Thanks for the fast reply.
I re-installed zorro several times and the zorro.exe was immediately eliminated by ms-sec-essentials. However, checking zorro.exe with Jottis Malware scanner, only one showed "something" (ClamAV, PUA.Win.Packer.Upx-48), all other engines reported nothing.

Repeated as suggested with virustotal. With one exception (Cylance, Webroot, W32.Malware.Gen) all others reported nothing.