Okay if anyones interested I did a little digging and came across this way to block things.
Go into the admin tools
Local Security Settings
right click softare and restriction > create a new one or something like that
then go into security levels and right click disallow go properties and make default
Then you can go into additional rules
new path rule to ban or allow a program etc...
edit: okay maybe don't set it as default i cant change it back and it wont let me use runas
.
I find it so funny that i can just go into the system32 folder and open it from their
, but I cant open it using the shortcut.