This step begins with the starting of the Session Manager (Smss.exe).
It will run the programs listed in its BootExecute Registry entry, as well as starting the required subsystems.
The Win32 subsystem will then start Winlogon.exe, which starts the Local Security Administration (Lsass.exe), and the Ctrl+Alt+Delete window appears.
The Service Controller (Screg.exe) will check the Registry for services and will load them.