There's quite a few lucky people on this thread.
Contrary to the beliefs expressed here, you don't need to download anything obviously dodgy or open an attachment to get infected these days. Any semi-amateur website is a potential risk- I've personally had, or narrowly blocked, infections from DeviantArt, Aint It Cool News, Bell of Lost Souls, One Piece of Bleach and several others. With the arguable exception of OPOB, none of those is a remotely 'dodgy' site.
UAC, especially in Windows 7, _does_ help. For example, one common attack vector is for a site to suddenly be hijacked into running what looks like the installer for Acrobat. UAC gives you a chance to prevent that install- and unless you were trying to install Acrobat, it's an easy catch.
Personally, I recommend upgrading to 7, and always running the very latest version of your browser. I tend to switch between IE8 and Firefox as new vulnerabilities pop up. I also run a dual-drive system and keep everything important on the non-system drive. To reiterate, and as thefreeman0001 points out above, the threat can come from just about anywhere- these guys are constantly trying to hijack sites, and their hacks generally stay up for less than an hour, so just because you've never been infected does _not_ mean you've never been to a site that has been.
Seriously, I was complacent like a lot of the above posters once. I learned my lesson.