Home › Forums › SharewareOnSale Deals Discussion › AFKSecurity / Oct 1 2026

Viewing 13 posts - 16 through 28 (of 28 total)
  • Author
    Posts
  • #24270484 Reply | Quote
    David
    Guest

    The installer language does not change anything about the licence. In every language, version 1.0.4 shows “Licence time remaining” with your 180 days and end date. If you still see only 34 days, update to 1.0.4: the full time appears after the next daily check.

    #24271856 Reply | Quote
    TK
    Guest

    [@David] could you please explain why my firewall logged over a period of time:

    01/10/2026 22:19:53 | 2544 | Microsoft Edge WebView2 | C:\program files (x86)\microsoft\edgewebview\application\154.0.4258.48\msedgewebview2.exe | Block | Out | 192.168.1.83 | 54698 | 192.168.1.254 | 53 | 17 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53702 | 104.18.38.233 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53701 | 172.64.149.23 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53700 | 104.18.38.233 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53699 | 172.64.149.23 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53698 | 104.18.38.233 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53697 | 172.64.149.23 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53696 | 104.18.38.233 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53695 | 172.64.149.23 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53710 | 23.11.41.157 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53709 | 23.11.41.157 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53708 | 23.11.41.157 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53707 | 23.11.41.157 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53706 | 23.11.41.157 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53705 | 162.159.142.9 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53704 | 172.66.2.5 | 80 | 6 |
    01/10/2026 22:19:48 | 5304 | afksec-guard.exe | C:\users\”””’\documents\innoextractor files\afksecurity 1_0_3\{app}\afksec-guard.exe | Block | Out | 192.168.1.83 | 53703 | 23.11.41.157 | 80 | 6 |

    Any idea what those unencrypted HTTP connection attempts from your service are for I note they are not preceded by any port 53 DNS look up? Only one of them has a rDNS but that is a23-11-41-157.deploy.static.akamaitechnologies.com the others have no rDNS

    Regarding the journal in my opinion you should cache the journal internally in a memory array and on application shutdown flush it to the file instead of performing fresh writes for each line… that will reduce the SSD erase/write cycles you place on the SSD and just because windows logs many things is no excuse to do the same in an inefficient manner.

    Also regarding the writes in odd places in locations within the Documents hierarchy if you really want to detect encryption early you should not place the canary/honeypot files deep in the file structure as they will b enumerated later on than the earlier files in the directories. Relying upon canary files means the mess has already hit the fan… personally I’d monitor the API in the same manner a procmon.exe and place the canary files near or at the start of the Documents folder structure so it will be processed before the important regular documents and check for the canary file being opened with write access requested… don’t wait for the canary files to be encrypted just check for intent to write to the canary files as a bad act and freeze that process before it actually performs any writes.

    #24272297 Reply | Quote
    David
    Guest

    Thanks for your feedback.

    Those port 80 connections came from Windows certificate revocation checks. The service verifies program signatures through WinVerifyTrust, and Windows was fetching revocation lists (CRL/OCSP) from the certificate authorities’ CDNs, which is why you see Cloudflare and Akamai. They use plain HTTP by design since the responses are signed. The DNS lookups are done by the Windows DNS Client service, so your firewall logs them under svchost, not under our process. It still shouldn’t happen: the protection service is not supposed to go online. In 1.0.5 revocation is read from the Windows cache only, so it makes no network connections, and a certificate Windows knows is revoked is still refused.

    On the journal: keeping it in memory until shutdown would lose exactly the lines that matter if the service is killed or the power goes. It never forced a disk flush per line, but reopening the file for each line was wasteful. In 1.0.5 the file stays open and bursts are written in one go. Your log was also inflated by repeated microphone events from one program, which 1.0.5 fixes.

    On canaries: you tested 1.0.3. Since 1.0.4 they sit at the root of Documents, Pictures and the profile, hidden, and named to sort first and last. But they are not the main detection. AFKSecurity watches file activity in real time and reacts to mass writes, renames and replacements across your files, whether or not a canary is involved. The canaries are a last line of defence in case that first layer misses something. Blocking the intent to write before the first write would need a kernel minifilter driver, like the one Procmon uses, and we chose not to ship a driver.

