ClickFix: explorer.exe spawns PowerShell/cmd via Run dialog paste

Detects the execution of PowerShell or Command Prompt with common adversarial flags (e.g., encoded commands, bypass, hidden windows) initiated by the Windows Explorer process. This pattern correlates the execution event with recent user interaction with the Windows Run MRU registry key, suggesting a possible manual execution of malicious commands via the 'Run' dialog box.