I suppose that the virus could be activated by plugging it in if the proper "Autorun" parameters were in place and your Windows machine is set up to autorun devices when they are plugged in. Mine is set to ask me what to do when a USB drive or CD/DVD is inserted.
Some viruses can be installed by webpages that exploit your browser and install software. Be leery of shady websites - stay away from pr0n, warez and torrent sites.
I normally don't run an AV, but in the past I have kept an updated version of AVG installed (but not running in the background and without all of the bells and whistles) and if I didn't trust a file, then I would right click and choose to "Scan with AVG". I suppose Malwarebytes would pick up a lot of baddies, but not all. As a rule, I don't open anything that I didn't download from a trusted website. And even then, after installation of software, I'll check msconfig for extra startup entries, and maybe even run HijackThis! to check for new entries and do a 'netstat -a' to see if any new ports are opened up.
If you're fooling around with viruses, you could very easily infect your machine. I suggest that you setup a separate machine that's not connected to the network, or at least that isn't allowed to communicate with any other computers on the network if you want to play with viruses.