Home › Forums › SharewareOnSale Deals Discussion › AFKSecurity / Oct 1 2026

Viewing 15 posts - 1 through 15 (of 28 total)
  • Author
    Posts
  • #24268777 Reply | Quote
    Ashraf
    Keymaster

    Have something to say about AFKSecurity? Say it here!

    Have suggestions, comments, or need help? Post it here! If you know of better software than AFKSecurity, post it here! If you know of issues with AFKSecurity, post it here! Share your knowledge with all of us. :-)

    #24268801 Reply | Quote
    Kaippuzha Kunjappan
    Guest

    Only gives a 34 day license instead of advertised 6 months (180 days)

    #24269171 Reply | Quote
    nonn21
    Guest

    Enter AFKSecurity license key: ~ Only 34 days, not 180 days =.=a

    #24269183 Reply | Quote
    Frank Mohnhaupt
    Guest

    Only for 34 days, not for 180 days !! :-(

    #24269339 Reply | Quote
    abdoul
    Guest

    35 jours et non 6 mois comme promis désinstallé ilico

    #24269589 Reply | Quote
    david
    Guest

    Hi everyone, I’m David, the developer of AFKSecurity. Thank you for trying it, and sorry for the confusion. Your licence is 6 months, and nothing is wrong with your key.

    The “34 days” on the Licence screen is not the end of your licence. It is how long AFKSecurity can keep working offline, without reaching the licence server. Once a day, the software checks in and renews that period. It never shows more than about 35 days, so it will stay around 34–35 days for most of your 6 months. In the last five weeks, it counts down to the real end date.

    I agree the screen is misleading. An update will show the real end date of your licence. Until then, here is the explanation in our FAQ: https://afksecurity.online/support.html#days-left

    #24269760 Reply | Quote
    TK
    Guest

    A question for the developer: You say this is an offline program that does NOT rely upon cloud computing or your resources on a server of any kind so WHY only a rental licensing model? Also why a limitation on the amount of days offline before it stops working? Is your DRM more important than paid for functionality of the program? Why cannot you make your DRM work offline? Or are you requiring more than just DRM verification and demanding usage stats reporting or other spyware activity?
    Why are you demanding continuous never ending payment for software than does not consume any of your resources of yours and whose activity is highly suspicious and some are classed as malicious activity hooking into other processes to gain insecure internet access!

    In an ideal world your software will appear to be doing nothing unless some potentially malicious activity occours and then your program SHOULD get in the way and take control… and then it’s don’t what it’s being paid for… but normally it should just be monitoring windows various API accesses a bit like Processmon from sysinternals and only show itself when something unusual happens. Now if your program pops up when NOTHING unusual is going on just to prove it’s on duty and giving you your moneys worth that is called a false positive and is annoying and intrusive and my mind does not need that unnecessary interruption from my current train of thought and neither does anyone else need that distraction! Let alone anyone with ADD/ADHD etc.

    Is this software really designed to provide a powerful, unobtrusive service or have you thought of a solution to a problem that you cannot really solve that you can try and make an indefinite revenue stream from for no real on going work?

    Will this question every API action until I confirm that API call was ok or does it assume a large number of things are harmless and is programmatically informed that writes by an unknown process to the any users Documents folders not just the current logged in user like windows ransomware protection already does … and requires no learning… just requires user authorisation for every new process write attempts… Why are you using MSedgview to just manage license? Isn’t that substantial overkill or are you using it to do more than a simple https request to validate a license? Personally I block unsolicited MSEdgview2 executable web access as it’s often abused by developers to sneak out web activity that they may not be legally entitled to… your program certainly has no need for emulating a web browser session and rendering functionality that I can see! I just executed afksec-gurad.exe and it tried to make a write to after a little while it started making a write attempt to a protected folder “%userprofile%\Documents\Steinberg\FX Chain Presets\” WHY? and later on unsolicited requests to a an external IP number on port 80 which it should NEVER do in this modern day and age and when blocked by my firewall the firewall ui executable makes a similar port request to an unknown internet IP address… THAT is a malicious act hooking into an existing process and trying to get internet access via wfui.exe is suspicious activity that this program should be BLOCKING not MAKING!!!! Now ending that process and trying executing afksec-app.exe and seeing what that tries to pull… Ah that then uses MSedgwebview2.exe to make DNS and HTTPS connections that are repeated periodically. And pops up a user interface. When pressing start it launches the afksec-guard.exe with admin rights, it’s NOT set to launch with admin rights in the programs own settings or API use but the launch process does it. It messes with the firewall adds a couple of rules and then removes them presumably to see if it has access rights to change the firewall rules… It is also not possible to disable/stop monitoring one you have manually started it and one gets a 2 day trial without giving the program internet access. Personally I find this program potentially malware from it’s insecure web requests, attempting to write to certain ransomware write protected folders for no disclosed reason which were never and will never be allowed without a justifiable reason reason being given for that write action. I note it writes to a journal file:

    C:\ProgramData\AFKSecurity\journal\journal.jsonl

    Why? It is a legitimate location but with SSDs being used for system drives you as a developer have to justify repeated writes to the system drive… each unnecessary write to a system SSD mathematically contributes to the eventual demise of the system as a whole!

