Glad to hear that you've got free space again! Now, let's see if we can figure out what is writing those files in the first place.
- Download and run Sysinternals Process Monitor (it is a standalone application).
- Clink cancel on its Filters dialog.
- In the Filter menu, make sure that Enable Advanced Output and Drop Filtered Events are both ticked.
- On the toolbar, in the group of five buttons on the end to the right, make sure that only the second one, Show File System Activity is ticked.
- Click the Filter button on the toolbar (or press [Ctrl]+[L]) to bring up the Filters dialog.
- You will see a row of controls at the top of the Filters dialog where you can fashion a rule. Set them to "Path" "contains" "NetworkService\AppData" then "Include".
- Click [Add], click [OK], and then click the Clear button on the toolbar (or press [Ctrl]+[X]).
When a program starts reading/writing files to the Network Service AppData folder, events should start appearing in the list, along with the name of the process that is responsible for the writes. If nothing appears, make sure that the Capture toolbar button (the third one, it looks like a magnifying glass) doesn't have an "x" over it. It if does, click on it to enable monitoring.
Please note that due to the rather loose filter we set, some legitimate events will probably end up in that list as well. After running for a few minutes on my system, a couple of entries appeared pertaining to a "VirtualStore" from svchost.exe, a Windows component. The kind of suspicious activity that is filling up that folder on your computer should be hundreds or thousands of events, so it should be obvious. You can click on the fourth button on the toolbar (next to the Capture button) to toggle auto-scrolling on or off.
You may be able to figure out the problem on your own by Googling the suspect's name (as long as it isn't svchost.exe). If not, you can take a screenshot of the suspicious activity and post it here, or save the Process Monitor log by clicking Process Monitor's save button and upload it somewhere, posting a link here.
