Parent process
Related files

PE structurePE file structure

Show functions
Import table
OpenServiceA, RegCreateKeyExA, RegSetValueExA, RegQueryValueExA, OpenSCManagerA, SetSecurityDescriptorSacl, CloseServiceHandle, ControlService, RegOpenKeyExA, RegCloseKey, SetFileSecurityA, AllocateAndInitializeSid, SetEntriesInAclA, FreeSid, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup
IntersectClipRect, GetDeviceCaps, GetViewportExtEx, GetWindowExtEx, CreateSolidBrush, PtVisible, RectVisible, TextOutA, ExtTextOutA, Escape, GetObjectA, GetTextColor, GetBkColor, DPtoLP, LPtoDP, GetMapMode, PatBlt, GetClipBox, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SetMapMode, SetTextColor, SetBkMode, SetBkColor, GetStockObject, SelectObject, RestoreDC, SaveDC, DeleteDC, DeleteObject, CreateDIBitmap, GetTextExtentPointA, BitBlt, CreateCompatibleDC, CreateBitmap
GetLocalTime, GetACP, RaiseException, HeapReAlloc, HeapSize, LCMapStringA, LCMapStringW, CompareStringA, CompareStringW, UnhandledExceptionFilter, FreeEnvironmentStringsA, FreeEnvironmentStringsW, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, HeapDestroy, HeapCreate, GetSystemTime, VirtualAlloc, IsBadWritePtr, GetStringTypeA, GetStringTypeW, SetUnhandledExceptionFilter, IsBadReadPtr, IsBadCodePtr, SetStdHandle, SetEnvironmentVariableA, GetTimeZoneInformation, HeapAlloc, ExitThread, GetProfileStringA, CreateThread, HeapFree, TerminateProcess, ExitProcess, GetCommandLineA, GetStartupInfoA, RtlUnwind, SizeofResource, GetFileTime, GetFileSize, GetFileAttributesA, GetOEMCP, GetCPInfo, GetFullPathNameA, GetVolumeInformationA, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, CreateFileA, GetCurrentProcess, DuplicateHandle, SetErrorMode, GetThreadLocale, GetProcessVersion, LoadLibraryA, FreeLibrary, GetVersion, GlobalGetAtomNameA, GlobalAddAtomA, GlobalFindAtomA, GetLastError, GetModuleHandleA, GetProcAddress, SetLastError, lstrcpyA, lstrcatA, GlobalFlags, MulDiv, lstrcpynA, TlsGetValue, LocalReAlloc, TlsSetValue, GlobalReAlloc, TlsFree, GlobalHandle, GlobalUnlock, TlsAlloc, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, FileTimeToLocalFileTime, FileTimeToSystemTime, FindResourceA, LoadResource, LockResource, GlobalFree, FormatMessageA, SuspendThread, ResumeThread, GlobalLock, GlobalAlloc, GlobalDeleteAtom, lstrcmpA, lstrcmpiA, GetCurrentThread, GetCurrentThreadId, MultiByteToWideChar, WideCharToMultiByte, lstrlenA, InterlockedDecrement, InterlockedIncrement, FindFirstFileA, FindClose, GetTickCount, DeleteFileA, GetPrivateProfileStringA, WritePrivateProfileStringA, SetEvent, ResetEvent, CreateEventA, LocalAlloc, LocalFree, SetThreadPriority, GetModuleFileNameA, CloseHandle, ReleaseMutex, CreateMutexA, WaitForSingleObject, VirtualFree
CoFreeUnusedLibraries, OleInitialize, CoTaskMemAlloc, CoTaskMemFree, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, StgOpenStorageOnILockBytes, CoGetClassObject, CLSIDFromString, CLSIDFromProgID, CoRegisterMessageFilter, CoRevokeClassObject, OleFlushClipboard, OleIsCurrentClipboard, OleUninitialize
ShellExecuteExA, ShellExecuteA
CreateDialogIndirectParamA, EndDialog, WinHelpA, GetClassInfoA, GetSubMenu, GetMenuItemID, DestroyWindow, GetClassLongA, SetPropA, GetPropA, CallWindowProcA, RemovePropA, GetMessageTime, GetMessagePos, SetForegroundWindow, RegisterWindowMessageA, OffsetRect, IntersectRect, IsIconic, GetWindowPlacement, SetFocus, ShowWindow, MoveWindow, SetWindowLongA, GetWindowTextLengthA, IsDialogMessageA, SendDlgItemMessageA, GetDlgItem, GrayStringA, DrawTextA, TabbedTextOutA, EndPaint, BeginPaint, GetWindowDC, ReleaseDC, GetDC, GetMenuItemCount, SetWindowTextA, GetDlgCtrlID, PtInRect, ScreenToClient, ClientToScreen, GetDesktopWindow, LoadCursorA, GetCapture, LoadStringA, wsprintfA, UnhookWindowsHookEx, MapDialogRect, SetWindowPos, GetWindow, SetWindowContextHelpId, GetMenuCheckMarkDimensions, LoadBitmapA, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, GetFocus, GetNextDlgTabItem, GetMessageA, GetActiveWindow, GetKeyState, CallNextHookEx, ValidateRect, PostMessageA, WaitMessage, DispatchMessageA, UnregisterClassA, HideCaret, ShowCaret, ExcludeUpdateRgn, DrawFocusRect, IsWindowVisible, GetCursorPos, SetWindowsHookExA, GetParent, GetLastActivePopup, IsWindowEnabled, MessageBoxA, EnableWindow, SetCursor, SendMessageA, GetLastInputInfo, GetForegroundWindow, IsWindow, GetWindowLongA, GetWindowTextA, GetClassNameA, GetSystemMetrics, GetWindowRect, SystemParametersInfoA, DefWindowProcA, PostQuitMessage, RegisterClassA, PostThreadMessageA, RegisterClipboardFormatA, InflateRect, CharUpperA, CreateWindowExA, PeekMessageA, DefDlgProcA, IsWindowUnicode, TranslateMessage, DestroyMenu, MessageBeep, GetNextDlgGroupItem, SetRect, CopyAcceleratorTableA, CharNextA, GetSysColorBrush, LoadIconA, UpdateWindow, MapWindowPoints, GetSysColor, SetActiveWindow, AdjustWindowRectEx, GetClientRect, CopyRect, EnableMenuItem, InvalidateRect, GetTopWindow, IsChild, GetMenu
ClosePrinter, DocumentPropertiesA, OpenPrinterA


