Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

74fff 42.11%
2adf9 5.26%
b1c6c 15.79%
7e41f 5.26%
30091 5.26%
dce71 10.53%
75e85 5.26%
1eba2 5.26%
d0cff 5.26%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenServiceA, ControlService, QueryServiceStatus, DeleteService, OpenSCManagerA, CreateServiceA, CloseServiceHandle, SetServiceStatus, RegisterServiceCtrlHandlerA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, StartServiceCtrlDispatcherA
gdi32.dll
Escape, ExtTextOutA, TextOutA, RectVisible, PtVisible, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SetMapMode, GetStockObject, SelectObject, RestoreDC, GetClipBox, CreateBitmap, SetTextColor, SetBkColor, GetObjectA, GetDeviceCaps, DeleteObject, DeleteDC, SaveDC
kernel32.dll
FreeLibrary, LoadLibraryA, LocalAlloc, TlsAlloc, GlobalFree, GlobalUnlock, GlobalHandle, GlobalLock, GlobalReAlloc, GlobalAlloc, TlsSetValue, LocalReAlloc, TlsGetValue, GetProcessVersion, lstrcmpA, GlobalFlags, GetCPInfo, GetOEMCP, WriteFile, SetFilePointer, FlushFileBuffers, RtlUnwind, RaiseException, GetStartupInfoA, GetCommandLineA, HeapAlloc, HeapFree, ExitThread, HeapSize, HeapReAlloc, TerminateProcess, GetACP, SetUnhandledExceptionFilter, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, HeapDestroy, HeapCreate, VirtualFree, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, VirtualAlloc, IsBadWritePtr, IsBadReadPtr, IsBadCodePtr, SetStdHandle, GetVersion, lstrcatA, GlobalGetAtomNameA, lstrcmpiA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, lstrcpyA, GetModuleHandleA, GetProcAddress, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, lstrcpynA, SetLastError, CreateEventA, SuspendThread, GetCurrentThreadId, SetThreadPriority, ResumeThread, SetEvent, WaitForSingleObject, MultiByteToWideChar, InterlockedDecrement, InterlockedIncrement, lstrlenA, WideCharToMultiByte, GetModuleFileNameA, CreateMutexA, CreateThread, CreateNamedPipeA, ConnectNamedPipe, ReadFile, FormatMessageA, LocalLock, LocalFree, GetLogicalDrives, DeviceIoControl, Sleep, GetPrivateProfileStringA, ExitProcess, GetLocalTime, WritePrivateProfileStringA, GetLastError, CreateFileA, GetCurrentProcess, CloseHandle, GetEnvironmentVariableA, GetVersionExA
shlwapi.dll
PathFileExistsA
user32.dll
MessageBoxA, GetTopWindow, EnableWindow, CopyRect, GetClientRect, AdjustWindowRectEx, SetFocus, GetSysColor, MapWindowPoints, LoadIconA, SetWindowTextA, IsWindowEnabled, GetSysColorBrush, ReleaseDC, GetDC, GetClassNameA, PtInRect, ClientToScreen, PostQuitMessage, DestroyMenu, TabbedTextOutA, DrawTextA, GrayStringA, GetCapture, GetClassInfoA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetDlgItem, GetWindowTextA, GetDlgCtrlID, DestroyWindow, GetClassLongA, SetPropA, UnhookWindowsHookEx, GetPropA, CallWindowProcA, RemovePropA, GetMessageTime, GetMessagePos, GetLastActivePopup, GetForegroundWindow, SetForegroundWindow, GetWindow, GetWindowLongA, SetWindowLongA, SetWindowPos, RegisterWindowMessageA, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetSystemMetrics, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, GetFocus, GetParent, GetNextDlgTabItem, LoadStringA, GetActiveWindow, SendMessageA, GetKeyState, ValidateRect, IsWindowVisible, PeekMessageA, GetCursorPos, SetWindowsHookExA, WinHelpA, FindWindowA, PostMessageA, LoadCursorA, RegisterClassExA, CreateWindowExA, ShowWindow, DefWindowProcA, DispatchMessageA, TranslateMessage, GetMessageA, TranslateAcceleratorA, LoadAcceleratorsA, UpdateWindow, CallNextHookEx
winspool.drv
OpenPrinterA, DocumentPropertiesA, ClosePrinter

chgservice.exe

Remove chgservice.exe
MD5:   75e85aa5c84fe5f9a8adce95327b763f
SHA1:   4ae85ddf610812e5cfdf21943959f7802a866674
SHA256:   347a392cf51a90f8b9caa0a55a4939ef0147104646325472af6a3d5ff6ad7170

Overview

chgservice.exe runs as a service under the name Change Modem Device Service with extensive SYSTEM privileges (full administrator access).

DetailsDetails

File name:chgservice.exe
Typical file path:C:\windows\syswow64\chgservice.exe
Size:132 KB (135,168 bytes)
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Change Modem Device Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00035254%
0.028634%
Kernel CPU:0.00025228%
0.013761%
User CPU:0.00010026%
0.014873%
Kernel CPU time:780,005 ms/min
100,923,805ms/min
Memory
Private memory:1.21 MB
21.59 MB
Private (maximum):3.18 MB
Private (minimum):3.14 MB
Non-paged memory:1.21 MB
21.59 MB
Virtual memory:49.72 MB
140.96 MB
Virtual memory (peak):51.7 MB
169.69 MB
Working set:3.16 MB
18.61 MB
Working set (peak):3.82 MB
37.95 MB
Resource allocations
Threads:4
12
Handles:93
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\ProgramData\chgservice.exe" -service
Owner:SYSTEM
Windows Service
Service name:Change Modem Device Service
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 36.84%
Microsoft Windows XP 31.58%
Windows 7 Home Premium 15.79%
Windows 7 Professional 10.53%
Windows 7 Home Basic 5.26%

Distribution by countryDistribution by country

India installs about 47.37% of chgservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 40.00%
American Megatrends 20.00%
Hewlett-Packard 20.00%
Acer 20.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE