Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.14%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.43%
5.1.2600.5512 (xpsp.080413-2105) 69.05%
5.1.2600.5512 (xpsp.080413-2105) 3.30%
5.1.2600.5512 (xpsp.080413-2105) 0.43%
5.1.2600.5512 (xpsp.080413-2105) 3.30%
5.1.2600.5512 (xpsp.080413-2105) 0.14%
5.1.2600.5512 (xpsp.080413-2105) 0.14%
5.1.2600.5512 (xpsp.080413-2105) 2.15%
5.1.2600.5512 (xpsp.080413-2105) 0.14%
5.1.2600.5512 (xpsp.080413-2105) 1.00%
5.1.2600.5512 (xpsp.080413-2105) 1.29%
5.1.2600.5512 (xpsp.080413-2105) 0.14%
5.1.2600.5512 (xpsp.080413-2105) 0.14%
5.1.2600.5512 (xpsp.080413-2105) 1.58%
5.1.2600.3311 (xpsp.080212-0004) 0.43%
5.1.2600.3300 (xpsp.080125-2028) 0.14%
5.1.2600.3244 (xpsp.071030-1535) 0.14%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 14.76%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.14%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.43%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.14%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.14%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.14%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.14%

PE structurePE file structure

Show functions
Import table
advapi32.dll
GetPrivateObjectSecurity, RegCreateKeyExW, RegDeleteKeyW, CreatePrivateObjectSecurity, GetSecurityDescriptorLength, DestroyPrivateObjectSecurity, RegQueryValueExW, AccessCheckAndAuditAlarmW, ObjectDeleteAuditAlarmW, ObjectCloseAuditAlarmW, AllocateAndInitializeSid, FreeSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetAce, MakeSelfRelativeSD, RegDeleteValueA, RegEnumKeyExW, SetPrivateObjectSecurity, RegCloseKey, RegQueryValueA, RegOpenKeyA, ObjectCloseAuditAlarmA, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, SetSecurityDescriptorDacl, AddAccessAllowedAce, AddAccessDeniedAce, InitializeAcl, InitializeSecurityDescriptor, GetLengthSid, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, OpenProcessToken, OpenThreadToken, LookupAccountSidA, GetTokenInformation, AccessCheckAndAuditAlarmA, IsValidSecurityDescriptor, RevertToSelf, RegSetValueExA, RegCreateKeyExA, RegSetValueExW, RegOpenKeyExA, RegQueryValueExA, RegisterEventSourceW, ReportEventW, RegisterEventSourceA, ReportEventA, DeregisterEventSource, RegOpenKeyExW
gdi32.dll
DeleteEnhMetaFile, DeleteMetaFile, DeleteObject, CreatePalette, GetPaletteEntries, SetEnhMetaFileBits, GetEnhMetaFileBits, CreateBitmapIndirect, GetObjectA, GetBitmapBits, SetMetaFileBitsEx, GetMetaFileBitsEx, GetStockObject
kernel32.dll
GetCurrentThreadId, InterlockedIncrement, GetModuleFileNameA, SetEvent, CreateThread, WaitForSingleObject, CreateEventA, GetTickCount, GetProcAddress, FreeLibrary, LoadLibraryA, ResumeThread, GetComputerNameA, TlsSetValue, DisconnectNamedPipe, WriteFile, WaitForMultipleObjects, ConnectNamedPipe, CloseHandle, CreateNamedPipeW, TlsAlloc, InitializeCriticalSection, SetConsoleCtrlHandler, SetProcessShutdownParameters, GetCurrentProcess, GetCurrentThread, LocalUnlock, LocalLock, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, OutputDebugStringA, lstrcmpiA, InterlockedExchange, GlobalDeleteAtom, lstrcpynA, GlobalHandle, lstrlenA, LocalAlloc, lstrcpyA, TlsGetValue, LocalFree, ReadFile, GlobalAddAtomA, GlobalReAlloc, EnterCriticalSection, LeaveCriticalSection, GlobalGetAtomNameA, GlobalSize, GlobalLock, GetLastError, GlobalUnlock, GlobalAlloc, GlobalFree, GlobalCompact, MultiByteToWideChar, WideCharToMultiByte, IsBadReadPtr, IsBadWritePtr, InterlockedDecrement, lstrcmpiW
msvcrt.dll
DllMain
ntdll.dll
NtSetInformationThread, _snprintf, memmove, RtlAnsiStringToUnicodeString, RtlInitUnicodeString, RtlCopyString, NtAllocateLocallyUniqueId, _chkstk, RtlInitAnsiString, RtlOpenCurrentUser, atoi, wcschr, wcslen, RtlValidRelativeSecurityDescriptor, wcscpy, wcscat, swprintf, wcscspn, _vsnwprintf
rpcrt4.dll
RpcServerUseProtseqEpA, RpcServerRegisterAuthInfoA, RpcServerListen, RpcImpersonateClient, RpcServerRegisterIf, NdrServerCall2
secur32.dll
LsaRegisterLogonProcess, LsaFreeReturnBuffer, LsaCallAuthenticationPackage, LsaLogonUser, LsaLookupAuthenticationPackage
user32.dll
SetThreadDesktop, FindWindowA, GetThreadDesktop, OpenDesktopW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, ImpersonateDdeClientWindow, OemToCharBuffA, GetMessageA, GetClassLongA, DefWindowProcA, GetWindowThreadProcessId, TranslateMessage, CreateWindowExA, DdeSetQualityOfService, SendMessageTimeoutA, DestroyWindow, PackDDElParam, ReuseDDElParam, PostMessageA, CharUpperA, SetWindowLongA, SendMessageA, IsWindow, GetWindowLongA, UnpackDDElParam, FreeDDElParam, DispatchMessageA, PeekMessageA, CloseDesktop, CloseWindowStation, GetWindow, PostQuitMessage, GetDesktopWindow, UpdateWindow, RegisterWindowMessageA, RegisterClipboardFormatA, LoadCursorA, DdeGetQualityOfService, GetClipboardFormatNameA, MessageBoxA, GetParent, RegisterClassA

