Obviously, there is always a risk. The question is "How great is that risk?" What is the probability of being hit? With an admin account and anti-v installed and running, can one say the risk is not there?...etc. The questions are endless.
From my experience, my brother-in-law, a complete noob on PCs was infected a few years ago. I cleaned up his laptop with a few tools, and told him to log in from there on as a non-admin account, i.e. Guest. Since then, he says he has been fine. Of course, I did also instruct him not to simply click/open unknown files and urls, even those that say it is good for his pc. Unlike me, he does have one of those free anti-v though.