said by fatdcuk
:said by Name Game
:This is one of the badboys that is of concern..but as you see in these links the jury is still out on whether anyone can positively ID the bad one.
Just for reference
SUPERAntiSpyware free can detect and remove the malware version of ip6fw.sys file but it dose not remove the orphaned run entry generated.
Runtime.sys is temporarily created at bootup and then is deleted but you can retrieve the malicious code by dumping it from drivers list of RootKit Unhooker

Autoruns can then be used to remove the orphaned run entries remaining:)
Thanks..that explains some things we see going on.