OK the rootkit that was detected was part of the Avast update files, so I would hazard a guess that it was updating when the anti rootkit scan was running