Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

74fff 42.11%
2adf9 5.26%
b1c6c 15.79%
7e41f 5.26%
30091 5.26%
dce71 10.53%
75e85 5.26%
1eba2 5.26%
d0cff 5.26%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenServiceA, ControlService, QueryServiceStatus, DeleteService, OpenSCManagerA, CreateServiceA, CloseServiceHandle, SetServiceStatus, RegisterServiceCtrlHandlerA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, StartServiceCtrlDispatcherA
gdi32.dll
Escape, ExtTextOutA, TextOutA, RectVisible, PtVisible, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SetMapMode, GetStockObject, SelectObject, RestoreDC, GetClipBox, CreateBitmap, SetTextColor, SetBkColor, GetObjectA, GetDeviceCaps, DeleteObject, DeleteDC, SaveDC
kernel32.dll
FreeLibrary, LoadLibraryA, LocalAlloc, TlsAlloc, GlobalFree, GlobalUnlock, GlobalHandle, GlobalLock, GlobalReAlloc, GlobalAlloc, TlsSetValue, LocalReAlloc, TlsGetValue, GetProcessVersion, lstrcmpA, GlobalFlags, GetCPInfo, GetOEMCP, WriteFile, SetFilePointer, FlushFileBuffers, RtlUnwind, RaiseException, GetStartupInfoA, GetCommandLineA, HeapAlloc, HeapFree, ExitThread, HeapSize, HeapReAlloc, TerminateProcess, GetACP, SetUnhandledExceptionFilter, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, HeapDestroy, HeapCreate, VirtualFree, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, VirtualAlloc, IsBadWritePtr, IsBadReadPtr, IsBadCodePtr, SetStdHandle, GetVersion, lstrcatA, GlobalGetAtomNameA, lstrcmpiA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, lstrcpyA, GetModuleHandleA, GetProcAddress, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, lstrcpynA, SetLastError, CreateEventA, SuspendThread, GetCurrentThreadId, SetThreadPriority, ResumeThread, SetEvent, WaitForSingleObject, MultiByteToWideChar, InterlockedDecrement, InterlockedIncrement, lstrlenA, WideCharToMultiByte, GetModuleFileNameA, CreateMutexA, CreateThread, CreateNamedPipeA, ConnectNamedPipe, ReadFile, FormatMessageA, LocalLock, LocalFree, GetLogicalDrives, DeviceIoControl, Sleep, GetPrivateProfileStringA, ExitProcess, GetLocalTime, WritePrivateProfileStringA, GetLastError, CreateFileA, GetCurrentProcess, CloseHandle, GetEnvironmentVariableA, GetVersionExA
shlwapi.dll
PathFileExistsA
user32.dll
MessageBoxA, GetTopWindow, EnableWindow, CopyRect, GetClientRect, AdjustWindowRectEx, SetFocus, GetSysColor, MapWindowPoints, LoadIconA, SetWindowTextA, IsWindowEnabled, GetSysColorBrush, ReleaseDC, GetDC, GetClassNameA, PtInRect, ClientToScreen, PostQuitMessage, DestroyMenu, TabbedTextOutA, DrawTextA, GrayStringA, GetCapture, GetClassInfoA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetDlgItem, GetWindowTextA, GetDlgCtrlID, DestroyWindow, GetClassLongA, SetPropA, UnhookWindowsHookEx, GetPropA, CallWindowProcA, RemovePropA, GetMessageTime, GetMessagePos, GetLastActivePopup, GetForegroundWindow, SetForegroundWindow, GetWindow, GetWindowLongA, SetWindowLongA, SetWindowPos, RegisterWindowMessageA, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetSystemMetrics, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, GetFocus, GetParent, GetNextDlgTabItem, LoadStringA, GetActiveWindow, SendMessageA, GetKeyState, ValidateRect, IsWindowVisible, PeekMessageA, GetCursorPos, SetWindowsHookExA, WinHelpA, FindWindowA, PostMessageA, LoadCursorA, RegisterClassExA, CreateWindowExA, ShowWindow, DefWindowProcA, DispatchMessageA, TranslateMessage, GetMessageA, TranslateAcceleratorA, LoadAcceleratorsA, UpdateWindow, CallNextHookEx
winspool.drv
OpenPrinterA, DocumentPropertiesA, ClosePrinter

chgservice.exe

Remove chgservice.exe
MD5:   74fffb94d7ffd4750bd429ccb197720e
SHA1:   148e4084f88614b4f0dc4cf4d410b97c1c4630bc
SHA256:   15d94da7b545f9b5591e87818c96aa1fe4d3db60c2260c7e4f8f56dd32b4e147

Overview

chgservice.exe runs as a service under the name Change Modem Device Service with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including 3.5G Connect published by iBall Baton, 3.5G Connect from iBall Baton and 3.5G Connect by iBall Baton.

DetailsDetails

File name:chgservice.exe
Typical file path:C:\windows\syswow64\chgservice.exe
Size:132 KB (135,168 bytes)
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Huawei Technologies Co.,Ltd
11% remove
Huawei Technologies Co.,Ltd
11% remove
iBall Baton
9% remove
Connect GSM / CDMA USB modem to router USB port & access Internet Anytime... Anywhere. Complies with IEEE 802.11b/g/n standards. With Auto-load sharing between fixed Broadband connection and 3G internet. Wireless security such as WEP, WPA-PSK & WPA2-PSK. With Firewall features such as IP, MAC, Domain filtering & DDNS.
Thesycon GmbH
3% remove

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Change Modem Device Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00043931%
0.028634%
Kernel CPU:0.00006445%
0.013761%
User CPU:0.00037486%
0.014873%
Kernel CPU time:12 ms/min
100,923,805ms/min
CPU cycles:1,098/sec
17,470,203/sec
Memory
Private memory:839 KB
21.59 MB
Private (maximum):2.61 MB
Private (minimum):1.97 MB
Non-paged memory:839 KB
21.59 MB
Virtual memory:30.18 MB
140.96 MB
Virtual memory (peak):31.93 MB
169.69 MB
Working set:2 MB
18.61 MB
Working set (peak):2.81 MB
37.95 MB
Page faults:768/min
2,039/min
I/O
I/O other transfer:0 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:4
12
Handles:40
600
GUI GDI count:13
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command lines:
  • "C:\Windows\System32\chgservice.exe" -service
  • "C:\faiyas\system32\chgservice.exe" -service
  • "C:\windows\syswow64\chgservice.exe" -service
Owner:SYSTEM
Windows Service
Service name:Change Modem Device Service
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 36.84%
Microsoft Windows XP 31.58%
Windows 7 Home Premium 15.79%
Windows 7 Professional 10.53%
Windows 7 Home Basic 5.26%

Distribution by countryDistribution by country

India installs about 47.37% of chgservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 40.00%
American Megatrends 20.00%
Hewlett-Packard 20.00%
Acer 20.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE