What Is the Role of winws.exe in Zapret's DPI Bypass Mechanism?

winws.exe is the core user-space executable that implements Zapret's DPI bypass by capturing network packets via the WinDivert driver, applying port-specific filters, and reinjecting modified traffic to evade deep packet inspection.

Flowseal/zapret-discord-youtube relies on winws.exe as the primary packet-processing engine in its DPI bypass stack. Located in the repository's bin directory, this binary orchestrates traffic interception alongside the WinDivert kernel driver to circumvent network-level blocking. Understanding its role reveals how the tool modifies packet signatures in real-time without requiring VPN tunnels.

Core Architecture of winws.exe in the Bypass Stack

winws.exe functions as the user-space counterpart to the WinDivert kernel driver, forming a complete DPI evasion system. While WinDivert operates at the network stack level to intercept raw packets, winws.exe implements the high-level logic that determines how to modify that traffic.

The binary resides at bin/winws.exe and is invoked by various batch strategies with specific filtering arguments. According to the repository documentation, when a strategy is executed, winws.exe appears in the Windows Task Manager, indicating the bypass is actively processing traffic (README.md line 83).

How winws.exe Intercepts and Modifies Packets

The executable leverages the WinDivert API to capture packets before they reach the operating system's standard network stack. This interception happens at the Windows Filtering Platform (WFP) layer, allowing winws.exe to inspect and rewrite packet headers—including TCP and UDP metadata—before reinjecting the traffic.

When launched, winws.exe accepts filter arguments such as --wf-tcp=80,443 and --wf-udp to specify which traffic streams require modification. These parameters dictate that only packets destined for common web ports (or other specified ranges) undergo DPI bypass processing, while leaving other network traffic untouched. The binary effectively "fakes" legitimate protocol handshakes—particularly TLS/SSL signatures—to prevent deep packet inspection systems from identifying and blocking the traffic.

Launch Strategies and Process Management

Batch Script Execution

Each strategy file (such as general.bat) launches winws.exe with predefined port configurations. The script executes the binary with specific filter sets:

rem Located in general.bat line 16 - launches winws.exe with default filters
"%BIN%winws.exe" --wf-tcp=80,443 --wf-udp=443,5000-5010

When this executes, the process spawns in the background and remains active until manually terminated or the system restarts.

Windows Service Installation

For persistent operation, service.bat can install winws.exe as a system service that starts automatically on boot. The installation occurs via the Windows sc command:

rem From service.bat line 349 - creates the persistent service
sc create zapret_service binPath= "%BIN_PATH%winws.exe" start= auto

Once installed, the service runs winws.exe continuously without requiring an active user session, ensuring the DPI bypass remains active across system restarts.

Status Verification and Termination

The repository provides multiple mechanisms to monitor and control the winws.exe lifecycle. To check if the process is running:

rem From service.bat line 151 - checks active processes
tasklist /FI "IMAGENAME eq winws.exe"

If the process terminates unexpectedly while the WinDivert driver remains loaded, service.bat detects this condition and performs cleanup operations (service.bat line 572).

To manually stop the bypass:

rem From service.bat line 201 - force terminates the executable
taskkill /IM winws.exe /F

Additionally, PowerShell-based utilities in utils/test zapret.ps1 query process status using Get-CimInstance to verify the executable is responding correctly (test ps1 line 559).

Practical Commands for Managing winws.exe

Start the DPI bypass using the general strategy:

call general.bat

Verify the bypass is active by checking for the process:

tasklist /FI "IMAGENAME eq winws.exe" /FO TABLE

Install as a persistent background service:

service.bat
rem Select "Install Service" from the interactive menu

Cleanly stop the service and remove the process:

sc stop zapret_service
taskkill /IM winws.exe /F

Summary

  • winws.exe serves as the user-space engine that implements DPI bypass logic in the Flowseal/zapret-discord-youtube repository.
  • It partners with the WinDivert driver to capture, modify, and reinject network packets at the Windows Filtering Platform layer.
  • The executable accepts port-specific filters (--wf-tcp, --wf-udp) to target only traffic that requires obfuscation.
  • Batch scripts like general.bat launch the process, while service.bat can install it as a persistent Windows service (service.bat line 349).
  • Lifecycle management is handled through standard Windows tools (tasklist, taskkill) and PowerShell cmdlets (utils/test zapret.ps1 line 559).

Frequently Asked Questions

What happens if winws.exe crashes but WinDivert remains loaded?

If winws.exe terminates unexpectedly while the WinDivert driver is still active, the system may experience network connectivity issues. The service.bat script detects this condition (service.bat line 572) and attempts to clean up the orphaned driver using sc delete WinDivert or similar recovery commands to restore normal networking.

How can I verify that winws.exe is actively modifying traffic?

Run tasklist /FI "IMAGENAME eq winws.exe" (service.bat line 151) to confirm the process is running. For deeper verification, inspect the WinDivert service status—when winws.exe is active, the driver should show as running in sc query WinDivert. Network traffic to filtered ports (like 443) should successfully reach destinations that were previously blocked by DPI.

Can multiple instances of winws.exe run simultaneously?

Running multiple instances is not recommended and typically prevented by the service installation logic. The service.bat script creates a single named service entry (service.bat line 349), and attempting to launch additional standalone instances may cause port conflicts or unpredictable behavior with the WinDivert driver.

Why does winws.exe require administrative privileges?

The executable requires elevation to communicate with the WinDivert kernel driver, which operates at the system level to intercept all network packets. Without administrator rights, winws.exe cannot open the necessary handles to the Windows Filtering Platform or modify packet headers in transit. The batch scripts automatically request elevation via UAC prompts when starting the bypass.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →