Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.17%
5.1.2600.5512 (xpsp.080413-2105) 80.47%
5.1.2600.5512 (xpsp.080413-2105) 1.50%
5.1.2600.5512 (xpsp.080413-2105) 0.17%
5.1.2600.5512 (xpsp.080413-2105) 0.17%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 17.20%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.17%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.17%

PE structurePE file structure

Show functions
Import table
advapi32.dll
GetPrivateObjectSecurity, RegCreateKeyExW, RegDeleteKeyW, CreatePrivateObjectSecurity, GetSecurityDescriptorLength, DestroyPrivateObjectSecurity, RegQueryValueExW, AccessCheckAndAuditAlarmW, ObjectDeleteAuditAlarmW, ObjectCloseAuditAlarmW, AllocateAndInitializeSid, FreeSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetAce, MakeSelfRelativeSD, RegDeleteValueA, RegEnumKeyExW, SetPrivateObjectSecurity, RegCloseKey, RegQueryValueA, RegOpenKeyA, ObjectCloseAuditAlarmA, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, SetSecurityDescriptorDacl, AddAccessAllowedAce, AddAccessDeniedAce, InitializeAcl, InitializeSecurityDescriptor, GetLengthSid, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, OpenProcessToken, OpenThreadToken, LookupAccountSidA, GetTokenInformation, AccessCheckAndAuditAlarmA, IsValidSecurityDescriptor, RevertToSelf, RegSetValueExA, RegCreateKeyExA, RegSetValueExW, RegOpenKeyExA, RegQueryValueExA, RegisterEventSourceW, ReportEventW, RegisterEventSourceA, ReportEventA, DeregisterEventSource, RegOpenKeyExW
gdi32.dll
DeleteEnhMetaFile, DeleteMetaFile, DeleteObject, CreatePalette, GetPaletteEntries, SetEnhMetaFileBits, GetEnhMetaFileBits, CreateBitmapIndirect, GetObjectA, GetBitmapBits, SetMetaFileBitsEx, GetMetaFileBitsEx, GetStockObject
kernel32.dll
GetCurrentThreadId, InterlockedIncrement, GetModuleFileNameA, SetEvent, CreateThread, WaitForSingleObject, CreateEventA, GetTickCount, GetProcAddress, FreeLibrary, LoadLibraryA, ResumeThread, GetComputerNameA, TlsSetValue, DisconnectNamedPipe, WriteFile, WaitForMultipleObjects, ConnectNamedPipe, CloseHandle, CreateNamedPipeW, TlsAlloc, InitializeCriticalSection, SetConsoleCtrlHandler, SetProcessShutdownParameters, GetCurrentProcess, GetCurrentThread, LocalUnlock, LocalLock, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, OutputDebugStringA, lstrcmpiA, InterlockedExchange, GlobalDeleteAtom, lstrcpynA, GlobalHandle, lstrlenA, LocalAlloc, lstrcpyA, TlsGetValue, LocalFree, ReadFile, GlobalAddAtomA, GlobalReAlloc, EnterCriticalSection, LeaveCriticalSection, GlobalGetAtomNameA, GlobalSize, GlobalLock, GetLastError, GlobalUnlock, GlobalAlloc, GlobalFree, GlobalCompact, MultiByteToWideChar, WideCharToMultiByte, IsBadReadPtr, IsBadWritePtr, InterlockedDecrement, lstrcmpiW
msvcrt.dll
DllMain
ntdll.dll
NtSetInformationThread, _snprintf, memmove, RtlAnsiStringToUnicodeString, RtlInitUnicodeString, RtlCopyString, NtAllocateLocallyUniqueId, _chkstk, RtlInitAnsiString, RtlOpenCurrentUser, atoi, wcschr, wcslen, RtlValidRelativeSecurityDescriptor, wcscpy, wcscat, swprintf, wcscspn, _vsnwprintf
rpcrt4.dll
RpcServerUseProtseqEpA, RpcServerRegisterAuthInfoA, RpcServerListen, RpcImpersonateClient, RpcServerRegisterIf, NdrServerCall2
secur32.dll
LsaRegisterLogonProcess, LsaFreeReturnBuffer, LsaCallAuthenticationPackage, LsaLogonUser, LsaLookupAuthenticationPackage
user32.dll
SetThreadDesktop, FindWindowA, GetThreadDesktop, OpenDesktopW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, ImpersonateDdeClientWindow, OemToCharBuffA, GetMessageA, GetClassLongA, DefWindowProcA, GetWindowThreadProcessId, TranslateMessage, CreateWindowExA, DdeSetQualityOfService, SendMessageTimeoutA, DestroyWindow, PackDDElParam, ReuseDDElParam, PostMessageA, CharUpperA, SetWindowLongA, SendMessageA, IsWindow, GetWindowLongA, UnpackDDElParam, FreeDDElParam, DispatchMessageA, PeekMessageA, CloseDesktop, CloseWindowStation, GetWindow, PostQuitMessage, GetDesktopWindow, UpdateWindow, RegisterWindowMessageA, RegisterClipboardFormatA, LoadCursorA, DdeGetQualityOfService, GetClipboardFormatNameA, MessageBoxA, GetParent, RegisterClassA

NETDDE.exe

Network DDE - DDE Communication by Microsoft

Remove NETDDE.exe
Version:   5.1.2600.5512 (xpsp.080413-2105)
MD5:   925f4eb54f0e9412bf90977d7eb0e203
SHA1:   08d4bc6dbba348e0fe7c24d3053279df3d0757ae
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

netdde.exe runs as a service under the name Network DDE (NetDDE) within the local user context as a shared service. This version is installed on Windows XP.

DetailsDetails

File name:netdde.exe
Publisher:Microsoft Corporation
Product name:Network DDE - DDE Communication
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\netdde.exe
File version:5.1.2600.5512 (xpsp.080413-2105)
Product version:5.1.2600.5512
Size:103 KB (105,472 bytes)
Build date:4/14/2008 2:38 AM
Digital DNA
PE subsystem:Windows GUI
Entropy:6.177987
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'NetDDE' (Network DDE)
  • 'NetDDEdsdm'
  • 'NetDDE'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 42.71% of Network DDE - DDE Communication.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 38.52%
Intel 16.30%
Toshiba 10.37%
American Megatrends 7.41%
Compaq 5.93%
GIGABYTE 5.19%
Hewlett-Packard 4.44%
Sahara 3.70%
Gateway 2.96%
Acer 2.22%
Lenovo 1.48%
ASUS 1.48%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE