ClickFix clipboard-injected PowerShell/mshta execution via Run dialog

Detects ClickFix-style clipboard/paste-and-run execution: PowerShell, PowerShell ISE, mshta, or cmd spawned from the Windows Run dialog (explorer.exe/RunMRU) with IEX/Invoke-Expression/DownloadString/FromBase64String or mshta HTTP(S) invocation, consistent with the UNC5142 ClickFix lure delivering the DeviceManager RAT.