DDNIMSGUser Application by Digital Delivery Networks Inc (Signed)

Remove DDNIMSGUser.exe
Version:   1, 5, 0, 0
MD5:   27faf26506976d4bf2a6b33e6112098c
SHA1:   f5caa1a373eb87c0f595e83c5c330dbd3e71dab7
SHA256:   cb3b58b16eb9a8e25f7a49682910ae17ce8ec3cc8b98f26ffb0e51f2dc6d97ce


ddnimsguser.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including Lenovo Idea Notes published by DDNi, Lenovo Idea Notes from DDNi and Lenovo Idea Notes by DDNi. The file is digitally signed by Digital Delivery Networks Inc which was issued by the Thawte Consulting (Pty) Ltd. certificate authority (CA). This particular version is usually found on Windows 7 Home Premium (6.1.7601.65536).


File name:ddnimsguser.exe
Publisher:Digital Delivery Networks, Inc.
Product name:DDNIMSGUser Application
Description:User Account
Typical file path:C:\Program Files\ddni\lenovo idea notes\ddnimsguser.exe
File version:1, 5, 0, 0
Size:216.67 KB (221,872 bytes)
Issued to:Digital Delivery Networks Inc
Authority (CA):Thawte Consulting (Pty) Ltd.
Effective date:Sunday, October 5, 2008
Expiration date:Sunday, October 3, 2010
Digital DNA
PE subsystem:Windows GUI
File packed:No
More details


The following programs will install this file
46% remove
Idea Central delivers News, Video, Shopping, Web Services and more right from your own desktop. Many products are available to try before you buy, and some are preloaded just waiting for you to unlock. (Preloaded products can easily be removed to free up disk space as well!) In addition, Idea Central consolidates the vast amount of news and information from the World Wide Web and puts it right at your fingertips. You have control over t...


Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'IdeaNotesUser' → C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Total CPU:0.00001695%
Kernel CPU:0.00000944%
User CPU:0.00000750%
Kernel CPU time:78 ms/min
CPU cycles:2,002/sec
Private memory:1.64 MB
21.59 MB
Private (maximum):3.52 MB
Private (minimum):120 KB
Non-paged memory:1.64 MB
21.59 MB
Virtual memory:57.23 MB
140.96 MB
Virtual memory (peak):60.23 MB
169.69 MB
Working set:716 KB
18.61 MB
Working set (peak):4.59 MB
37.95 MB
Page faults:2,895/min
I/O read transfer:254 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
I/O other transfer:0 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
Resource allocations
GUI GDI count:10
GUI GDI peak:11
GUI USER count:8
GUI USER peak:8

BehaviorsProcess properties

Integrety level:Medium
Command line:"C:\Program Files\ddni\lenovo idea notes\ddnimsguser.exe"
Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 100.00%
