Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
Read the full analysis on IntelFusions