Microsoft has gradually improved the security of your SAM file, but also has maintained backward compatibility with systems such as Windows 9x inherently unsafe. With the increasing sophistication of tools capable of brute force attack on the LM and NTLM hashes, encryption (especially LM) has become virtually worthless if the password is not really entropic and complex. In Vista, at last, has been eliminated at least the weakest link, the LM hash.
If we study the result of an online or offline dump (after 'leapfrog' the SysKey) of SAM, we will see something like this:
Administrator: 500:42 f29043y123fa9c74f23606c6g522b0: 71759a1bb2web4da43e676d6b7190711:::
that in fact the hidden LM hash of the password
(42f29043y123fa9c74f23606c6g522b0) and NTLM hashes
(71759a1bb2web4da43e676d6b7190711)
Read more »