My system at home creates a similar answer to Catch's.... Sort of.... ;)
I don't really do anything dangerous from home and my sweetie only did _once_.... Spyware... She hasn't done it since because I locked her down a little bit more. I have a domain that she logs into and the policies are set there. Just to make things a little more difficult for her box to infect mine I don't log in as a domain workstation and nothing on the domain has any rights to my box. If I want to work on the domain I log in to the server via term services and do what I need to.
I use my work's mail sentry to pass all my incoming mail through for my personal domain so it is filtered for executables, viruses and spam there which protects sweetie.... If I want to pass an executable I rename it to .txt and it comes through just fine.
My box has two NIC's, one of which is attached to a hub outside the firewall and "stealthed" but it is usually disabled unless I see the firewall getting a lot of traffic or "odd" traffic in the logs. Then I either fire up Ethereal or Snort on it out of interests sake.
All boxes autoupdate and have AV and sweeties box is firewalled since she is wireless using WPA/PSK, MAC filtered etc. and the WAP is placed in the basement to minimize range... Once I leave the driveway it's almost unusable.
Actually... Now I've listed it all out.... I probably am pretty close to practicing what I preach... Just without the "techno-nazi" label.... ;)
