, , . , , Microsoft Windows.
, Windows .
,
Windows, , . . - , / . , , . .
Windows 10:

, - , , . , , (, ).
Windows . - , , / . Windows. , .
Windows 10:

. Windows. , .
:

, .
, . , . Microsoft Windows, fork()
, . , , .
, . , .
! Windows .
, , , . , . - . , , (orphan process). . .
:

, , (PID) , , , . Microsoft Windows Resource Monitor , , .
Windows 10:

, Microsoft Windows, RAMMap, Windows Sysinternals Microsoft.
, RAMMap:

, RAMMap . , :

, . , .
Windows
=, , () , . . , , , , , .
Windows , SSD. Windows . .
, , () .
, :
. -. Windows 10 .
Windows , .
Windows
Windows , (registry). . Windows , . () , , , . . HKEY_LOCAL_MACHINE\SYSTEM.
Windows:
HKEY_CLASSES_ROOT (HKCR)
: Windows. , .HKEY_CURRENT_USER (HKCU)
: . , .HKEY_LOCAL_MACHINE (HKLM)
: , .HKEY_USERS (HKU)
: .HKEY_CURRENT_CONFIG (HKCC)
: .
Registry Editor (regedit
) Windows.
Windows:

, , . , , , .
. , LastWrite, . , . , - AutoRun. , , , .
, :
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
, Windows , [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- "Notepad"="c:\windows\notepad.exe"
Windows Management Instrumentation
Windows . Windows . Windows Management Instrumentation (WMI) - , Windows, Windows .
WMI - Windows, Windows, . , .
WMI Windows, :
- Computer Management ( ) Windows 10/Server 2019.
- .
- WMI .
WMI:

Windows (WMI) . WMI SMB (RPCS) . RPCS 135.
WMI WMI command-line (WMIC). - wmic process call create
.
WMI , .
Windows , . Performance Monitor, , Resource Monitor. ( ) - , Windows 10, Windows Server. , , . .
Windows 10/Server 2019:

, Windows, . , . , , 1 10, .
Windows 10:

, . , , , . , , , -.
Windows - , . , - Event Viewer. Event Viewet , .
, . , . 4 :
- Security \ -
- Application \ -
- Setup \ -
- System \ -
Windows (Event Viewer):

, , , . :

, , , , .
- 4624. Windows. 4625. , : , , , (, , , ), , ID .
Windows, /Security ( 7):
- 4725 -
- 4723 -
- 4724 -
- 4720\4726 - \
- 4648 -
- 4698 -
- 4697 -
- 4688\4689 - \