TokenGrabber Stealer: WindowsUpdate Persistence After Anti-VM Gate

Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.