The first set of updates your Windows PC needs are Microsoft Windows Updates.
Many PCs automatically download these, some PCs automatically install these. If you don't install the critical security updates microsoft issues via windows update, you are likely to get infected by using the internet or even by just being connected to the internet.
To check if your XP or Vista machine is up to date please go to http://windowsupdate.microsoft.com/
Windows 7 machines need to run the windows update command (in start, all programs, windows update).
We prefer to always do custom updates from the microsoft site, but express updates will work for most people as well.
Note: if you have not updated your machine for a long time you could be doing this for a few hours. Just remember the longer the updates take the more vulnerable you were before you started applying them.