in windows XP the regular USER group will stop someone from installing any applications. but if the application does not have to be installed to run, (just runs from the directory it is in. there is no install to it), then that will not stop them. If you right click the D: drive and go to properties then security add that user’s account to the security listing then set an explicit DENY permission on the drive. If the DENY permission is set then it doesn’t matter what other permissions they have, the deny always overrides.
what kind of restrictions on the web do you want to do? under internet options, security there is a restricted sites section that you can add sites to but that should block all users, not just the one. I prefer to do this on a web filter at the gateway, not on the pc. It is just eaiser to manage, especially if they go to another pc the restrictions won’t be there if the original restrictions were set at the first pc.