Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

74fff 42.11%
2adf9 5.26%
b1c6c 15.79%
7e41f 5.26%
30091 5.26%
dce71 10.53%
75e85 5.26%
1eba2 5.26%
d0cff 5.26%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenServiceA, ControlService, QueryServiceStatus, DeleteService, OpenSCManagerA, CreateServiceA, CloseServiceHandle, SetServiceStatus, RegisterServiceCtrlHandlerA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, StartServiceCtrlDispatcherA
gdi32.dll
Escape, ExtTextOutA, TextOutA, RectVisible, PtVisible, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SetMapMode, GetStockObject, SelectObject, RestoreDC, GetClipBox, CreateBitmap, SetTextColor, SetBkColor, GetObjectA, GetDeviceCaps, DeleteObject, DeleteDC, SaveDC
kernel32.dll
FreeLibrary, LoadLibraryA, LocalAlloc, TlsAlloc, GlobalFree, GlobalUnlock, GlobalHandle, GlobalLock, GlobalReAlloc, GlobalAlloc, TlsSetValue, LocalReAlloc, TlsGetValue, GetProcessVersion, lstrcmpA, GlobalFlags, GetCPInfo, GetOEMCP, WriteFile, SetFilePointer, FlushFileBuffers, RtlUnwind, RaiseException, GetStartupInfoA, GetCommandLineA, HeapAlloc, HeapFree, ExitThread, HeapSize, HeapReAlloc, TerminateProcess, GetACP, SetUnhandledExceptionFilter, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, HeapDestroy, HeapCreate, VirtualFree, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, VirtualAlloc, IsBadWritePtr, IsBadReadPtr, IsBadCodePtr, SetStdHandle, GetVersion, lstrcatA, GlobalGetAtomNameA, lstrcmpiA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, lstrcpyA, GetModuleHandleA, GetProcAddress, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, lstrcpynA, SetLastError, CreateEventA, SuspendThread, GetCurrentThreadId, SetThreadPriority, ResumeThread, SetEvent, WaitForSingleObject, MultiByteToWideChar, InterlockedDecrement, InterlockedIncrement, lstrlenA, WideCharToMultiByte, GetModuleFileNameA, CreateMutexA, CreateThread, CreateNamedPipeA, ConnectNamedPipe, ReadFile, FormatMessageA, LocalLock, LocalFree, GetLogicalDrives, DeviceIoControl, Sleep, GetPrivateProfileStringA, ExitProcess, GetLocalTime, WritePrivateProfileStringA, GetLastError, CreateFileA, GetCurrentProcess, CloseHandle, GetEnvironmentVariableA, GetVersionExA
shlwapi.dll
PathFileExistsA
user32.dll
MessageBoxA, GetTopWindow, EnableWindow, CopyRect, GetClientRect, AdjustWindowRectEx, SetFocus, GetSysColor, MapWindowPoints, LoadIconA, SetWindowTextA, IsWindowEnabled, GetSysColorBrush, ReleaseDC, GetDC, GetClassNameA, PtInRect, ClientToScreen, PostQuitMessage, DestroyMenu, TabbedTextOutA, DrawTextA, GrayStringA, GetCapture, GetClassInfoA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetDlgItem, GetWindowTextA, GetDlgCtrlID, DestroyWindow, GetClassLongA, SetPropA, UnhookWindowsHookEx, GetPropA, CallWindowProcA, RemovePropA, GetMessageTime, GetMessagePos, GetLastActivePopup, GetForegroundWindow, SetForegroundWindow, GetWindow, GetWindowLongA, SetWindowLongA, SetWindowPos, RegisterWindowMessageA, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetSystemMetrics, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, GetFocus, GetParent, GetNextDlgTabItem, LoadStringA, GetActiveWindow, SendMessageA, GetKeyState, ValidateRect, IsWindowVisible, PeekMessageA, GetCursorPos, SetWindowsHookExA, WinHelpA, FindWindowA, PostMessageA, LoadCursorA, RegisterClassExA, CreateWindowExA, ShowWindow, DefWindowProcA, DispatchMessageA, TranslateMessage, GetMessageA, TranslateAcceleratorA, LoadAcceleratorsA, UpdateWindow, CallNextHookEx
winspool.drv
OpenPrinterA, DocumentPropertiesA, ClosePrinter

chgservice.exe

Remove chgservice.exe
MD5:   d0cff036a2bd3e0fae5e7246f58352e7
SHA1:   fb932d232c2889a7be0564cb01b1cfbda24af54b

Overview

chgservice.exe runs as a service under the name Change Modem Device Service with extensive SYSTEM privileges (full administrator access).

DetailsDetails

File name:chgservice.exe
Typical file path:C:\windows\syswow64\chgservice.exe
Size:112 KB (114,688 bytes)
Build date:5/10/2013 11:15 AM
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Change Modem Device Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
Memory
Private memory:1.09 MB
21.59 MB
Private (maximum):3.24 MB
Private (minimum):128 KB
Non-paged memory:1.09 MB
21.59 MB
Virtual memory:46.59 MB
140.96 MB
Virtual memory (peak):49.09 MB
169.69 MB
Working set:292 KB
18.61 MB
Working set (peak):3.5 MB
37.95 MB
Page faults:1,287/min
2,039/min
I/O
I/O other transfer:0 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:4
12
Handles:50
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\ProgramData\chgservice.exe" -service
Owner:SYSTEM
Windows Service
Service name:Change Modem Device Service
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 36.84%
Microsoft Windows XP 31.58%
Windows 7 Home Premium 15.79%
Windows 7 Professional 10.53%
Windows 7 Home Basic 5.26%

Distribution by countryDistribution by country

India installs about 47.37% of chgservice.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 40.00%
American Megatrends 20.00%
Hewlett-Packard 20.00%
Acer 20.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE