To make that clear: malware, which has administrator's rights, does not need to shutdown filtering software like the Windows-Firewall or a "Personal Firewall" for arbitrary communication.
Only malware, which has not, and only has restricted user's rights, is to be discussed. And for such a malware, it's usually very easy, too, as my PoC codes show.
Nobody needs to shutdown a "Personal Firewall", just ignore it.
Yes. And not a typical environment. But, why not, let's discuss this case.
In this case, I'd filter with the Unix box, because this is much more easy. The Windows box would get filtered network. On the Windows box, I'd perhaps would not give network access at all, at least not for the "idiot user" (if she/he is one), I'd just send a browser throug X11 to the Windows box - no downloads onto the Windows box. And mail I'd provide through an SMTP server and an IMAP server on the Unix box only.
Maybe it would be a good idea to filter out mails on the Unix box already, which are doubtful. If the user can be educated, then maybe attachements can be allowed. But then the user is no idiot any more ;-)
I'd not fear tunneling downloads through the browser, though, if the user is an idiot. But to make sure, I'd configure a restricted user account for her/him.
But really, if the user is called "idiot" and deservedly so, then you'd better buy a Macintosh anyways ;-)
Yours, VB.