Security researchers modify InprocServer32 to redirect malware’s COM calls to a monitoring proxy DLL.
reg add HKCU\Software\Classes\CLSID\86ca1aa0-34aa-4e8b-a509-50c905bae2a2\InprocServer32 /ve /d "" /f
: