You know, while Windows has plenty of security holes, the main way of hackers exploiting those holes is through executable files on their target's computer. To do that, they need to get an executable up and running on said computer, a task which is normally accomplished through a virus. And while there are of course many ways in which viruses can spread, I'd hazard a guesstimate that about 70-90% spread through vulnerabilities in Internet Explorer (which is the basis for the Outlook Express and Outlook email rendering engines).
The solution? Use Mozilla (or Opera - does it have a mail client though?). I remember many many virus-infected email I received in the Mozilla mail client - for the most part I could even view the email without any worries that the virus would self-execute. Not that that's a good idea mind you, but still... it's to prove the point that while your car may have a 40-gallon gas tank, all that gas needs to enter through the one little opening. Make sure that opening is secure, and you've secured the whole system.