"would a good virus/malware program for XP keep her safe from attacks w/o Microsoft's updates"
Not as much as a solid education on common attack vectors.
The issue with running XP or any unsupported OS is not whether it is then suddenly insecure, as in all honesty it doesn't magically become insecure overnight, but rather the piece of mind of knowing you have done all you can to secure yourself from threats. I don't know if anyone can give a definite quantifiable answer as to how much it is insecure in comparison, but you can assume the answer to be 'more than 0' and therefore why risk it.
Working in 'the industry' for ten years, I can count on one hand in my entire life how many viruses I have had. And I knew beforehand what I was...