We have been hacving problems with one of our administrators doing things that he shouldn't be doing, and have installed a logging program on a particular server.
How do I make it so that he does not see or have access to this installed program?
(I am the administrator, he has his own login with some administrative rights)
Yes and no... you can use the "find/search" utility to find files and folders you might not otherwise have access to... that doesn't always work depending on the rights that folder and possibly the parent folder has, however, if the user has the access to the parent folder, he/she might be able to take ownership of it and regain full access. There are programs that are able to run stealth, like SpectorPro for example, it's basically a rootkit style app that hides from api calls, and waits for a particular key-stroke sequence to happen, then prompts for a password so you can view the log or change a setting etc...
When I've run into this sort of thing, I use a combination, spector pro and bo2k, typically, if they find anything, they find bo2k, and don't try looking for the spector pro app, they think they found the logging tool, and it's just on this one server... so if I avoid that server, I don't get logged... poor them...
BO2K - List of Features
it's only happened twice(users detected bo2k in the process tree), and I've used 20+ times in combination with software like spector pro.
Rootkit revealer, and many other rootkit detectors will find spector pro hiding, so you might not want to use the bo2k and spector pro combo.