Don, (and the EH community)
You are absolutely correct, I am always open to feedback and any ideas that can help shape my column. I really enjoy doing my articles, and am very thankful to you and the EH community for your continued support. Please feel free to let me know of any ideas or issues you would like to see addressed, in future columns. As Don has already stated, I am an admin and I may have missed crucial topics which would benefit all of us.
I didn't use the actual name of the exploit, (just in case the attacker reads our site) but as far as I could tell, it was some type of trojan, possibly a key logger. My best guess is that the attacker was attempting to use the machine as a jumping off point, but never quite figured out what to do; once he/she had access. The scanner(s) didn't detect anything which forced me to use google and figure out what exactly was taking place.
It is good to know that Stinger is worthless, I always use it as secondary scanner, maybe its time I move to something else like housecall, http://housecall.trendmicro.com/
I guess since it's freeware, we can't really expect top notch performance; and like you said they should catch a piece of malware that has been around 3-4 mos. Lets face it, most patches are issued and not applied for months on end, then attackers take advantage of the pre-existing flaw.
I have started to get into sandboxing, and like the idea of running a process in an area that keeps a process from causing havoc on a machine. I will need to look into these two products, ( NormanSandbox and Anubis) since I am only familiar with Sandboxie, http://www.sandboxie.com/
which honestly I am less than thrilled with.
I know blowing away the machine is the safest way, but it is also time consuming and a huge pain. I (and everyone else) am hoping for an anti-rookit that updates like anti-virus and stays one step ahead of malware programmers.
Thank you for giving me more apps to look into, and helping me to refine my approach to an incident. It is vital to stay on the cutting edge of the best tools which help to combat attackers tactics.