Quote Originally Posted by Cider View Post

This is possibly the brainwave I was looking for - applocker I take it?

http://www.microsoft.com/windows/ent...aspx#applocker
That would work, but I actually use GPOs to do this. User Policies > Admin Templates > System > Run only approved Windows executables. [If I remember correctly]

And then I use Software Restriction Policies [in a separate GPO] to keep anything from running out of %temp% and %tmp%. This one can cause problems installing some software, so I keep it as a separate GPO, for easy removal.