Potential DLL Sideloading Followed by MSI-Based Payload Deployment

Detects execution chains where a suspicious DLL (autorun.dll) is loaded from user-controlled directories and followed by a silent MSI installation. This pattern is commonly associated with malware staging and secondary payload deployment.