On first check with win services they were set to auto, then I set them to manual in case they were system critical. Here is a split from the dds. listing & both point to temp folders.
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\
drivers\b57nd60x.sys [2009-7-13 229888]
S3 GQRFNVTJO;GQRFNVTJO;c:\users\admini~1\appdata\local\temp\gqrfnvtjo.exe --> c:\users\admini~1\appdata\local\temp\GQRFNVTJO.exe [?] S3 massfilter;ZTE Mass Storage Filter
Driver;c:\windows\system32\drivers\massfilter.sys [2009-9-7 7168] S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
S3 RHKH;RHKH;c:\users\admini~1\appdata\local\temp\rhkh.exe --> c:\users\admini~1\appdata\local\temp\RHKH.exe [?] S3 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-1-10 993848] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-2-23 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-11-6 1343400] .