

The file in question, "UNINSTALLEXCHANGE.PS1", seems to have been located in the /SETUP folder of my Avast installation, although I currently cannot find it in there anymore. While the warning above mentions the source being Windows' PowerShell, I did not have one actively open myself, which means that some other program must have tried to run a command through PowerShell/cmd. Given that I did not perform a scan myself, and that the following threat popped up while I was not actively at my computer, I assume Avast must have detected an action occurring in the background. Yesterday, I noticed the following Avast BehaviorShield warning popup:
