I looked at teh event log and 2 things seem to be happening. one is microsoft update. the other is mfehidk. here is something from eventvwr in system.
Event Type: Warning
Event Source: mfehidk
Event Category: (256)
Event ID: 516
Date: 2/15/2012
Time: 5:03:57 PM
User: N/A
Computer: JIM-13L5NOM9I4U
Description:
Process **\SVCHOST.EXE pid (1668) contains signed but untrusted code, but was allowed to perform a privileged operation with a McAfee driver.
Data:
0000: 00 00 00 00 03 00 58 00 ......X.
0008: 00 01 00 00 04 02 00 81 .......
0010: 00 00 00 00 00 00 00 00 ........
0018: 00 00 00 00 00 00 00 00 ........
0020: 00 00 00 00 00 00 00 00 ........
here is somthing from application in evenvwr that happens every hour:
Event Type: Information
Event Source: crypt32
Event Category: None
Event ID: 7
Date: 2/12/2012
Time: 10:47:20 PM
User: N/A
Computer: JIM-13L5NOM9I4U
Description:
Successful auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
anything related to microsoft updates or mcafee's mfehidk.sys driver seem to yank the focus away.