Logging on

The Windows subsystem automatically starts Winlogon.exe, and Winlogon.exe starts the Local Security Administration (Lsass.exe). You now see the Begin Logon dialog box, which contains the text Press Ctrl+Alt+Delete to log on. At this time, Windows NT might still be initializing network device drivers, but you can logon now.

Next the Service Controller (Screg.exe) executes, which makes a final pass through the Registry looking for services that are marked to load automatically. Auto-load services have a Start value of 0x2 in the subkeys HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DriverName.The services that are loaded during this phase are loaded based on their dependencies, because they are loaded in parallel. The dependencies are described in the DependOnGroup and DependOnService entries in the subkey HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DriverName.

Note

Windows NT startup is not considered good until a user successfully logs on to the system. After a successful logon, the Clone control set is copied to the LastKnownGood control set.