    I note that the attempt to hook into the wfcui.exe is to gain access to their license server and done in the clear, no encryption which is amateurish, means I can probably packet sniff the license validation with a simple packet sniffer program and back engineer the communication required to validate the license… and hack it by providing my own server to spoof the activation server!
    Personally I don’t believe that this software has the power or authority to protect me from any malicious software… it will have to have had the process executed before any potential restraining actions can be performed by this poorly designed software.
    There is a report tab that provides vague summaries of what it saw but does NOT detail it . I has a button to write a report to my Documents but I don’t want to give this program write access to my Documents because of the prior suspect write attempts to ransomware protected folders.. The save report should be to a user definable location not a protected location that this program has no business writing into, as I do NOT trust this program due to it’s previously detected bad actions that should NEVER have occurred by legitimate software of this type. I’m ignoring the temptation to reverse engineer the licensing algorithm used and will be deleting this as at best snake oil monitoring things that may or may not be malicious, the software cannot determine and what is malicious and what is benign and performs acts that are detected by windows and other programs MalwareBytes windows firewall control that is being illegally may not be criminally ilegal but it is against the rules of good and well behaved programming trying to bypass the systems firewall by attacking the firewall UI process that might have permission to access the internet to check for updates like this hooked in to try and sneak past windows firewall rules. I’m erasing this now…

    #24269772 Reply | Quote
    David
    Guest

    Thank you for taking the time to test AFKSecurity this closely. This is the kind of scrutiny a security tool should get, and some of your points are fair. Let me go through them one by one.

    Licence. The licence check goes over HTTPS, and each right of use is digitally signed by our server with a private key that never leaves our hands. The software verifies that signature, so a spoofed server cannot produce anything it would accept. The check sends a hardware fingerprint and, at activation, the licence key. No usage data, no file names, no activity. When the offline period ends, the software does not stop: it keeps monitoring and logging, but no longer freezes programs or cuts the network.

    Port 80 traffic. The AFKSecurity service has no network code of its own. The only network code in the product is the licence check in the window, over HTTPS on port 443. The port 80 traffic comes from Windows itself: AFKSecurity checks program signatures, including certificate revocation, and Windows downloads the revocation lists from the certificate authorities over plain HTTP, as it always does. Those lists are signed. AFKSecurity does not inject into or hook any process; detecting that is part of its job.

    The write in Documents\Steinberg. That is a decoy file. AFKSecurity places five small hidden trap files in user folders; ransomware that encrypts them gives itself away. You are right that this was not clearly disclosed, and it should not land in other vendors’ folders.

    WebView2. The window uses Microsoft’s WebView2 to draw its interface, not to handle the licence. WebView2 makes some background connections of its own to Microsoft.

    Report location. Fair point: the report should not be saved to Documents without asking.

    Firewall rules. At startup, the service removes its own two isolation rules if a previous run left them behind. It only creates them when it actually cuts the network. Nothing else in your firewall is touched.

    Stopping it. Protection can be stopped from the window, from the tray icon, or from the command line. The service needs administrator rights because it runs as a Windows service; that is stated on the download page.

    Journal writes. The journal is capped at 24 MB in total and rotated. Its write volume is very small compared with what Windows itself writes every day.

    Does it act before a program runs? No, and it does not claim to. It is not an antivirus and is meant to run alongside one. It watches behaviour and steps in when a program starts doing what ransomware or an intruder does. For ransomware, the reaction has been measured at under a second, before most files are touched.

    What happens next. I will publish version 1.0.4 to fix the points you raised. It will:

    explain the decoy files in the window, show where they are, let you turn them off, and keep them out of other applications’ folders;
    turn off WebView2’s background connections;
    let you choose where reports are saved;
    show the real end date of your licence on the licence screen, instead of the offline period.

    I’m sorry the first impression was this bad. Thank you for pointing out what was genuinely wrong. I’ll post here when 1.0.4 is out.

    David

    #24269859 Reply | Quote
    David
    Guest

    AFKSecurity 1.0.4 is out

    Your giveaway licence is 6 months from activation. The “35 days” shown until now was how long the software works without contacting our server, renewed every day. It was not the end of your licence. Version 1.0.4 now shows both: the days without contacting the server, and the licence time remaining with its end date.

    Update from the Updates tab, or download it from https://afksecurity.online/download.html

    What changed: https://afksecurity.online/changelog.html

    David

    #24270032 Reply | Quote
    F
    Guest

    Hard to use

    #24270084 Reply | Quote
    Ziggy
    Guest

    [@TK] As usual a very extensive review, T.K. and one greatly appreciated. Fair points of criticism and excellent pointers for the developer to address those issues raised in your review. Good to see the developer reply with his course of action based on your review. I’ll give it a miss… By the way, with the end of Windows 10 in 2027, what would you suggest as a free anti-virus as I will continue to use the system regardless of Windows 11. Not sure whether Microsoft will continue with “Defender” once they totally kill off Windows 10. look forward to your reply…

    #24270167 Reply | Quote
    nonn21
    Guest

    The new revised version now shows 180 days.
    We recommend using the English version of the installation file. Thank you.

    #24270186 Reply | Quote
    Ray
    Guest

    34 days, all of you bad reviews for laying

    #24270188 Reply | Quote
    Wale
    Guest

    Hi,
    i added license key but it says 34 days remaining not 180 (6months)

    #24270189 Reply | Quote
    Wale
    Guest

    Hi,
    i added license key but it says 34 days remaining not 180 (6months)

    OK Now that iv seen other replies i understand clearly
    sorry for the first reply

Viewing 15 posts - 1 through 15 (of 28 total)
Reply To: Reply #24269772 in AFKSecurity / Oct 1 2026