By re formatting the thing and re installing the operating System: there is a risk of destroying evidence.
Phileas, Obviously this is only an opinion based on descriptions of what has been said; on the thread and I stand by the advice I've suggested, but only the potential victim can really decide the best course of action.
Obviously in this case - I cannot state that this applies in this alleged instance, but given the very advanced state of the science of malware development, there are already established ways of circumventing the re installation of the operating system. [Edit: and preserving the functionality of the malware].
Think of Stuxnet and its variants. [Further edit: I cannot verify the voracity of this site but its worth a look
https://security.stackexchange.com/q...ntial-malware].
CAT III