Should I block it?

No, this file is 100% safe to run.

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
ReportEventA, DeregisterEventSource, SetTokenInformation, GetTokenInformation, FreeSid, SetNamedSecurityInfoA, SetNamedSecurityInfoW, IsValidSid, CloseEventLog, RegOpenKeyExW, GetSidSubAuthority, GetSidSubAuthorityCount, EqualSid, RegQueryValueExW, LookupAccountSidW, RevertToSelf, ImpersonateLoggedOnUser, LookupAccountNameW, IsValidSecurityDescriptor, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AddAce, InitializeAcl, GetLengthSid, AllocateAndInitializeSid, OpenProcessToken, AdjustTokenPrivileges, LookupPrivilegeValueW, RegCloseKey, RegEnumValueA, RegQueryInfoKeyA, RegOpenKeyExA, RegQueryValueExA, RegisterEventSourceA
gdi32.dll
ExtSelectClipRgn, OffsetRgn, OffsetWindowOrgEx, CreateFontW, PtInRegion, SetWindowOrgEx, GetStockObject, CreateDCW, FrameRgn, ExtCreatePen, SetDIBits, CreateRectRgnIndirect, SetRectRgn, GetSystemPaletteEntries, CreateDCA, SetDIBColorTable, ExtEscape, GetRegionData, GetBitmapBits, CreateEllipticRgn, CreateRoundRectRgn, GetWindowOrgEx, CreateBrushIndirect, CreateRectRgn, GetRgnBox, CombineRgn, ExtTextOutW, GetDeviceCaps, StretchBlt, GetObjectA, SetPixel, CreateDIBSection, SelectClipRgn, LineTo, DeleteDC, MoveToEx, SetTextColor, SetBkMode, CreatePen, BitBlt, CreateCompatibleBitmap, CreateCompatibleDC, GetTextExtentPoint32W, GetTextExtentExPointW, GetDIBits, GetClipRgn, CreateFontIndirectW, SetBkColor, DeleteObject, GetObjectW, CreateSolidBrush, SelectObject
kernel32.dll
DllMain
mpr.dll
WNetCloseEnum, WNetEnumResourceW, WNetOpenEnumW
ole32.dll
CoRevokeClassObject, GetRunningObjectTable, CreateFileMoniker, CoRegisterClassObject, CoInitializeSecurity, CoInitializeEx, CoUninitialize, CoCreateInstance, CoInitialize, CreateBindCtx, CoTaskMemFree
shell32.dll
SHChangeNotify
shlwapi.dll
PathFileExistsW, StrCpyW
urlmon.dll
URLDownloadToFileA
user32.dll
DllMain
version.dll
GetFileVersionInfoA, VerQueryValueA
wininet.dll
DetectAutoProxyUrl, InternetQueryOptionA
winmm.dll
timeGetDevCaps, timeSetEvent, timeKillEvent, PlaySoundA
ws2_32.dll
WSACloseEvent, WSAEventSelect, WSACreateEvent, WSAIoctl

lmi_rescue_srv.exe

LogMeIn Rescue by LogMeIn (Signed)

Remove lmi_rescue_srv.exe
Version:   7.1.389
MD5:   14b0b207dedfab58b157b5a66cabb937
SHA1:   8dce949c1375ca7eeca541fded55af896ebf00c0
SHA256:   56b0beaa68e50b7a2b14131ab28e1a3ab6c3599e0a50212ebd373a99d7851ba6

Overview

lmi_rescue_srv.exe runs as a service under the name LogMeIn Rescue (1fe40ef2-7c55-4580-9cc1-ca11b005ce6c) (LMIRescue_1fe40ef2-7c55-4580-9cc1-ca11b005ce6c) within the local user context. The file is digitally signed by LogMeIn which was issued by the VeriSign certificate authority (CA). This particular version is usually found on Microsoft Windows XP (5.1.2600.196608).

DetailsDetails

File name:lmi_rescue_srv.exe
Publisher:LogMeIn, Inc.
Product name:LogMeIn Rescue
Typical file path:C:\Documents and Settings\user\Application data\logmein rescue applet\lmir0001.tmp\lmi_rescue_srv.exe
Original name:LMI_Rescue.exe
File version:7.1.389
Size:2.42 MB (2,533,800 bytes)
Certificate
Issued to:LogMeIn
Authority (CA):VeriSign
Effective date:Monday, October 5, 2009
Expiration date:Wednesday, October 10, 2012
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'LMIRescue_1fe40ef2-7c55-4580-9cc1-ca11b005ce6c' (LogMeIn Rescue (1fe40ef2-7c55-4580-9cc1-ca11b005ce6c))

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00158741%
0.028634%
Kernel CPU:0.00087107%
0.013761%
User CPU:0.00071634%
0.014873%
Kernel CPU time:29,453 ms/min
100,923,805ms/min
Context switches:340/sec
284/sec
Memory
Private memory:6.36 MB
21.59 MB
Private (maximum):10.22 MB
Private (minimum):5.89 MB
Non-paged memory:6.36 MB
21.59 MB
Virtual memory:59.37 MB
140.96 MB
Virtual memory (peak):65.17 MB
169.69 MB
Working set:6.16 MB
18.61 MB
Working set (peak):10.28 MB
37.95 MB
Page faults:96,154/min
2,039/min
I/O
I/O read transfer:15.12 KB/sec
1.02 MB/min
I/O read operations:676/sec
343/min
I/O write transfer:22 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:5.6 KB/sec
448.09 KB/min
I/O other operations:1,335/sec
1,671/min
Resource allocations
Threads:10
12
Handles:263
600
GUI GDI count:27
103
GUI USER count:20
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command lines:
  • "C:\Documents and Settings\user\Application data\logmein rescue applet\lmir0003.tmp\lmi_rescue.exe" -gui -fontsize 0 -sid 1fe40ef2-7c55-4580-9cc1-ca11b005ce6c
  • "C:\Documents and Settings\user\Application data\logmein rescue applet\lmir0003.tmp\lmi_rescue_srv.exe" -service -sid 1fe40ef2-7c55-4580-9cc1-ca11b005ce6c
  • "C:\Documents and Settings\user\Application data\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe" -gui -fontsize 0 -sid 3d7030d9-39da-44dc-82de-2390f1797e74
  • "C:\Documents and Settings\user\Application data\logmein rescue applet\lmir0001.tmp\lmi_rescue_srv.exe" -service -sid 3d7030d9-39da-44dc-82de-2390f1797e74
Owner:User
Windows Service
Service name:LMIRescue_1fe40ef2-7c55-4580-9cc1-ca11b005ce6c
Display name:LogMeIn Rescue (1fe40ef2-7c55-4580-9cc1-ca11b005ce6c)
Type:Win32OwnProcess
Parent processes:

ResourcesThreads

Averages
 
LMI_Rescue_srv.exe (main module)
Total CPU:0.03834093%
0.272967%
Kernel CPU:0.02530889%
0.107585%
User CPU:0.01303204%
0.165382%
Context switches:75/sec
79/sec
Memory:2.57 MB
1.16 MB
advapi32.dll (Advanced Windows 32 Base API by Microsoft)
Total CPU:0.00058013%
Kernel CPU:0.00040950%
User CPU:0.00017063%
Context switches:2/sec
Memory:620 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE