset” and a true clean install are not always the same. For maximum confidence, use a trusted computer to create official installation media, boot the laptop from it, remove the old system partitions during setup, and install Windows fresh. Once configured, check startup apps, running processes, browser extensions, installed remote-access software, and unusual network connections. If those look normal and scans remain clean, there is no practical reason to keep reinstalling.
You can’t mathematically prove that a negative is impossible, but security decisions are based on evidence and reasonable threat models. A clean reinstall followed by normal file, process, and network checks is strong evidence that the RAT is gone. If your accounts show no suspicious activity and the person who installed it is no longer involved, repeatedly wiping the laptop is unlikely to provide additional protection.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures