CRPx0 ClickFix RunMRU Registry Write with PowerShell or curl

Detects modifications to the Windows RunMRU registry key that include suspicious strings such as 'powershell', 'curl', or long base64-encoded sequences. This behavior is indicative of the 'ClickFix' technique, where users are socially engineered to paste and execute malicious commands directly into the Windows Run dialog.