For the first part of the query it certainly seems to be lot of work,but it can be done by imposing various restrictions.
1.Disable Task Manager -users cant disable any service.
2.Play with gpedit.msc[Group Policy Editor],you'll find lotsa tweaks that will make that setup.
3.Password protect your anti-virus & firewall.
4.Certainly disabling the admin account is not a option,users will complain of not being able to proceed with tasks such as installing programs...blah blah.Moreover executables require admin priviledges.If thats what any of them require such functions.
You can also have a look here:
http://www.thinkdigit.com/forum/viewtopic.php?t=15937
Surf Kelly's registry tweaks page,you'll find lotsa goodies.