Some software use it to check for updates such as Lastpass. You could run procmon in boot logging mode, reboot and once you see the popup reopen procmon (this will take awhile) and review the output to see what launched powershell. Alternate would be download sysmon and install it as a service and reboot, it should log in the event log every process create.