W2k the UAC is the final safeguard to prevent a virus from installing itself ie you have to ok it's installation, remove that and they will just install themselves. Having AV and malware software, although essential is not a guarantee that you wont get hit, although it helps, running an account without Admin privileges so that nothing can be installed is the safest, running an Admin account without the UAC enabled is the most dangerous.