WireFox v1.0.6
WireFox bridges the missing link of WireGuard on Windows: intelligent background roaming and kernel-level tunnel watchdog protection.
📝 What's New in v1.0.6
- Graceful Tunnel Teardown & SCM Protection:
- Extended SCM service stop timeout from 3s to 8s, allowing Windows NDIS and the Wintun kernel miniport sufficient time to dismantle routes and unbind adapters cleanly without throwing false
TimeoutExceptionerrors. - Eliminated premature force-killing of services in
StopPendingstate. - Replaced high-frequency
wg.exe show interfacesconsole subprocess polling during adapter settle with in-memory .NET BCL adapter checks. - Guaranteed clean disposal of
ServiceControllerhandles prior to any service deletion, preventing Win32 Error 1072 (ERROR_SERVICE_MARKED_FOR_DELETE). - Guarded
sc.exe deleteso healthy stops never delete the Windows service entry, enabling instant tunnel starts in under 1 second via existing service reuse without driver reinstallation.
- Extended SCM service stop timeout from 3s to 8s, allowing Windows NDIS and the Wintun kernel miniport sufficient time to dismantle routes and unbind adapters cleanly without throwing false
- Eliminated Redundant Teardown Churn on Trusted Networks:
- Prevented repeated invocations of
StopAllTunnelsAsync(),taskkill /F, and DNS cache flushing on routine DHCP lease renewals, Wi-Fi roaming events, or IPv6 address changes while safely sitting on trusted networks. - Replaced nuclear hard stops on trusted settle with gentle single-interface stops.
- Prevented repeated invocations of
- Automatic Stale Tunnel Recovery on Outage / Sleep Wake:
- Added proactive handshake freshness validation on untrusted network settle: if the WireGuard service remained alive across a prolonged network outage or sleep state but has a stale handshake, WireFox automatically refreshes the tunnel cleanly instead of idling in an unverified state.
- Refactored
ForceRestartTunnelAsync()to attempt a fast graceful restart first before escalating to nuclear wipeout. - Removed aggressive periodic
StopPendingforce-kills from background watchdog checks.
- WireGuard-Only Interface Scope Enforcement:
- Enforced strict WireGuard naming specification (
1-32chars,[a-zA-Z0-9_=+.-]) and SCM service backing (WireGuardTunnel$<name>) during tunnel discovery. - Prevents non-WireGuard synthetic adapters (Npcap packet capture drivers, VirtualBox/VMware bridges, NDIS filter miniports) from being detected as phantom tunnels, without relying on vendor-specific blacklists.
- Enforced strict WireGuard naming specification (
- UI & UX Polish:
- Fixed active tunnel name clipping on Card 1 in the Diagnostics page with text wrapping, max height constraints, and hover tooltips.
- Added instant toast notification feedback when running manual Diagnostic Scans.
- Enhanced Connection Details vitals on the Status page with bold category labels (
Gateway:,AP:,DNS:) and responsive wrapping. - Configured
TextWrapping="NoWrap"on the Live Log Console to enable smooth horizontal side-scrolling for long log strings and file paths.
Run PowerShell as Administrator to install or seamlessly upgrade in place:
irm https://raw.githubusercontent.com/TalviFox/WireFox/main/install.ps1 | iex🔒 Checksums & Binary Verification
| File | SHA-256 Checksum |
|---|---|
| WireFox.exe | affd9bb61acc70c57354edf49db3427dd42eb83b9e2cf9ad45f4b1cc95afa8ad |
| uninstall.ps1 | c19435cfbffd6288ae505579109a031c7d1983ea94af167c116a71ae442383c6 |
| verify.ps1 | b62465441f23f42c5cab181ea67366349a5780e8535fab9c72a4870b789ae0d7 |
Verify integrity before running (PowerShell):
irm https://raw.githubusercontent.com/TalviFox/WireFox/main/verify.ps1 | iex