I don't understand. You don't have to boot into windows to retrieve a user's password. You can boot BT, and run samdump which will dump all of the users passwords to the screen. Either use the option redirect the output (I don't remember what it is at the moment) or use samdump2 >hash.txt
Now you can use john the ripper, l0phcrack, or plain-text.info to crack the hash.



