If they're using their own user accounts (which they should be...or at least sharing a non-Administrator account), you can restrict write access so that they can't save anything to the harddrive. Also, you can look into using poledit.exe (policy editor) for more control.
Also, invest in a good antivirus app and keep it updated.
~Ladi