Let's think about this logically. Did you hear anything on the news about the Microsoft site being hacked? If it happened it would be the number one news story around the world for weeks. Of course it's not been compromised. Microsoft spend millions of dollars to protect their own servers and if there had been any problems you would surely know about it on every news bulletin you see, hear or read.
Your mate certainly didn't get his PC infected from Microsoft. More likely he uses it on file sharing sites which is where the majority of infections can be found.
Disabling automatic updates is the ideal way to open your PC to infection from the latest viruses. Microsoft create Critical Updates via the automated process because that's what they are - Critical.
--------------------
Do you know that we're all in line for succession to the throne? Really?
Well, if forty-eight million, two hundred thousand, seven hundred and one people died I'd be Queen.