C-drive keeps filling up

Anonymous
2015-01-14T17:54:01+00:00

Here's a problem that I haven't been able to resolve for the last two months.  I've researched this problem on this forum and nothing been able to solve it yet.  My work computer's c-drive keeps filling up to capacity.  I have a 235 GB hard drive with very few programs loaded onto it and almost no picture or video files taking up space.  The computer is hooked up to a network here where I work, but nobody else has this problem.  Even if I'm able to free up several GB's of space, the c-drive will fill up in just a couple of days.  I think I might have a virus.  These are the measures I've tried to correct this issue:

  • Ran Disk Cleanup which freed up about 2 GB's initially.  After a couple of days, the c-drive filled back up again.  Subsequently, running Disk Cleanup only free's up a few MB's now.
  • Ran MalewareBytes, Eset online scanner, and Super-AntiSpyware programs to try to identify a virus, but neither of them can find anything other than cookies.  I've also run these programs in Safe Mode.
  • My Microsoft Security Essentials program had been removed, and I can't get it to re-install.  I even tried several work-arounds listed on this forum to install it, but I still get error messages when installing.
  • Tried the "Fix It" function
  • Tried System Restore but apparently that's been disabled too since there are no restore points to be found
  • Disabled the Hibernate function to free up several GB's, but the computer quickly filled-up within a couple of days.
  • Disabled the Backup function.
  • Deleted temp files from my user profile
  • I also run into problems trying to install the security updates from the Windows Update function.  I haven't been able to get the security updates to install for a couple of months now.

Anything thing I do that free's up space will only work temporarily.  The c-drive will continue to fill up in a matter of minutes or hours even if I'm away from my computer during that time.  

The strangest part is that if I right-click on the c-drive in My Computer, it will show that the 232 GB hard-drive is nearly or completely full (0 bytes).   If I open the c-drive, select all the files and folders in it and right-click, it only shows about 51 GB's of storage space used.  This does affect my computer greatly when trying to save or print even small files that only take up a few KB's.  Is there any other fix that I haven't tried yet?

I ran the WinDirStat utility but that doesn't show me anything other than the 51 GB's taking up storage space.  Also, my hard-drive is not partitioned.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

51 answers

Sort by: Oldest
  1. Anonymous
    2015-02-04T22:07:47+00:00

    Glad to hear that you've got free space again!  Now, let's see if we can figure out what is writing those files in the first place.

    1. Download and run Sysinternals Process Monitor (it is a standalone application).
    2. Clink cancel on its Filters dialog.
    3. In the Filter menu, make sure that Enable Advanced Output and Drop Filtered Events are both ticked.
    4. On the toolbar, in the group of five buttons on the end to the right, make sure that only the second one, Show File System Activity is ticked.
    5. Click the Filter button on the toolbar (or press [Ctrl]+[L]) to bring up the Filters dialog.
    6. You will see a row of controls at the top of the Filters dialog where you can fashion a rule.  Set them to "Path" "contains" "NetworkService\AppData" then "Include".
    7. Click [Add], click [OK], and then click the Clear button on the toolbar (or press [Ctrl]+[X]).

        When a program starts reading/writing files to the Network Service AppData folder, events should start appearing in the list, along with the name of the process that is responsible for the writes.  If nothing appears, make sure that the Capture toolbar button (the third one, it looks like a magnifying glass) doesn't have an "x" over it.  It if does, click on it to enable monitoring.

        Please note that due to the rather loose filter we set, some legitimate events will probably end up in that list as well.  After running for a few minutes on my system, a couple of entries appeared pertaining to a "VirtualStore" from svchost.exe, a Windows component.  The kind of suspicious activity that is filling up that folder on your computer should be hundreds or thousands of events, so it should be obvious.  You can click on the fourth button on the toolbar (next to the Capture button) to toggle auto-scrolling on or off.

        You may be able to figure out the problem on your own by Googling the suspect's name (as long as it isn't svchost.exe).  If not, you can take a screenshot of the suspicious activity and post it here, or save the Process Monitor log by clicking Process Monitor's save button and upload it somewhere, posting a link here.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2015-02-16T16:36:19+00:00

    I've run the Process Monitor and a screenshot is attached below.  All the entries writing to that particular folder are either "System" for "svchost.exe" processes.  Most of the operations read: FASTIO_ACQUIRE_FOR_MOD_WRITE or some other form "FASTIO" operation as well as numerous "IRP_MJ_READ" operations.  I haven't been able to find out what is causing this or how to remove/stop it.  I appreciate all you help in this matter.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-02-16T17:18:02+00:00

    Please provide a copy of your System Information file. Type System Information in the Search Box above the start Button and press the ENTER key (alternative is Select Start, All Programs, Accessories, System Tools, System Information). Select File, Export and give the file a name noting where it is located. Do not place the cursor within the body of the report before exporting the file. The system creates a new System Information file each time system information is accessed. You need to allow a minute or two for the file to be fully populated before exporting a copy. Please upload the file to your OneDrive, share with everyone and post a link here. Reports in normal mode preferred. Please say if the report has been obtained in safe mode.

    Was this answer helpful?

    0 comments No comments
  4. LemP 74,985 Reputation points Volunteer Moderator
    2015-02-16T17:36:47+00:00

    In the same session (that is, you can stop Process Monitor but don't log off),

    • Start the Task Manager (right-click in the Task Bar and select "Start Task Manager")
    • Click the "View" menu and click "Select columns"
    • Find "PID (Process Identifier)" and click to put a check in its box, then click OK

    • Select the "Processes" tab and find the instance of svchost.exe that has the same PID as shown in the Process Monitor output.  If you were doing this after getting the screen that you posted above, you'd be looking for PID of 22696.  The actual PID will almost certainly be different the next time you run Process Monitor.
    • Right-click on the instance of svchost.exe and select "Go to service(s)."
    • Report the services that are highlighted.  Be sure to use the scroll bar to look at everything; the services hosted by an instance of svchost.exe may not be adjacent in the display of services.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-02-16T18:17:21+00:00

    Please do as LemP suggested above, but add one more step at the end: Click the PID column header so that the services are sorted by PID.  This will cause all the services hosted by the culprit to be visible on one screen.  Then take a screenshot and post it here.

    Was this answer helpful?

    0 comments No comments