File details
File name: netdde.exe
Name: Network DDE - DDE Communication
Description: Microsoft® Windows® Operating System
Version: 5.1.2600.5512 (xpsp.080413-2105)
Product version: 5.1.2600.5512
Size: 108.5 KB
Original file name: NETDDE.EXE
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0008127594%
Privileged CPU:
0.0005418396%

User CPU:
0.00027091981647%

Privileged CPU time: 62.5 ms
Privileged CPU time /min: 0 ms
 | Memory utilization averages |
Committed memory:
31.8 MB
Peak committed memory: 32.34 MB
Paged memory:
1.02 MB
Peak paged memory: 1.02 MB
Paged system memory:
33.66 KB
Non-paged system memory: 4.16 KB
Working set memory:
3.02 MB
Peak working set memory: 3.02 MB
Min working set memory: 3 MB
Private memory:
1.02 MB
Page faults:
939
Page faults /min: 5
 | Process I/O averages |
Total read operations:
3
Read operations /min: 1
Total read transfer: 84 Bytes
Read transfer /min: 0 Bytes
Total write operations:
3
Write operations /min: 1
Total write transfer: 20 Bytes
Write transfer /min: 0 Bytes
Total other operations:
173
Other operations /min: 1
Total other transfer: 2.25 KB
Other Transfer /min: 12 Bytes
 | GUI Object Averages |
GDI objects:
8
USER objects:
7
Resources
Handle count average: 71
Thread count average: 10
Thread resource averages
Total CPU: 0.000272876988%
Privileged CPU: 0.000204666769%
User CPU: 0.000068210218%
Module memory size: 128 KB
Process details
Runs as (owner): System
Integrety level: Undefined
Windows platform: 32-bit
Runs as a service: Yes
Parent Process
Process Command
C:\WINDOWS\system32\netdde.exe
Service details
Name: Network DDE
Service name: NetDDE
Service type:
Win32ShareProcess
Description: “Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.”
Image hashes
MD5: b857ba82860d7ff85ae29b095645563b
SHA-1: 7235c82aa9698d9297a73e44cb365fd5973cef78
SHA-256: 86ff0e4cdd9c394e8babd93a4d57e73ff9a779261717dec6e9cde99f1c6b0f4c
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 6.17799
File packed: No
Import Table
advapi32.dll

GetPrivateObjectSecurity
RegCreateKeyExW
RegDeleteKeyW
CreatePrivateObjectSecurity
GetSecurityDescriptorLength
DestroyPrivateObjectSecurity
RegQueryValueExW
AccessCheckAndAuditAlarmW
ObjectDeleteAuditAlarmW
ObjectCloseAuditAlarmW
AllocateAndInitializeSid
FreeSid
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
GetAce
MakeSelfRelativeSD
RegDeleteValueA
RegEnumKeyExW
SetPrivateObjectSecurity
RegCloseKey
RegQueryValueA
RegOpenKeyA
ObjectCloseAuditAlarmA
SetServiceStatus
RegisterServiceCtrlHandlerA
StartServiceCtrlDispatcherA
SetSecurityDescriptorDacl
AddAccessAllowedAce
AddAccessDeniedAce
InitializeAcl
InitializeSecurityDescriptor
GetLengthSid
GetSidSubAuthority
InitializeSid
GetSidLengthRequired
OpenProcessToken
OpenThreadToken
LookupAccountSidA
GetTokenInformation
AccessCheckAndAuditAlarmA
IsValidSecurityDescriptor
RevertToSelf
RegSetValueExA
RegCreateKeyExA
RegSetValueExW
RegOpenKeyExA
RegQueryValueExA
RegisterEventSourceW
ReportEventW
RegisterEventSourceA
ReportEventA
DeregisterEventSource
RegOpenKeyExW
gdi32.dll

DeleteEnhMetaFile
DeleteMetaFile
DeleteObject
CreatePalette
GetPaletteEntries
SetEnhMetaFileBits
GetEnhMetaFileBits
CreateBitmapIndirect
GetObjectA
GetBitmapBits
SetMetaFileBitsEx
GetMetaFileBitsEx
GetStockObject
kernel32.dll

GetCurrentThreadId
InterlockedIncrement
GetModuleFileNameA
SetEvent
CreateThread
WaitForSingleObject
CreateEventA
GetTickCount
GetProcAddress
FreeLibrary
LoadLibraryA
ResumeThread
GetComputerNameA
TlsSetValue
DisconnectNamedPipe
WriteFile
WaitForMultipleObjects
ConnectNamedPipe
CloseHandle
CreateNamedPipeW
TlsAlloc
InitializeCriticalSection
SetConsoleCtrlHandler
SetProcessShutdownParameters
GetCurrentProcess
GetCurrentThread
LocalUnlock
LocalLock
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetModuleHandleA
GetStartupInfoA
OutputDebugStringA
lstrcmpiA
InterlockedExchange
GlobalDeleteAtom
lstrcpynA
GlobalHandle
lstrlenA
LocalAlloc
lstrcpyA
TlsGetValue
LocalFree
ReadFile
GlobalAddAtomA
GlobalReAlloc
EnterCriticalSection
LeaveCriticalSection
GlobalGetAtomNameA
GlobalSize
GlobalLock
GetLastError
GlobalUnlock
GlobalAlloc
GlobalFree
GlobalCompact
MultiByteToWideChar
WideCharToMultiByte
IsBadReadPtr
IsBadWritePtr
InterlockedDecrement
lstrcmpiW
msvcrt.dll
ntdll.dll

NtSetInformationThread
_snprintf
memmove
RtlAnsiStringToUnicodeString
RtlInitUnicodeString
RtlCopyString
NtAllocateLocallyUniqueId
_chkstk
RtlInitAnsiString
RtlOpenCurrentUser
atoi
wcschr
wcslen
RtlValidRelativeSecurityDescriptor
wcscpy
wcscat
swprintf
wcscspn
_vsnwprintf
rpcrt4.dll

RpcServerUseProtseqEpA
RpcServerRegisterAuthInfoA
RpcServerListen
RpcImpersonateClient
RpcServerRegisterIf
NdrServerCall2
secur32.dll

LsaRegisterLogonProcess
LsaFreeReturnBuffer
LsaCallAuthenticationPackage
LsaLogonUser
LsaLookupAuthenticationPackage
user32.dll

SetThreadDesktop
FindWindowA
GetThreadDesktop
OpenDesktopW
SetProcessWindowStation
GetProcessWindowStation
OpenWindowStationW
ImpersonateDdeClientWindow
OemToCharBuffA
GetMessageA
GetClassLongA
DefWindowProcA
GetWindowThreadProcessId
TranslateMessage
CreateWindowExA
DdeSetQualityOfService
SendMessageTimeoutA
DestroyWindow
PackDDElParam
ReuseDDElParam
PostMessageA
CharUpperA
SetWindowLongA
SendMessageA
IsWindow
GetWindowLongA
UnpackDDElParam
FreeDDElParam
DispatchMessageA
PeekMessageA
CloseDesktop
CloseWindowStation
GetWindow
PostQuitMessage
GetDesktopWindow
UpdateWindow
RegisterWindowMessageA
RegisterClipboardFormatA
LoadCursorA
DdeGetQualityOfService
GetClipboardFormatNameA
MessageBoxA
GetParent
RegisterClassA