Field briefing / Security engineering / 2026.06.10
What we found..
What we built..
Two per-customer Webroot uninstallers, one hidden keycode, and one remover that works on any machine without it.
Two files that were almost the same.
Webroot ships these uninstallers built one per customer site, two different organizations in our case. Both are genuine. Each carries a valid Authenticode signature from Webroot Inc., product UltimateUninstall, version 1.13.0.9. Near-identical in size, yet not the same file.
builds
difference
version
signature
The difference is a key you cannot see.
Each build holds one customer-specific value: a Webroot keycode. It sits inside a compressed payload, so changing that one value scrambles bytes across the whole file. The customer name appears in zero readable locations. That is why two builds of the same tool look so different.
(fully packed)
differs
strings found
The lock is a feature, not a bug.
Webroot runs with tamper and self-protection so malware cannot quietly switch off the antivirus. The keycode is the uninstaller's authorization token. So removing Webroot for any customer has a right way and a wrong way, and the difference matters.
Crack the signed binary.
Patch the file to skip the keycode and tamper check. That defeats endpoint protection, the exact move attackers use to blind a machine.
Use the machine's own key.
Let each computer present its own keycode to the official uninstaller. Supported, signature-safe, and survives agent updates.
A remover that reads each machine's own key.
Remove-Webroot.ps1 runs on the target machine, finds the agent, reads that machine's own keycode from its local config, drives Webroot's official uninstall, then sweeps the leftovers. One script, any customer, no hardcoded name, no tamper bypass.
Built and syntax-clean. Two things to confirm on a live agent first: the exact registry value that holds the keycode, and the current uninstall switch. A built-in discover-only mode prints both from one test machine.