Maybe view this:
Anatomy of a Malware attack:
http://www.theregister.co.uk/2008/08/22/anatomy_of_a_hack/Also, consider using FireFox (You probably already do)
Install the plug=in "no script"
This disables remote scripts which are the biggest threats to web surfers.