If I opened a malicious email link that gave someone remote access to my laptop, then wiped the laptop and reinstalled Windows, would the malware still appear in Settings under "Add or remove programs" if it survived? Can malware hide from the installed-programs list, and does reinstalling Windows over the internet provide the same protection as reinstalling from a USB drive?
2 Answers
A cloud or internet-based Windows reinstall is usually fine if it actually performed a full reset and removed the old partitions. The important part is deleting the previous installation, not whether the installer came from a USB drive. For maximum certainty, boot from official installation media, delete every partition on the affected drive, and install Windows again. Malware surviving in firmware is theoretically possible but extremely uncommon; standard remote-access malware normally will not survive a proper clean install.
The installed-programs list is not a reliable way to detect malware. Many malicious programs do not register themselves there, so something could be present without appearing in that list. However, a genuine clean installation that deletes the existing Windows partitions should remove ordinary malware from the system drive. Afterward, update Windows fully and run a reputable security scan. It is also wise to change important passwords from a separate, known-clean device, especially if the attacker had remote access.

I wiped the drive and reinstalled Windows using the built-in internet download rather than an external USB installer. Is that generally sufficient?