NETDDE.exe

Network DDE - DDE Communication by Microsoft

Remove NETDDE.exe
Version:   5.1.2600.5512 (xpsp.080413-2105)
MD5:   b857ba82860d7ff85ae29b095645563b
SHA1:   7235c82aa9698d9297a73e44cb365fd5973cef78
SHA256:   86ff0e4cdd9c394e8babd93a4d57e73ff9a779261717dec6e9cde99f1c6b0f4c
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

netdde.exe runs as a service under the name Network DDE (NetDDE) with extensive SYSTEM privileges (full administrator access) as a shared service. This version is installed on Windows XP and is compiled as a 32 bit program.

DetailsDetails

File name:netdde.exe
Publisher:Microsoft Corporation
Product name:Network DDE - DDE Communication
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\netdde.exe
File version:5.1.2600.5512 (xpsp.080413-2105)
Product version:5.1.2600.5512
Size:108.5 KB (111,104 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:6.177987
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'NetDDE' (Network DDE)
  • 'NetDDEdsdm'
  • 'NetDDE'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00081276%
0.028634%
Kernel CPU:0.00054184%
0.013761%
User CPU:0.00027092%
0.014873%
Kernel CPU time:63 ms/min
100,923,805ms/min
Memory
Private memory:1.02 MB
21.59 MB
Private (maximum):3.02 MB
Private (minimum):3 MB
Non-paged memory:1.02 MB
21.59 MB
Virtual memory:31.8 MB
140.96 MB
Virtual memory (peak):32.34 MB
169.69 MB
Working set:3.02 MB
18.61 MB
Working set (peak):3.02 MB
37.95 MB
Page faults:939/min
2,039/min
I/O
I/O read transfer:0 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:12 Bytes/sec
448.09 KB/min
I/O other operations:1/sec
1,671/min
Resource allocations
Threads:10
12
Handles:71
600
GUI GDI count:8
103
GUI USER count:7
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:C:\Windows\System32\netdde.exe
Owner:SYSTEM
Windows Service
Service name:NetDDE
Display name:Network DDE
Description:“Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.”
Type:Win32ShareProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 42.71% of Network DDE - DDE Communication.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 38.52%
Intel 16.30%
Toshiba 10.37%
American Megatrends 7.41%
Compaq 5.93%
GIGABYTE 5.19%
Hewlett-Packard 4.44%
Sahara 3.70%
Gateway 2.96%
Acer 2.22%
Lenovo 1.48%
ASUS 1.48%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE