Turkey's native antivirus announced "CHOMAR"

Status
Not open for further replies.

roger_m

Level 42
Verified
Top Poster
Content Creator
Dec 4, 2014
3,135
I'm downloading this right now. The size of the installer is massive, about 930MB in size. The online installer was going to take a long time to download it, so I'm downloading the offline installer using a download manager to speed up the download.

I have very low expectations for this antivirus. Usually these little known antiviruses, have terrible detection rates and big issues with false positives (unless they are using a well know AV engine rather then their own one). But, I have a spare computer to try it on, so I figured why not.
 
Last edited:

roger_m

Level 42
Verified
Top Poster
Content Creator
Dec 4, 2014
3,135
I've been giving it a try. When installing it, the license agreement is only shown in Turkish. However you can copy the license agreement text. So you would be able to paste it into Google Translate if you felt the need to read it. Apart from the license agreement, everything else is in English.

The user interface actually looks really nice, and is entirely in English. However, as you will see from the screenshots, the configuration options are extremly limited. Any threats detected by the realtime protection or on demand scans are auto quarantined, and there is no way to change this behaviour. There is no proactive protection.

I ran a scan on a malware pack from early in the month (with just 6 samples), and nothing was detected. Next, I scanned over 6 gigs of installers on a flash drive (this laptop only has USB 2.0), which includes many PUPs. The scan took just over 5 minutes to complete. Eighteen files were detected and automatically quarantined. Nine of these files were detected as UnclassifedMalware. One of these is a definite false positive, while the others could be considered PUPs. It would be better if they were actually detected as PUPs, but sadly it is very common for harmless PUPs to be detected by antiviruses as malware. Also, there was one more false positive.

Subsequent scans of the same folder, were completed in just two seconds.

When restoring files from quarantine, there is an exception option, which I thought would whitelist files when restoring them. However, it restores files without whitelisting them, and they are detected again when you do a subsequent scan. There is no option to manually exclude files or folders.

Chomar.png Chomar1.0.png Chomar1.1.png
Chomar2.png Chomar3.1.png Chomar3.2.png
Chomar3.3.png Chomar3.png Chomar4.png
 
Last edited:

mal1

Level 4
Verified
Well-known
Oct 1, 2015
183
I think "native" in the title of the topic seems inaccurate or even misleading (what do you expect from Google translate?). It suggests Chomar is the first/only Turkish antimalware vendor (it's not, Zemana is Turkish too). It could also imply that Chomar is only for Turkish natives/speakers...
I don't speak Turkish, but I think "yerli" here meant domestic, local or locally produced/made.

Chomar antivirus for android has a rating of 4.9 on Google play store (+2000 users), not bad at all!
 

Combofix

Level 1
Thread author
Oct 12, 2015
14
Zemana use another substructur ( from hitmanpro) and if i remember correctly long time ago they shared with Sunbelt. Chomar has own engine so native is mean developed everything from Turkish people. But they want to using from global.
Chomar pronunce with same in Turkish Çomar . Çomar is bandog so they use this logo.
And got OPSWAT Gold certificate.
 
Last edited:

Tsiehshi

Level 2
Verified
Nov 11, 2017
51
It looks rather shady to me.

When I decided to watch some reviews, I saw that some of its detection names match with those of ClamAV and the unique part of Baidu's engine despite their claims of using a completely unique engine.

In this video, you can see Win.Worm.Cekar.48 and HackTool.Win32.Crack.XZ. After Googling them, it turned out that the former is on one of ClamAV's virus lists, and searching for Win.Worm.Cekar (not the complete name, but still) also led here. I couldn't find any exact match for the latter, but HackTool.Win32.Crack leads to Baidu.

Also, the detection names seen in the test on this very page are PUP.Win32.OpenCandy.D, Adware.Win32.SpeedingUpMyPC.AM, PUP.Win32.DownloadGuide.H, PUP.NSIS.FakeAV.BT, Win.Worm.Wiking-2428, Adware.Win32.RegDefense and Adware.Win32.RegUtility.A. Adware.Win32.SpeedingUpMyPC.AM seems to be linked to Baidu.

I then emailed them, but they pretty much responded that it's just a coincidence.
 
Last edited:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top