NeedyMantis DLL Sideload

Detects the two Windows-networking-named DLLs the report confirms as sideloaded via the normal OS loader (WinSparkle.dll, libcurl.dll) plus vim64.dll (a filename Vim's real installer never produces at all). Path check now covers any location outside a small allowlist of known-legitimate vendor install folders, not just ProgramData, so it also catches the reported ProgramData\\USOShared, ProgramData\\VIM, and ProgramData\\TightVNC\\VIM placements. Known limitation: the one reported case where the malicious WinSparkle.dll sits at the exact canonical Program Files\\Poedit path cannot be distinguished by path alone -- that specific sideload is instead caught by the companion 'Extensionless Archive Paired with Same-Named DLL Drop' rule via the archive-pairing signal.