You can try this for av/firewall:
http://personalfirewall.comodo.com/free-download.htmlAs for the computers themselves I would use secpol.msc and gpedit.msc to lock down the services on the computer. If there are no rules you can pretty much shut everything usable down with those. If you dont know what those are type them in a run bar and hit enter and go through each one.
As for attacking... If you have physical access to them during the contest then this would be a 3 minute win on your part by booting any sam cracking tool. You can even use Microsoft Dart to reset admin passwords.
If no physical access to it then like others have said bring a laptop with backtrack on it. Or bring a backtrack live dvd and boot from it then attack from there.
If possible check the bios for boot password setups. If there is one and physical access is allowed tot he computers this will atleast require them to know the boot password to boot to a live cd or usb stick. Also set the boot order to only allow the local drive and nothing else.
If you want to get crazy you can always encrypt the entire drive with truecrypt as well. If I remember correctly you need to know the password to even boot up the drive which means unless they know the password for the drive then they cant crack the password too any accounts.
I know there are ways around some of these recommendations but they dont sound to bright from what you have said so they should work.
Hope that helps.