[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe]
<c><hpms2wtn.exe>
[HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Control\Lsa]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\rising\RavTools\RegCleaner\3.0\LM\Run]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SOFTWARE\rising\RavTools\RegCleaner\3.0\LM\RunServices]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirawallPolicy\StandardProfile\AuthorizedApplications\list]
<C:\WINDOWS\system32\hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Lsa]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirawallPolicy\StandardProfile\AuthorizedApplications\list]
<C:\WINDOWS\system32\hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirawallPolicy\StandardProfile\AuthorizedApplications\list]
<C:\WINDOWS\system32\hpms2wtn.exe>
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache\]
<C:\WINDOWS\system32\hpms2wtn.exe>
[HKEY_USERS\.DEFAULT\SYSTEM\CurrentControlSet\Control\Lsa]
<Windows Virtual Assistance><hpms2wtn.exe>
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache\]
<C:\WINDOWS\system32\hpms2wtn.exe>
[HKEY_USERS\S-1-5-18\Software\SYSTEM\CurrentControlSet\Control\Lsa]
<Windows Virtual Assistance><hpms2wtn.exe>