superboy, do you ever visit any of those "click LIKE to watch this {movie, picture, whatever}" facebook sites? Prime way to get malware on your box. Had to clean up two of my brothers' PCs last weekend, I'm pretty sure that's how they got crap on their system (neither of them download warez, and at least the youngest of them doesn't watch pr0n). The malware had even disabled AdBlockPlus and Ghostery both in Chrome and FireFox.
Attacks can also happen totally automated from drive-by attacks, of course, and you don't even need to visit seedy sites, a single compromised banner-ad server is enough. AdBlockPlus+NoScript+Ghostery ftw... oh, and not having Java, Flash or AdobePDF plugins in your browser.