Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.17%
5.1.2600.5512 (xpsp.080413-2105) 80.47%
5.1.2600.5512 (xpsp.080413-2105) 1.50%
5.1.2600.5512 (xpsp.080413-2105) 0.17%
5.1.2600.5512 (xpsp.080413-2105) 0.17%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 17.20%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.17%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.17%

PE structurePE file structure

Show functions
Import table
advapi32.dll
GetPrivateObjectSecurity, RegCreateKeyExW, RegDeleteKeyW, CreatePrivateObjectSecurity, GetSecurityDescriptorLength, DestroyPrivateObjectSecurity, RegQueryValueExW, AccessCheckAndAuditAlarmW, ObjectDeleteAuditAlarmW, ObjectCloseAuditAlarmW, AllocateAndInitializeSid, FreeSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetAce, MakeSelfRelativeSD, RegDeleteValueA, RegEnumKeyExW, SetPrivateObjectSecurity, RegCloseKey, RegQueryValueA, RegOpenKeyA, ObjectCloseAuditAlarmA, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, SetSecurityDescriptorDacl, AddAccessAllowedAce, AddAccessDeniedAce, InitializeAcl, InitializeSecurityDescriptor, GetLengthSid, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, OpenProcessToken, OpenThreadToken, LookupAccountSidA, GetTokenInformation, AccessCheckAndAuditAlarmA, IsValidSecurityDescriptor, RevertToSelf, RegSetValueExA, RegCreateKeyExA, RegSetValueExW, RegOpenKeyExA, RegQueryValueExA, RegisterEventSourceW, ReportEventW, RegisterEventSourceA, ReportEventA, DeregisterEventSource, RegOpenKeyExW
gdi32.dll
DeleteEnhMetaFile, DeleteMetaFile, DeleteObject, CreatePalette, GetPaletteEntries, SetEnhMetaFileBits, GetEnhMetaFileBits, CreateBitmapIndirect, GetObjectA, GetBitmapBits, SetMetaFileBitsEx, GetMetaFileBitsEx, GetStockObject
kernel32.dll
GetCurrentThreadId, InterlockedIncrement, GetModuleFileNameA, SetEvent, CreateThread, WaitForSingleObject, CreateEventA, GetTickCount, GetProcAddress, FreeLibrary, LoadLibraryA, ResumeThread, GetComputerNameA, TlsSetValue, DisconnectNamedPipe, WriteFile, WaitForMultipleObjects, ConnectNamedPipe, CloseHandle, CreateNamedPipeW, TlsAlloc, InitializeCriticalSection, SetConsoleCtrlHandler, SetProcessShutdownParameters, GetCurrentProcess, GetCurrentThread, LocalUnlock, LocalLock, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, OutputDebugStringA, lstrcmpiA, InterlockedExchange, GlobalDeleteAtom, lstrcpynA, GlobalHandle, lstrlenA, LocalAlloc, lstrcpyA, TlsGetValue, LocalFree, ReadFile, GlobalAddAtomA, GlobalReAlloc, EnterCriticalSection, LeaveCriticalSection, GlobalGetAtomNameA, GlobalSize, GlobalLock, GetLastError, GlobalUnlock, GlobalAlloc, GlobalFree, GlobalCompact, MultiByteToWideChar, WideCharToMultiByte, IsBadReadPtr, IsBadWritePtr, InterlockedDecrement, lstrcmpiW
msvcrt.dll
DllMain
ntdll.dll
NtSetInformationThread, _snprintf, memmove, RtlAnsiStringToUnicodeString, RtlInitUnicodeString, RtlCopyString, NtAllocateLocallyUniqueId, _chkstk, RtlInitAnsiString, RtlOpenCurrentUser, atoi, wcschr, wcslen, RtlValidRelativeSecurityDescriptor, wcscpy, wcscat, swprintf, wcscspn, _vsnwprintf
rpcrt4.dll
RpcServerUseProtseqEpA, RpcServerRegisterAuthInfoA, RpcServerListen, RpcImpersonateClient, RpcServerRegisterIf, NdrServerCall2
secur32.dll
LsaRegisterLogonProcess, LsaFreeReturnBuffer, LsaCallAuthenticationPackage, LsaLogonUser, LsaLookupAuthenticationPackage
user32.dll
SetThreadDesktop, FindWindowA, GetThreadDesktop, OpenDesktopW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, ImpersonateDdeClientWindow, OemToCharBuffA, GetMessageA, GetClassLongA, DefWindowProcA, GetWindowThreadProcessId, TranslateMessage, CreateWindowExA, DdeSetQualityOfService, SendMessageTimeoutA, DestroyWindow, PackDDElParam, ReuseDDElParam, PostMessageA, CharUpperA, SetWindowLongA, SendMessageA, IsWindow, GetWindowLongA, UnpackDDElParam, FreeDDElParam, DispatchMessageA, PeekMessageA, CloseDesktop, CloseWindowStation, GetWindow, PostQuitMessage, GetDesktopWindow, UpdateWindow, RegisterWindowMessageA, RegisterClipboardFormatA, LoadCursorA, DdeGetQualityOfService, GetClipboardFormatNameA, MessageBoxA, GetParent, RegisterClassA

NETDDE.exe

Network DDE - DDE Communication by Microsoft

Remove NETDDE.exe
Version:   5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5:   23afdc87c7824605864e07021e01b4c8
SHA1:   354c350ab4ed7ca692dadacec75a19c6337f006b
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

netdde.exe runs as a service under the name Network DDE (NetDDE) within the local user context as a shared service. This version is installed on Windows XP.

DetailsDetails

File name:netdde.exe
Publisher:Microsoft Corporation
Product name:Network DDE - DDE Communication
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\netdde.exe
File version:5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version:5.1.2600.2180
Size:105.5 KB (108,032 bytes)
Build date:8/4/2004 3:01 PM
Digital DNA
PE subsystem:Windows GUI
Entropy:6.177987
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'NetDDE' (Network DDE)
  • 'NetDDEdsdm'
  • 'NetDDE'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 42.71% of Network DDE - DDE Communication.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 38.52%
Intel 16.30%
Toshiba 10.37%
American Megatrends 7.41%
Compaq 5.93%
GIGABYTE 5.19%
Hewlett-Packard 4.44%
Sahara 3.70%
Gateway 2.96%
Acer 2.22%
Lenovo 1.48%
ASUS 1.48%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE