Relocated consent.exe side-loading msimg32.dll from TEMP/AppData

Detects instances where the legitimate Windows consent.exe process loads the library 'msimg32.dll' from a non-standard system directory, specifically targeting suspicious paths such as user-writable AppData or application installation folders. This behavior is indicative of DLL side-loading, where an attacker places a malicious DLL with the same name as a legitimate library to achieve arbitrary code execution under the context of the trusted consent.exe process.