I have Windows Defender and Malwarebytes, but I don't use VPNs. I just don't trust the VPN providers that much.
I also would never use Bitcoin/crypto wallets on my smartphone(I have an Android device). I think that the mobile devices are a little bit more vulnerable than PC/laptops. Just don't click suspicious links, don't download suspicious files and don't use free public Wi-Fi. You will be fine just by following those tips, even if you don't have anti-virus software and VPN.
Imho this in insufficient if you want to ensure your coins are safe. Of course, it's always a balance between how much the safety costs and how much money you protect.
Imho if you don't want to pay for a hardware wallet and you know a bit of this and that on computers, making a Tails OS stick and use it as a cold storage (with internet always disabled from start) is already way better than relying on Windows (which btw I also prefer).
Well, never say never. A 0-day vulnerability is always possible (imho even for Linux!). And better get the correct protection before feeling sorry you didn't.
It's like insurance: you tend to see it as money thrown out of the window... until you need it, if ever.