Task Manager's Startup apps list is helpful but does not show every automatic launch location. Microsoft's Autoruns lists scheduled tasks, services, shell extensions and other autostart entries, including the image path and publisher. This makes it useful when a removed app still starts a helper or a suspicious program reappears. The safe approach is to preserve a baseline, verify the entry and disable one reversible item at a time before deleting anything.
Before you start
Get Autoruns from Microsoft's Sysinternals page, not a repackaged download. Back up files and note the symptom, entry name, timestamp and account. A work PC may contain management agents that should never be disabled locally. If malware is suspected, avoid logging into sensitive accounts on that PC while triage continues.Do it step by step
- Run Autoruns with appropriate rights and allow the scan to finish. Save an initial snapshot or export before editing any entry.
- Use options to verify signatures and hide Microsoft entries for analysis, but remember a hidden entry still exists. Review the full list before drawing conclusions.
- Search for the unexpected app's publisher, path and filename across Logon, Scheduled Tasks and Services. Check whether its executable still exists and what application installed it.
- Inspect file properties and vendor documentation. An unsigned or missing file can be suspicious, but neither condition alone proves malware.
- Uncheck one confirmed unwanted entry to disable it reversibly, restart and test the original symptom. Do not delete a driver, security service or system task on a hunch.
- If the cause is an installed app, uninstall it through Windows or the vendor's tool, then recheck Autoruns. Restore the entry if disabling it caused an unrelated function to fail.