AngieSW,
You can do this with the router. You will need the IP address for the PC's involved. Also if you have not done it already, you will need to create a username and password for the router so that the following settings cannot be changed.
On my D-Link Router DI-624, once you get into the router's settings page. Under Advance tab> Filters> there you can add IP addresses one at a time, and block Port 80, then press apply for each PC you add to the list. If you want to also block email, you will need to block ports 25 & 110. If your email programs uses different ports then you will need to block those port also for each PC. For newsgroup access, the standard port is 119, but you may need to add additional ports if your service uses a different port for newsgroups. Remembering to press APPLY for each PC.
Other brands of Routers should have a similar setting.
You may want to create a policy, that if these abuses continue. And the spyware/malware are definitely their fault, and not a random attack. Then they should pay for the time loss to the company, needed to cleanup their PC's. Unless they are so "invaluable" to your workplace, it might be time for an "upgrade" in personnel.
--
Add MS to your News Reader: news://msnews.microsoft.com
Rich/rerat
(RRR News) <message rule>
<<Previous Text Snipped to Save Bandwidth When Appropriate>>
We have some employees who abuse their internet privileges on a continuous
basis, and we end up with spyware and virus problems on their systems. Are
there any settings in windows xp, the router, or wireless access point I can
use to prevent them from accessing the internet at least temporarily. We
would like the file and printer sharing to be still available to them. Thank
you for your input.