Autoruns software logo

Autoruns

Pro Verified

Autoruns is a Windows startup manager that reveals every program, driver, service and shell extension configured to run automatically at boot or sign-in, so you can identify unwanted autostarts and trim them deliberately.

★★★★★ 4.8 (0 comments) •Updated: October 2, 2026 • 100% Safe & Clean
v14.3 Windows Desktop 64-bit System Information

What Autoruns Reveals About Windows Startup

Autoruns is a free Sysinternals utility that shows every program, driver, service, scheduled task and shell extension configured to start automatically on Windows. Instead of the short list in Task Manager, it audits more than a dozen autostart locations in one window, from Registry Run and RunOnce keys to AppInit DLLs, Winlogon notifications, Winsock providers and image hijacks. Its workflow is straightforward: run the tool, refresh the scan, then filter results by category using the tabs across the top. Select any entry to open the file's properties or jump straight to the Registry location that creates it, then uncheck a box to disable the item or delete it outright. That makes boot-time behaviour visible and editable rather than a mystery.

Where Autoruns earns its place is in troubleshooting. A slow sign-in, a mystery tray icon or a browser toolbar that reappears after removal usually traces back to an autostart entry that no normal settings screen displays. Blank-slate comparisons help too: because each tab lists empty locations as well as populated ones, you can see which hooks are unused on a healthy machine and spot ones that appeared later. Administrators use it to audit a fleet before imaging, to confirm patch or agent deployments, and to check for persistence left behind by unwanted software. If you already tune Windows with PowerToys, Autoruns is the natural companion for the startup layer those tweaks do not touch.

Benefits of Using Autoruns

The payoff from Autoruns is certainty. Windows spreads autostart configuration across the Registry, the file system, task scheduler, services database and several DLL injection points, and most tools expose only a slice of that. Autoruns collects all of them in a single, sortable view with the publisher, description, signer and timestamp attached to each row, so a suspicious executable stands out without guesswork. Built-in filters let you hide signed Microsoft entries and concentrate on third-party additions, while optional signature verification and VirusTotal hash lookups flag unsigned or previously unknown files. Every change is reversible: unticking an entry disables it without deleting the configuration, so you can reboot, observe the effect and restore it if something breaks. Reading the same data across other user accounts or an offline Windows installation turns the tool into a lightweight forensic and audit instrument, and the command-line companion exports the whole inventory for reporting.

Autoruns Features

✓

Complete Autostart Inventory

Autoruns inspects every autostart location Windows recognises, including logon entries, Registry Run and RunOnce keys, startup folders, scheduled tasks, services and drivers, Explorer and Internet Explorer add-ons, AppInit DLLs, image hijacks, Winlogon notifications, Winsock providers, print monitors, LSA providers and media codecs. Tabbed categories keep the long list organised so you can review one area at a time and never wonder whether something is still hiding elsewhere.

✓

Hide Signed Microsoft Entries

A dedicated filter strips out entries signed by Microsoft so the view shrinks to third-party software, drivers and shell extensions. On a typical machine most rows disappear instantly, which turns an overwhelming list into a short set of items genuinely worth investigating. It is the fastest way to answer what was added to this PC by something other than the operating system itself.

✓

Digital Signature Verification

Optional signature checking compares each autostart image against its embedded certificate and highlights entries that fail verification or carry no signature at all. Unsigned binaries are a common indicator of unwanted persistence, so reviewing this column gives a quick triage signal before you spend time tracing file paths and publishers. Verification runs as part of a scan and can be switched on whenever a deeper audit is needed.

✓

VirusTotal Hash Lookup

Autoruns can query VirusTotal for the file hashes of detected autostart images and report how many engines flag each one as malicious or unknown. Reports for suspicious files open directly in a browser, and files VirusTotal has never seen before can be submitted for scanning. This pairs a local inventory with reputation data, which helps most when a startup item has an unfamiliar name but a plausible looking description.

✓

Jump to Entry Navigation

Selecting an entry and choosing Jump to Entry opens the exact Registry key or file system folder that defines it, so you can inspect the raw configuration, export a key before editing, or confirm how a path is assembled. Seeing where an autostart actually lives makes manual remediation far safer than deleting files by name, because it shows precisely which value controls the behaviour.

✓

Disable or Delete Entries

Clearing the check box beside an entry disables it while leaving the underlying configuration intact, and Delete removes the autostart definition entirely. Disabling first is the cautious path: reboot, test the affected application, and simply re-tick the box if something stops working. That reversible workflow lets you prune startup items experimentally instead of committing to permanent changes you may regret.

✓

Multi-User and Offline Scans

The User menu switches the view to the autostart configuration belonging to other accounts on the same machine, which matters on shared computers where a different profile may host the problem. Command-line options extend this further by targeting an offline Windows installation, letting you examine a failing or unbootable system from a recovery environment before deciding what to remove.

✓

Autorunsc Command-Line Automation

The package includes Autorunsc, a console companion that prints autostart items as CSV, tab-delimited text or XML. You can filter by category, request file hashes, hide Microsoft entries, add normalised timestamps and scan specific accounts, which makes it practical to schedule recurring audits, diff results between two points in time, or feed startup data into an asset inventory.

Old Versions

Version 14.20
Updated June 19, 2026
Version 14.11
Updated May 9, 2026

Frequently Asked Questions About Autoruns

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *