You could create the users account with reduced privileges on computers. But you can block users also using the GPM
On your w2k3 srv:
Simply go to Start Menu
then Administrative Tools
nav to Group Policy Management
Expand domain (which you want to implement the policy)
Right click on default domain policy
go to edit
on computer configuration
nav to administrative templates
then windows components
select windows installer and then select disable if its not configured
Please note this will affect all users, also there are a number of policies within that you may find of use.
Be sure when setting domain wide policies otherwise you might shot yourself in the leg when senior management complain.