Wow, this thread is long-in-the-tooth! More than four years, and still the "get FireFox". Pretty soon it will be "get LazerFox".
It's true that IE, and a lot of Windows OS settings for that matter, are not set up very secure by default.
You can leave everything as is, open all those emails, install those shady programs and click on everything on every shady site you visit. Then blame IE when things are kaput.
Besides having virus/spyware tools, and definitely a firewall, you should have a good idea what's on your own machine. What programs/services are set to run on startup? Check your HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run key and know what those programs are. Run services.msc and see what's started automatically. Most malware doesn't use the Startup folder anymore, but check it anyway. Use programs like Tlist and Kill to view and stop running processes. When your box is hijacked the task manager (ctrl-alt-delete) sometimes isn't good enough to find and kill bogus processes. It might be a good idea to save a list of running processes when your computer is acting right. Then when you have problems, you can kill those funky-sounding procs one at a time and maybe narrow down the offender. I hate when programs you install like Norton, Office, Ulead, etc... run a bunch of crap on startup. You have to check things out before and after you install anything, and maybe cleanup a little of the garbage. And have a reliable backup system. I use Ghost to just completely restore the partition to what I KNOW is a clean state. I have Win2K. I don't know if the XP restore points are reliable, but I wouldn't rely on them alone.
Well I rambled enough (the letters are black - background's white

)
I have to stop now; my browser is crashing.