for what purpose? if u can access the sam and dump passwords then u should be able to simply net user blah password /add and windows encrypts the password, so then you can dump the sam and get that value instead of trying to find a program that's gonna do it for you, plus it writes it to the sam so you don't need to inject it urself. ur question seems confusing, maybe if u gave us a scenario it would help...