Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

74fff 42.11%
2adf9 5.26%
b1c6c 15.79%
7e41f 5.26%
30091 5.26%
dce71 10.53%
75e85 5.26%
1eba2 5.26%
d0cff 5.26%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenServiceA, ControlService, QueryServiceStatus, DeleteService, OpenSCManagerA, CreateServiceA, CloseServiceHandle, SetServiceStatus, RegisterServiceCtrlHandlerA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, StartServiceCtrlDispatcherA
gdi32.dll
Escape, ExtTextOutA, TextOutA, RectVisible, PtVisible, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SetMapMode, GetStockObject, SelectObject, RestoreDC, GetClipBox, CreateBitmap, SetTextColor, SetBkColor, GetObjectA, GetDeviceCaps, DeleteObject, DeleteDC, SaveDC
kernel32.dll
FreeLibrary, LoadLibraryA, LocalAlloc, TlsAlloc, GlobalFree, GlobalUnlock, GlobalHandle, GlobalLock, GlobalReAlloc, GlobalAlloc, TlsSetValue, LocalReAlloc, TlsGetValue, GetProcessVersion, lstrcmpA, GlobalFlags, GetCPInfo, GetOEMCP, WriteFile, SetFilePointer, FlushFileBuffers, RtlUnwind, RaiseException, GetStartupInfoA, GetCommandLineA, HeapAlloc, HeapFree, ExitThread, HeapSize, HeapReAlloc, TerminateProcess, GetACP, SetUnhandledExceptionFilter, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, HeapDestroy, HeapCreate, VirtualFree, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, VirtualAlloc, IsBadWritePtr, IsBadReadPtr, IsBadCodePtr, SetStdHandle, GetVersion, lstrcatA, GlobalGetAtomNameA, lstrcmpiA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, lstrcpyA, GetModuleHandleA, GetProcAddress, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, lstrcpynA, SetLastError, CreateEventA, SuspendThread, GetCurrentThreadId, SetThreadPriority, ResumeThread, SetEvent, WaitForSingleObject, MultiByteToWideChar, InterlockedDecrement, InterlockedIncrement, lstrlenA, WideCharToMultiByte, GetModuleFileNameA, CreateMutexA, CreateThread, CreateNamedPipeA, ConnectNamedPipe, ReadFile, FormatMessageA, LocalLock, LocalFree, GetLogicalDrives, DeviceIoControl, Sleep, GetPrivateProfileStringA, ExitProcess, GetLocalTime, WritePrivateProfileStringA, GetLastError, CreateFileA, GetCurrentProcess, CloseHandle, GetEnvironmentVariableA, GetVersionExA
shlwapi.dll
PathFileExistsA
user32.dll
MessageBoxA, GetTopWindow, EnableWindow, CopyRect, GetClientRect, AdjustWindowRectEx, SetFocus, GetSysColor, MapWindowPoints, LoadIconA, SetWindowTextA, IsWindowEnabled, GetSysColorBrush, ReleaseDC, GetDC, GetClassNameA, PtInRect, ClientToScreen, PostQuitMessage, DestroyMenu, TabbedTextOutA, DrawTextA, GrayStringA, GetCapture, GetClassInfoA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetDlgItem, GetWindowTextA, GetDlgCtrlID, DestroyWindow, GetClassLongA, SetPropA, UnhookWindowsHookEx, GetPropA, CallWindowProcA, RemovePropA, GetMessageTime, GetMessagePos, GetLastActivePopup, GetForegroundWindow, SetForegroundWindow, GetWindow, GetWindowLongA, SetWindowLongA, SetWindowPos, RegisterWindowMessageA, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetSystemMetrics, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, GetFocus, GetParent, GetNextDlgTabItem, LoadStringA, GetActiveWindow, SendMessageA, GetKeyState, ValidateRect, IsWindowVisible, PeekMessageA, GetCursorPos, SetWindowsHookExA, WinHelpA, FindWindowA, PostMessageA, LoadCursorA, RegisterClassExA, CreateWindowExA, ShowWindow, DefWindowProcA, DispatchMessageA, TranslateMessage, GetMessageA, TranslateAcceleratorA, LoadAcceleratorsA, UpdateWindow, CallNextHookEx
winspool.drv
OpenPrinterA, DocumentPropertiesA, ClosePrinter

chgservice.exe

Remove chgservice.exe
MD5:   30091bfa32c615cc41abc8352e9c76ee
SHA1:   d118975210b109642d3c1e3f0f5fad8bf3b715f0
SHA256:   1ffb49da4ab0f8d5a4f9f397eb3b1e99630de4573a6c44e9b154304e10be7151

Overview

chgservice.exe runs as a service under the name Change Modem Device Service with extensive SYSTEM privileges (full administrator access).

DetailsDetails

File name:chgservice.exe
Typical file path:C:\windows\syswow64\chgservice.exe
Size:132 KB (135,168 bytes)
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Change Modem Device Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
Memory
Private memory:1.32 MB
21.59 MB
Private (maximum):3.25 MB
Private (minimum):96 KB
Non-paged memory:1.32 MB
21.59 MB
Virtual memory:31.55 MB
140.96 MB
Virtual memory (peak):35.77 MB
169.69 MB
Working set:504 KB
18.61 MB
Working set (peak):3.27 MB
37.95 MB
Resource allocations
Threads:4
12
Handles:48
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Windows\System32\chgservice.exe" -service
Owner:SYSTEM
Windows Service
Service name:Change Modem Device Service
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 36.84%
Microsoft Windows XP 31.58%
Windows 7 Home Premium 15.79%
Windows 7 Professional 10.53%
Windows 7 Home Basic 5.26%

Distribution by countryDistribution by country

India installs about 47.37% of chgservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 40.00%
American Megatrends 20.00%
Hewlett-Packard 20.00%
Acer 20.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE