Per-User COM Hijacking via HKCU CLSID InProcServer32 to AppData DLL

Detects the modification of InProcServer32 registry keys within the user's Classes/CLSID hive to point to a file located in the AppData directory. This pattern is commonly used for COM hijacking to achieve persistence or execute arbitrary code under the user's context.