


                   Frequently Asked Questions about F/WIN
                   ======================================


I ALREADY HAVE A VIRUS SCANNER.  WHY USE F/WIN?

     a.   F/WIN uses heuristic detection for macro viruses that
          infect Microsoft Word documents.  That means it can
          find known and UNKNOWN macro viruses and trojans, as
          well as deliberate acts of sabotage in Word macros.

     b.   F/WIN can remove known and unknown macro viruses. A lot
          of the regular antivirus programs can only detect macro
          viruses and of course they only can remove KNOWN
          viruses.  F/WIN is able to clean an infected document
          which had macros installed before infection.  Only the
          virus macros will be removed in this case.

     c.   F/WIN offers a complex heuristic which has a very high
          detection ratio but also has very little false
          positives on harmless files.  The heuristic detection
          allows F/WIN to produce a detailed virus analysis.

     d.   F/WIN offers full OLE 2.0 support and is able to
          correctly handle very large and complex Word documents
          without problems.  F/WIN does not use the defective
          OLE2.DLL or OLE32.DLL for accessing Word documents.
          F/WIN will also handle Macintosh and Asian Word
          documents.

     e.   F/WIN is a passive scanner.  That means you don't have
          to use Word templates to defend yourself against macro
          viruses.  These templates are no real safe protection,
          and of course, you will need Winword for using them.
          F/WIN is a DOS based virus scanner and doesn't stay
          resident in memory.

     f.   F/WIN can detect and remove the only known PE-EXE
          (Windows 95 viruses).

     g.   F/WIN can detect known and unknown viruses that infect
          Windows EXE files which use the <Winsurfer> or <Ph33r>
          infection scheme like <Tentacle>.

     h.   F/WIN is inexpensive, especially when considering the
          protection that it provides.




SHOULD I REPLACE MY EXISTING SCANNER WITH F/WIN?

     No.  F/WIN is a specialized scanner that is intended to
     supplement the one you currently have. By now, there are
     more than 10000 known viruses for DOS, but only about
     250 Windows specific Macro and EXE viruses.  You will need
     a normal DOS antivirus program, of course.  However, it's
     likely that the number of Windows viruses will increase
     in the future.  Macro viruses like <Concept> or <Wazzu> are
     already considered as being more common than boot viruses
     like <Monkey.B>, <NYB> or <Form.A>.



DOES F/WIN DETECT MACRO VIRUSES IN OTHER SOFTWARE LIKE AMIPRO,
WORD PERFECT, ETC.?

     At this time it does not.  That is a feature we hope to add
     to it at a future date.  So far, F/WIN only detects macro
     viruses in Microsoft Word 6.0 and 7.0 documents.  The known
     non-Winword macro viruses like AmiPro.Green_Stripe,
     Excel.Laroux or Excel.Sofa aren't reported to be common.



HOW OFTEN WILL F/WIN BE UPDATED?

     Because of it's heuristic nature, F/WIN doesn't need regular
     updates like normal virus scanners.  Normally, updates will
     be released to provide bug fixes or add new features, and
     will appear at least every two months.  Of course customers
     will be provided with a new version if they detect a virus
     which F/WIN missed.



HOW WILL I RECEIVE UPDATES?

     Because the FWIN.KEY is valid for every new version, you
     just need to download the shareware version from your local
     BBS or FTP/WWW site and replace the FWIN.EXE file!  The
     latest shareware version of F/WIN is available at:

     http://www.fwin.com                        (Homepage)
     http://www.psnw.com/~joe
     http://www.cyberbox.north.de               (German site)

     The program is released as a ZIP archive and will have a
     file name like FWIN402E.ZIP (English version) and
     FWIN402G.ZIP (German version).



HOW SAFE IS F/WIN?  CAN IT DESTROY MY DOCUMENTS?

     The cleaning process has proven to be safe in our tests.
     But if for some reason it would damage your document, it
     makes a backup of it before attempting to remove the virus.
     The backup allows you to try a different method for cleaning
     or to recover the file if the cleaning process failed.
     F/WIN will not modify a file when it fails to create a backup
     of the infected file before.



HOW QUICKLY WILL I GET A REPLY TO QUESTIONS?

     As we both aren't full-time virus researchers, we can't
     always respond at once.  We will check our accounts at
     least one time a day, so you will get answers within one or
     two days. We will do our best to get to you as quickly as
     possible.  If you are e-mailing us about a current virus
     emergency, please put "VIRUS EMERGENCY" in the SUBJECT line
     of your e-mail message.  Those messages will be given first
     priority.


WHY SHOULD I CHOOSE F/WIN OVER OTHER AV PRODUCTS TO PROTECT
AGAINST WORD MACRO VIRUSES?

     F/WIN was designed from the beginning by its author (Stefan
     Kurtzhals) to be able to detect and remove known and unknown
     viruses and trojans, while at the same time allowing Word
     users to go on using WordBasic macros they wanted to use.
     While most Word users don't use WordBasic macros, many do.
     And those that do, often find these macros to be real
     time-savers because they automate repetitive, tedious
     processes that would normally have to be done manually.

     F/WIN Anti-virus has built into it profiles of how viruses
     and trojans "behave".  If it finds macros that fit the
     pattern, it warns the user so that they can choose whether
     or not to remove the macros.  These build-in behavior
     profiles offer several advantages to F/WIN users:

     1.   Users can go on using most, if not all of the macros
          they currently use without having to deal with endless
          false alarms.  If a product produces too many false
          alarms, users will simply quit using it and leave
          themselves with little or no defenses.  The heuristic
          detection of F/WIN is very well balanced and has only
          very little false positives.

     2.   F/WIN distinguishes between a trojan and a virus.  This
          can be important for a user to know for damage
          assessment purposes, because viruses spread themselves
          to other files.  Trojans don't.

     3.   F/WIN doesn't just say it's found potentially dangerous
          macros like some products do.  It goes a step further
          and tells the user exactly what suspicious behavior it
          has found.  The user gets a detailed report about the
          possible damages the virus might cause.

     4.   F/WIN uses an optimized OLE 2.0 file access and does
          properly handle the complex Word Document format.
          It does not need to rely on the defective OLE2.DLL
          and OLE32.DLL.


F/WIN IS A DOS PROGRAM.  WILL IT HANDLE THE LONG FILE NAMES
WINDOWS 95 USES?

     Yes it will.  We have tested F/WIN in the following
     environments:

     PC DOS (5.0+)
     MS DOS (5.0+)
     Windows 3.x
     Windows 95 (DOS 7.0)
     Windows NT 3.51
     Windows NT 4.00
     OS/2 Warp 3.0, 4.0 (from a DOS window)

     There is an advantage to using a DOS version in Windows 95
     and Windows 3.x.  If a virus or trojan deletes or damages
     critical files that Windows 3.x or Windows 95 uses, you
     can't get into those environments to run your virus scanner.
     In the case of either Widows 3.x or Windows 95, you could
     boot from a floppy (or not), and still be able to run F/WIN
     to find the culprit.  Most anti-virus programs offer a DOS
     versions for situation like this, but there are some that
     don't.  Remember, if a virus manages to infect your system,
     Windows will most likely not start up and you can't use your
     Windows based antivirus program.  It is strongly recommended
     to boot from a DOS boot disk before trying to remove a
     virus.

