[quote=dougwalkabout]
An average XP user who practices safe computing/email practices and doesn't have their PC connected directly to the Internet (i.e. is behind a firewall or NAT router) can be reasonably secure from infection for a long time. For these people, visiting an infected website may be their biggest risk, so trying to do as much web surfing without Java and Javascript could improve their security tremendously, although you lose a lot of functionality, but it's a price to pay for more peace of mind.
This is the biggest issue.  Sadly many average XP users still use MSIE and MSOE with all the defaults enabled.  I rebuilt my MIL's PC three times because she wouldn't update adaware, used IE and played yahoo games and now she pays a local PC shop to rebuild it rather than using safer software/sites.