For antivirus, Microsoft's built-in one is fine. Ideally use an OS that has better security and lower default permissions like popular Linux distros (at the very least, it's a smaller target than Windows). I haven't checked recently, but using Malware Bytes for occasional runs (not as active protection though) was good and is probably still good.
But in general, use FOSS, at the very least they'll probably not pull a Reddit and screw over their users.