COM Object Hijacking via HKCU CLSID InProcServer32 Registry Modification

Detects modifications to COM object InProcServer32 registry keys within the user's registry hive (HKEY_USERS). Attackers often hijack COM objects to achieve persistence by pointing them to malicious DLLs or OCX files. This rule specifically filters out common legitimate paths (Windows directories, Program Files) and known installers to reduce noise.