A couple of days ago I noticed repeated balloon tooltips notifying me that TeaTimer was scanning logonui.exe. I think I know what logonui.exe is, and I was surprised to see it being scanned repeatedly during a session. Should I be concerned, or is this normal? Or if I need to take further troubleshooting steps, what should they be?

Yesterday's full S&D scan did not turn up any immediate threats. NAV also does not report any threats.

Win XP SP1
Spybot S&D