The best protection against malware is education - knowing what the risks and vulnerabilities are, etc.
Otherwise...
1) Disable all in-browser execution environments (Flash,Java,Silverlight,etc).
2) Block all unknown third-party scripts.
3) Look for anything with full marks in Protection+Performance at av-test and cross-check it with AV Comparatives.
If you use any sites that require Flash, then complain to the site owners - 99.9%+ of Flash uses are obsolete now - and (if you trust the site) make sure you selectively enable it only for that site.
If you need Java for anything, install the Server JRE version and you don't get the shitty browser plugin auto installed across all browsers.
uBlock Origin and uMatrix browser plugins give you control over blocking all/selected third-party JavaScript (and other resources).
EDITED: 29 Apr 2017 12:51 by BOUGHTONP