    Version 1.0.5 is planned within the next 14 days at most. It brings these fixes, plus an optional password to protect exceptions, a visible warning if the settings vault is erased or changed, and the installer in English by default. I’m mainly working on my other software right now, so I’ll collect more feedback until then and include what I can.

    Thanks
    David

    #24272930 Reply | Quote
    Robert
    Guest

    @TK. Hi TK. In the discussion about Softorbits, (https://sharewareonsale.com/discuss/topic/softorbits-ai-photo-editor-sep-24-2026), you made the kind proposal to give us : “a method to move all softorbits software to another partition even on another physical drive relatively simply and should works one time for all programs that install themselves into a subdirectory of C:\Users\[loginname]\AppData\Roaming\Softorbits\some program subfolder name”.
    I hope you’ll read this message, and I’ll keep this page open in my browser looking forward to your answer.
    As you don’t look at this older page, I re-post this message here.
    By the way, a great thank you for all your interesting and instructive past contributions.

    #24273531 Reply | Quote
    TK
    Guest

    [@Robert] I did check back to the page a few times since I wrote that post and never saw any replies so figured no one was interested… I shall compile a set of instructions aimed at windows 10 but should function in any windows from windows 2000 and above, even windows 11… I have noticed one caveat the mechanism might get removed by the uninstallation of one of the softorbits programs due to improper way it tries to delete the root folder of all softoribts installations even if there are other softorbits programs installed… this silently fails in a conventional installation as one cannot delete a folder that contains something else without deleting those first apparently but one can delete an empty folder used as a an anchor for another volume instead a of a drive letter… what I consider a bug in the handling of that folder… but micorosft would just view it as a quirk of the rules and ignore it and never fix it as it has existed since the process was invented and remains until today… I shall try an ACL hack to deny writes and modify to the folder and see if that fixes it without breaking the other drives ACLs which according to similar rules there probably is no ACL inheritance rules from folders used in place of drive letters to map a local volume… trying it out now… might stop new installations though… When I do publish the process it will be on that page if it is still available, if not I’ll find another way to publish it.

    #24274787 Reply | Quote
    TK
    Guest

    [@David] Did you ever weigh up the costs of using msedgewebview2.exe module just to form the GUI rendering? You are forced to have the approximately 11MBytes
    C:\Users\WINDOWSLOGIN\AppData\Local\com.afksecurity.console\EBWebView

    You force the user to endure the web activity the module forces on us just to ensure its up to date etc.

    Which is completely superfluous to the process of generating a static local GUI like yours, if you are not downloading the GUI components from a web server using it is a waste of resources! Also does your uninstal process clean up that folder hierarchy? If not that is also another reason NOT to use that bloated unsuitable module for a locally generated GUI IMHO. I know a badware developer that has also chosen to use it in some of their products, Softorbits also do not uninstall their EBWebView hierarchy on uninstallation simply because those folders are generated after the install script (which auto generates the uninstall script) has completed and the setup has terminated and only once the program is run is the appdata\local\ folders created and never removed when uninstalled. I don’t know for certain as I did not install your software using the install script as I did not trust the procedure… being a very new program by an unknown developer. So had to uninstall it manually and I found these unwanted extra bloat that needed manual removal and probably were not removed by your uninstaller. Of course I could be wrong, feel free to correct me if I am:-)

    #24275144 Reply | Quote
    David
    Guest

    You’re right about one thing, the uninstaller left that folder behind. It’s created the first time the window opens, after setup has finished, so the uninstaller didn’t know about it.

    Version 1.0.6 removes it on uninstall. It only holds the window’s cache, the chosen language and the last open tab.

    On WebView2, the choice was deliberate.
    It’s a native Windows component: part of Windows 11, delivered to Windows 10 through Windows Update, and kept up to date by Microsoft, security fixes included. AFKSecurity doesn’t bundle its own copy. Only on the rare machine where it’s missing does the installer fetch Microsoft’s official installer, and setup says so before it does. A component that is already there and patched by Microsoft is one less thing for me to maintain. That leaves my time for what actually protects the machine: the service.

    The window’s job is to show clearly what the service sees and does, with nothing hidden. That’s what people expect from this kind of software, and it doesn’t need a custom rendering engine.

    On web activity.

    The interface is entirely inside the executable. Nothing is loaded from a web server.
    Since 1.0.4, the window starts WebView2 with its background services turned off, component updates, crash reports, translation, SmartScreen lookups, sync and pings.

