If you run that script it won't work because:

"domainadministrator" is not a valid account. On my Windows 2000 machine in my domain, you use:

code:
SHELL '%COMSPEC% /C NET LOCALGROUP "Administrators" | FIND /I "RPZ\Domain Admins" >NUL 2>NUL'

instead of the line you have. If you go to a command prompt on the target machine and check by typing:

NET LOCALGROUP "Administrators"

If the domain admins group is listed, it will tell you what you need to look for.

Personally, I like the ADSI method much better for doing this. (See posts above.)

Brian