A very common malware insertion technique these days is known as an "iframe attack" that comes in thru your web browser. For a description, I'll refer you to this article
http://isc.sans.org/diary.html?storyid=3078 about a nasty little piece of malware called MPack.
I've been hit by an iframe attack. Running as a "limited user account" with a good (is there any other kind) antivirus will block any infection, or at least tremendously limit the damage. The attack that hit me came from a compromised legit web server (and cleared in a matter of hours), and about as effective as bug on the windshield.