    WebView2 is updated by Microsoft’s own Edge updater, which runs on Windows whether AFKSecurity is installed or not.
    The protection doesn’t use WebView2 at all. It runs as a separate service with no interface. Choose “Quit the application”, from the tray icon or when you close the window, and the msedgewebview2 processes are gone; the protection keeps running.

    Every connection the product makes and every place it writes is listed here: https://afksecurity.online/connections.html.

    #24275160 Reply | Quote
    David
    Guest

    AFKSecurity 1.0.5 is out. Update from the Updates tab, or download it from the site.

    Thanks to everyone who reported issues here. This release fixes the slowdown some of you saw, stops flagging Microsoft components, removes all network connections from the protection service, and adds an optional password for exceptions.

    Changelog: https://afksecurity.online/changelog.html

    #24277596 Reply | Quote
    Robert
    Guest

    @TK. A big thank you for your reply.

    #24277604 Reply | Quote
    Robert
    Guest

    @TK : Its about the way to install softorbits and other soft that forces us to install them on a specific place like c:\users\etc
    I keep this page open in my browser in the hope of seeing your reply. And a big thank you in advance.

    #24278096 Reply | Quote
    TK
    Guest

    [@Robert] I have done the method on my system BUT it does not catch ALL softorbits nasty folders as sometimes softorbits dumps AI model inferences in a differently named folder and also the license json file and the problem with that is one would need multiple partitions for each of these nasty extra folders to avoid critical filename collisions that could wreck the licensed state… That normally happens when softobits/grtsoft abuse msedgewebview2.exe to produce their static GUI like this program does instead of conventional integrated GUI framworks like QT or wxwindows etc. that are far less messy. Just got to get round to writing it all down in a coherantmanner for a posting… a bit annoying it cannot resolve all softorbits bad programming practices but it does help a bit so I guess it could be worthwhile if one must install softorbits software which is mediocre at best once you’ve mitigated all the bad actor installation and programming practices.

    #24280412 Reply | Quote
    Robert
    Guest

    @TK. Hi. Thank you for your reply. I have used symbolic links. Do you have another method for moving other software besides this bloody softorbits?
    I put here an example for other people who want to use symbolic links:

    Open a command prompt with administrative rights and type : (“D:\softorbits” may be anything else)
    mklink /d “C:\users\my user name\appdata\roaming\softorbits” “D:\softorbits”

    IMPORTANT : Before using this command, the content of the folder “softorbits” in
    “C:\users\my user name\appdata\roaming\softorbits” must have been copied manually to D:\softorbits, or any other place, and this content (not the folder itself) MUST have been been deleted from its original place on C:

    The free soft “treesizefree” allows us to see the real size of the original folder on C: (now 0 bytes) because Explorer or other file managers don’t show the real size of zero bytes but the old full size. They only show a little arrow on the folder icon to alert us that a symbolic link is in action on this folder.

    #24283287 Reply | Quote
    TK
    Guest

    [@Robert] the method I’ve used does not use symbolic links… no command line is used… question does that work well and survive uninstalls? “my” method uses disk-management UI to assign the entire other partition to an empty SoftOrbits folder after renaming the original SoftOrbits folder, without any Softobits program running of course. to SoftOrbits1 and then after making that folder point to the new partition add an everyone user group to the linking empty folder to deny writes to hopefully prevent it from being deleted by a future uninstall… then move all the files and folders from Softorbits1 folder to the new Softorbits folder which puts them all over to the other partition/drive letter. MY advice if the mklink command works fine for you then stick with it… It might be useful to move all the wasteful EBWebview folders from the appdata\local\appspecific folder\EBWebview from lazy developers misusing a an in app web-browser rendering engine to create an offline GUI because it’s simpler than using any of the established low impact GUI frameworks in existence. And avoid potential name collisions if multiple folders are redirected to the same partitions root of the filesystem.

    Personally I don’t find Softorbits software to be particularly well written or uniquely functional, often stealing other developers code and repackaging it in their bloody minded installers… I only devised the redirection method so I can test them without causing unwanted writes to my system drive and put the files on a different non-system SSD that is obviously less stressed.

Viewing 13 posts - 16 through 28 (of 28 total)
Reply To: Reply #24275144 in AFKSecurity / Oct 1 2026