ClickFix paste-and-run: PowerShell launched via Run dialog from explorer.exe

Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.