Field briefing  /  Security engineering  /  2026.06.10

What we found..
What we built..

Two per-customer Webroot uninstallers, one hidden keycode, and one remover that works on any machine without it.

Codename
EKO-II
Subject
Webroot SecureAnywhere
Artifacts
2 signed .EXE
Status
Built / validating
Prepared by
sotoprojdev.com
Play the briefing 18 sec  ·  1080p
01

Two files that were almost the same.

Webroot ships these uninstallers built one per customer site, two different organizations in our case. Both are genuine. Each carries a valid Authenticode signature from Webroot Inc., product UltimateUninstall, version 1.13.0.9. Near-identical in size, yet not the same file.

2
Per-customer
builds
2,592
Bytes of size
difference
1.13.0.9
Same product
version
VALID
Webroot Inc.
signature
02

The difference is a key you cannot see.

Each build holds one customer-specific value: a Webroot keycode. It sits inside a compressed payload, so changing that one value scrambles bytes across the whole file. The customer name appears in zero readable locations. That is why two builds of the same tool look so different.

Anatomy of one uninstaller (schematic)
PE
Compressed payload  ·  entropy 8.00  ·  keycode sealed inside
Signature
The keycode lives in the hatched region. Because it is packed, a one-value change ripples through it. The signature block (about 56 KB) is generated separately, which accounts for most of the byte delta.
8.00
Bits per byte
(fully packed)
39.1%
Of the body
differs
0
Plaintext customer
strings found
03

The lock is a feature, not a bug.

Webroot runs with tamper and self-protection so malware cannot quietly switch off the antivirus. The keycode is the uninstaller's authorization token. So removing Webroot for any customer has a right way and a wrong way, and the difference matters.

The wrong way

Crack the signed binary.

Patch the file to skip the keycode and tamper check. That defeats endpoint protection, the exact move attackers use to blind a machine.

We did not do this.
The way we took

Use the machine's own key.

Let each computer present its own keycode to the official uninstaller. Supported, signature-safe, and survives agent updates.

This is what we built.
04

A remover that reads each machine's own key.

Remove-Webroot.ps1 runs on the target machine, finds the agent, reads that machine's own keycode from its local config, drives Webroot's official uninstall, then sweeps the leftovers. One script, any customer, no hardcoded name, no tamper bypass.

01
DetectFind the agent through registry keys, services, and WRSA.exe.
02
DiscoverRead the machine's own keycode by its shape, not a fixed value name, so it survives version drift.
03
UninstallRun the official WRSA.exe removal using that keycode.
04
SweepRemove residual services, folders, registry keys, and scheduled tasks.
Discover // simplified# scan local config for a value shaped like a keycode foreach ($root in $WebrootHives) { foreach ($value in (Get-Values $root)) { if ($value -match '^\w{4}(-\w{4}){4}$') { return $value # this machine's own key } } }
Status / before fleet rollout

Built and syntax-clean. Two things to confirm on a live agent first: the exact registry value that holds the keycode, and the current uninstall switch. A built-in discover-only mode prints both from one test machine.