About a month ago, I downloaded an executor from a video site and my computer was compromised. The attacker accessed my Gmail and Facebook accounts and sent a cryptocurrency scam image from them. I reset Windows, removed my files, reinstalled Windows, installed ESET, ran full scans with both ESET and Windows Security, changed my account passwords, and enabled two-factor authentication. The scans found nothing afterward. Is that enough to consider the computer clean, or could the malware have survived? I also receive frequent sextortion emails in my spam folder that contain some of my old passwords. I'm worried the sender might eventually obtain one of my current passwords.
3 Answers
The old-password sextortion emails are usually recycled breach data and spam, not proof that someone currently has access to your computer. Still, every password that appeared in those messages should be considered exposed. Use a different, unique password for each account, keep 2FA enabled, and check your account security pages for unfamiliar devices, login sessions, forwarding rules, and connected apps. Never respond or pay.
Security software scans and 2FA are useful, but neither one proves a compromised machine is clean. A clean install from trusted media is the strongest next step if you are unsure what kind of malware was involved. Keep Windows and your browser updated, download software only from reputable sources, and avoid running unknown executors or cracked programs.
If the Windows reset was performed from the potentially infected system, it should not be treated as a guaranteed clean installation. For maximum confidence, create Windows installation media using a separate known-clean computer, boot from it, delete every partition on the affected drive, and install Windows fresh. Afterward, change your passwords again from that clean system and sign out other sessions. Also make sure your recovery email addresses, phone numbers, app passwords, and email forwarding rules have not been changed.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures