netstat -a to see all the network connections open, that might give you a hint on what the machine is acting as (in particular if it's sending mails left and right). Use a firewall (zonealarm for example) in paranoid mode for outgoing connections (ie, block all by default), then allow processes one by one to see which one is infected. And get a antivirus scanner.