It will not be a rootkit, but the behaviour of the file that alerted Avast. As long as the installer was downloaded from a reputable site I would go for a false positive