I use Avira and it has an option to disable auto-run. I say it is useless because "now you are vulnerable to new attacks", only next update will fix this security issues. It is like how antivirus works ... i see a virus -> make signature -> update -> detect -> you are safe.
People will get infected no matter what ... If you see the USB doesn't need to auto-run to infect someone, it is the same with CDs and DVDs. You just make a shortcut and it is done. There are so many techniques, just watch how the backdoors, RATs work, watch some black hat forums
People can get infected with a drive-by, make a small java applet that runs a exe in background. With windows updates or with no updates it is the same.