Skip to main content
Hello...I just wanted to let the community know what I learned today and encase anyone else needs help. I have VS installed on my W7. I had VS check the file wsainstall.exe and iIdecided to block it because I thought it was PE.StealerZBot! 1.6524. Which sounded scary to me. WebrootAnywhere scanned my PC and found 8 threats. I opened a Support Ticket and they responded back...saying sometimes this issue is caused by a disk error and to check disk with Microsofts tools. So I'm doing that full disk scan via restart of PC and then sending log files to support. Hopefully I have a good outcome..

.
Good to know - thanks for sharing the info!
And Sherry that is the default install file for WSA see the end of the link below.

 

Standard Download Link:

http://anywhere.webrootcloudav.com/zerol/wsainstall.exe

 

And Rising AV always gives the installer a FP on VirusTotal: https://www.virustotal.com/en/file/16fc0692ab919d0a795b9e066db59f984185accdfeaa7c9d569641c8a13be91b/analysis/1394575989/

 

Rising PE : Stealer.Zbot!1.6524

 

HTH,



 

Daniel 😉
And ?..ThankYou, now you tell me. I'm still checking my disk at 39%. And blocking that file from VS caused a ruckus leading to freezing up webroots web page and knocking out VS with pop up boxes and I had to restore windows. So learning is relearning? Where's a funny face now?
Yes you have to watch what VS trys to block as it trys to block everything from updating because it does it from the user space not C Windows or C Program Files if you want to know more about VS send me a PM.

 

Thanks,

 

Daniel 😉

Reply