You are right, those too. I would also recommend Sandboxie[1], not sure on its effectiveness but the convenience to just right click and run apps in its own sandbox is huge. Does anyone know an open source alternative to it?
Also on Windows, consider looking at Software Restriction Policies. For my host partition, I have things configured to deny execute for anything not in Windows (and excluding some temp/cache dirs). So if I step away for a minute and someone tries to download and run an exe, Windows should prevent it. Would also prevent me from drunkenly saving cute.jpg.exe to my desktop and running it.
I saw this a few years ago but never got round to trying it. Does anyone know how effective this actually is?