ClickFix RunMRU registry write with PowerShell/curl/base64

Detects modifications to the Windows Explorer RunMRU registry key where values contain suspicious commands such as 'powershell', 'curl', or long base64-encoded strings, indicating potential command execution or persistence attempts.