I have ezAntivrus running permanently, as well as the firewall built into XP.
In addition, I have Spybot S&D and AdAwareSE, which I try to run at least once a week.
I avoid microsoft products as far as practical, my browser is FireFox and my email client is Thunderbird.
Whatever email client you use, set it to block images by default - this is very good protection from spam. When a spam site sends you a mail with an embedded picture, they can track that you have read the pic from where it is hosted on their site, therefore confirming your email address as "live". With blocked pictures, they will eventually assume that your email address isn't valid. If you do trust the email, a simply click on "display images" will show it in full.
Most people are now educated enough to spot "phishing" emails a mile off. I now ignore anything purporting to be from eBay or PayPal unless it's a bid confirmation or watch list update.