1. boot into safe mode (because some AD softwares have multiple processes, and it can general itself as soon as you delete it, both in registry and files).
2. run regedit.
remove suspected keys under:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
or
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3. remove related folders/files.
4. run AD-aware or spy-bot to double check.