Run untrusted installers in a disposable Windows desktop. Add a simple config to lock it down, then close it to erase ...
That's it. Exit the file and save over the existing one, and you've got an immutable OS in that VM. When you boot it from now ...