Exactly - with the number of hijacked banner web ads as well as the still not entirely fixed SQL injection hacks that are being purveyed through out the net, not running an AV / AM / something means you're been lucky.
Part of that luck in Vista can be attributed to UAC, but there are more than a handful of Trojans and rootkits out there int the world that are UAC sensitive....