Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.16%
5.1.2600.5512 (xpsp.080413-2105) 79.02%
5.1.2600.5512 (xpsp.080413-2105) 3.77%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 16.89%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.16%

PE structurePE file structure

Show functions
Import table
advapi32.dll
GetPrivateObjectSecurity, RegCreateKeyExW, RegDeleteKeyW, CreatePrivateObjectSecurity, GetSecurityDescriptorLength, DestroyPrivateObjectSecurity, RegQueryValueExW, AccessCheckAndAuditAlarmW, ObjectDeleteAuditAlarmW, ObjectCloseAuditAlarmW, AllocateAndInitializeSid, FreeSid, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetAce, MakeSelfRelativeSD, RegDeleteValueA, RegEnumKeyExW, SetPrivateObjectSecurity, RegCloseKey, RegQueryValueA, RegOpenKeyA, ObjectCloseAuditAlarmA, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, SetSecurityDescriptorDacl, AddAccessAllowedAce, AddAccessDeniedAce, InitializeAcl, InitializeSecurityDescriptor, GetLengthSid, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, OpenProcessToken, OpenThreadToken, LookupAccountSidA, GetTokenInformation, AccessCheckAndAuditAlarmA, IsValidSecurityDescriptor, RevertToSelf, RegSetValueExA, RegCreateKeyExA, RegSetValueExW, RegOpenKeyExA, RegQueryValueExA, RegisterEventSourceW, ReportEventW, RegisterEventSourceA, ReportEventA, DeregisterEventSource, RegOpenKeyExW
gdi32.dll
DeleteEnhMetaFile, DeleteMetaFile, DeleteObject, CreatePalette, GetPaletteEntries, SetEnhMetaFileBits, GetEnhMetaFileBits, CreateBitmapIndirect, GetObjectA, GetBitmapBits, SetMetaFileBitsEx, GetMetaFileBitsEx, GetStockObject
kernel32.dll
GetCurrentThreadId, InterlockedIncrement, GetModuleFileNameA, SetEvent, CreateThread, WaitForSingleObject, CreateEventA, GetTickCount, GetProcAddress, FreeLibrary, LoadLibraryA, ResumeThread, GetComputerNameA, TlsSetValue, DisconnectNamedPipe, WriteFile, WaitForMultipleObjects, ConnectNamedPipe, CloseHandle, CreateNamedPipeW, TlsAlloc, InitializeCriticalSection, SetConsoleCtrlHandler, SetProcessShutdownParameters, GetCurrentProcess, GetCurrentThread, LocalUnlock, LocalLock, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, OutputDebugStringA, lstrcmpiA, InterlockedExchange, GlobalDeleteAtom, lstrcpynA, GlobalHandle, lstrlenA, LocalAlloc, lstrcpyA, TlsGetValue, LocalFree, ReadFile, GlobalAddAtomA, GlobalReAlloc, EnterCriticalSection, LeaveCriticalSection, GlobalGetAtomNameA, GlobalSize, GlobalLock, GetLastError, GlobalUnlock, GlobalAlloc, GlobalFree, GlobalCompact, MultiByteToWideChar, WideCharToMultiByte, IsBadReadPtr, IsBadWritePtr, InterlockedDecrement, lstrcmpiW
msvcrt.dll
DllMain
ntdll.dll
NtSetInformationThread, _snprintf, memmove, RtlAnsiStringToUnicodeString, RtlInitUnicodeString, RtlCopyString, NtAllocateLocallyUniqueId, _chkstk, RtlInitAnsiString, RtlOpenCurrentUser, atoi, wcschr, wcslen, RtlValidRelativeSecurityDescriptor, wcscpy, wcscat, swprintf, wcscspn, _vsnwprintf
rpcrt4.dll
RpcServerUseProtseqEpA, RpcServerRegisterAuthInfoA, RpcServerListen, RpcImpersonateClient, RpcServerRegisterIf, NdrServerCall2
secur32.dll
LsaRegisterLogonProcess, LsaFreeReturnBuffer, LsaCallAuthenticationPackage, LsaLogonUser, LsaLookupAuthenticationPackage
user32.dll
SetThreadDesktop, FindWindowA, GetThreadDesktop, OpenDesktopW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, ImpersonateDdeClientWindow, OemToCharBuffA, GetMessageA, GetClassLongA, DefWindowProcA, GetWindowThreadProcessId, TranslateMessage, CreateWindowExA, DdeSetQualityOfService, SendMessageTimeoutA, DestroyWindow, PackDDElParam, ReuseDDElParam, PostMessageA, CharUpperA, SetWindowLongA, SendMessageA, IsWindow, GetWindowLongA, UnpackDDElParam, FreeDDElParam, DispatchMessageA, PeekMessageA, CloseDesktop, CloseWindowStation, GetWindow, PostQuitMessage, GetDesktopWindow, UpdateWindow, RegisterWindowMessageA, RegisterClipboardFormatA, LoadCursorA, DdeGetQualityOfService, GetClipboardFormatNameA, MessageBoxA, GetParent, RegisterClassA

NETDDE.exe

Network DDE - DDE Communication by Microsoft

Remove NETDDE.exe
Version:   5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5:   d40598fd7b7dccbfb22d777e0dfb1cf0
SHA1:   696f980735910d243c83a38684f7e30f71d75c3f
SHA256:   6b6125e0961791c693cff62058f1b9d96d8393a7f7e0c4f6e5a19eccf53ff9ab
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

netdde.exe runs as a service under the name Network DDE (NetDDE) within the local user context as a shared service. This version is installed on Windows XP.

DetailsDetails

File name:netdde.exe
Publisher:Microsoft Corporation
Product name:Network DDE - DDE Communication
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\netdde.exe
File version:5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version:5.1.2600.2180
Size:111.5 KB (114,176 bytes)
Digital DNA
PE subsystem:Windows GUI
Entropy:6.177987
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
  • 'NetDDE' (Network DDE)
  • 'NetDDEdsdm'
  • 'NetDDE'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 42.71% of Network DDE - DDE Communication.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 38.52%
Intel 16.30%
Toshiba 10.37%
American Megatrends 7.41%
Compaq 5.93%
GIGABYTE 5.19%
Hewlett-Packard 4.44%
Sahara 3.70%
Gateway 2.96%
Acer 2.22%
Lenovo 1.48%
ASUS 1.48%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE