I've discovered the same account associated with "Special Permissions" on my OS Drive. Just removed it, but in the process made a connection back to a strange occurance around a month ago where the entire size of all of my harddrives were downloaded within two hours on the same day. Here are all of the logs from that day including a picture I took shortly after the discovery. Eventually "MSFT 5.0" masked itself with my Computer Name too.
It will not allow me to post the raw images on this thread so you can find all related logs in this google share drive.
Main folder with logs included from Norton Security/Windows/ASUS Router at time of occurance: https://drive.google.com/drive/folders/1DlowoBjYtDrfV7EydHf3lNqYUsj4Zk-5?usp=drive_link
SSID Before Spoof: https://drive.google.com/file/d/18EZ9NHzZpjISMOF1JHuJvvnOTta8wiPm/view?usp=drive_link
SSID After Spoof: https://drive.google.com/file/d/1r9JBJyKg67No-jEn61qXZJcAdn5KoU5O/view?usp=drive_link
You'll notice in the logs that Windows Update and General were the specified downloading applications, a little further digging and diahost.exe was responsible for the 1.3TB+ DL to who knows where.