Malware and virus files can be very small. they can easily hide inside any file you download.
To go along with this (and a uniquely Windows centric issue, in my experience) is that they can be labeled as say a .txt and it's really an exe (not an exe within a txt file, but a pure exe file) and they can fool systems and it will run (even more hazardous is that combined with how you have your admin account setup as well (if you only have 1 account on a Win machine that by default is your admin account (really no bueno, but that's for another time)).
This and a few others (in my opinion) are why things aren't always as secure on a Windows machine, but I digress. This can happen with any OS, but it's just heightened with Windows and add that to the large user base, prime real estate.
But I don't think I've ever infected anything this way...
Contrary to popular belief, not all malware/virus etc are obvious. Sure Ransomware is, but not everything is. Even monitoring resources religiously may not show signs of being infected.
Brave new world out there.