I would have re-installed the OS from scratch after a deep format. I guess I don't trust used gear unless I've scraped it down first.
I leave auto updates on for my four machines at home. Never had a problem and the updates fix urgent security problems in a relatively timely manner. At work I have 21 machines that are running XP. We have to push those because of permissions configuration. Most of them do not have access to an outside the plant network so security is less of a concern. Never had MSFT brick one of my machines unlike IOS updates.