I have a user (XP pro) who gets locked out of her account every day.

If you have checked out everything on the AD with her account, then something must be attempting a login during the evening. I would check processes on her system if they are using her specfic login credentials or other systems that might have services or processes using her credentials. You can review the security logs on the Domain controller to get the exact times of attempted logins. There should be a specific number of fail attempts and that number should match your domain password policy. good luck