Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

14.0.4.620 34.21%
14.0.3.336 13.16%
14.0.2.180 7.89%
14.0.0.335 44.74%

Relationships

Parent process
Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
DeleteService, OpenServiceW, OpenSCManagerW, CreateServiceW, CloseServiceHandle, AdjustTokenPrivileges, SetServiceStatus, LookupPrivilegeValueW, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, OpenProcessToken
kernel32.dll
VerifyVersionInfoW, VerSetConditionMask, GetVersionExW, GetModuleHandleW, DeviceIoControl, LoadLibraryA, GetTickCount, DecodePointer, EncodePointer, IsProcessorFeaturePresent, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, DeleteFileW, ReadConsoleInputW, QueryPerformanceFrequency, GetStdHandle, lstrlenW, CreateFileW, SetConsoleMode, FreeConsole, Sleep, WideCharToMultiByte, InitializeCriticalSection, WriteFile, SetConsoleScreenBufferSize, QueryPerformanceCounter, GetNumberOfConsoleInputEvents, AllocConsole, SetFilePointer, LocalFree, GetCurrentProcessId, CloseHandle, GetCurrentThreadId, DeleteCriticalSection, CreateEventW, InterlockedExchangeAdd, EnterCriticalSection, GetProcAddress, GetLastError, GetModuleFileNameW, LeaveCriticalSection, FormatMessageW, FreeLibrary, InitializeCriticalSectionAndSpinCount, LoadLibraryW, OutputDebugStringW, SetEvent, WaitForSingleObject, GetCurrentProcess, InterlockedCompareExchange, TerminateProcess, GetStartupInfoW, HeapSetInformation, InterlockedExchange
msvcp100.dll
DllMain
msvcr100.dll
DllMain
user32.dll
GetSystemMetrics

sched.exe

Avira Product Family by Avira Operations GmbH & Co. KG (Signed)

Remove sched.exe
Version:   14.0.0.335
MD5:   3478f48b23a0d9f6eadd4a2405ba70ef
SHA1:   89fbc5f0fc5854517b5da41fd6508c63dd859d4e

Overview

sched.exe runs as a service under the name Avira Planificateur (AntiVirSchedulerService) with extensive SYSTEM privileges (full administrator access). This is typically installed with the program Avira Free Antivirus published by Avira GmbH. The file is digitally signed by Avira Operations GmbH & Co. KG which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:sched.exe
Publisher:Avira Operations GmbH & Co. KG
Product name:Avira Product Family
Description:Antivirus Host Framework Service
Typical file path:C:\Program Files\avira\antivir desktop\sched.exe
Original name:avguard.exe
File version:14.0.0.335
Size:430.07 KB (440,392 bytes)
Build date:9/20/2013 2:31 PM
Certificate
Issued to:Avira Operations GmbH & Co. KG
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Avira GmbH
25% remove
Avira AntiVir Personal includes a branded version of the Ask.com Toolbar, a web browser extenstion that provides search advertising and results. Upon installation the user is presented with the option to install the Ask toolbar. If accepted, the toolbar will be installed in the user's web browser (Internet Explorer, Chrome and Firefox) and will modify the home page and search settings.

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'AntiVirSchedulerService' (Avira Planificateur)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00255311%
0.028634%
Kernel CPU:0.00119958%
0.013761%
User CPU:0.00135353%
0.014873%
Kernel CPU time:1,439,326 ms/min
100,923,805ms/min
CPU cycles:24,680/sec
17,470,203/sec
Memory
Private memory:3.22 MB
21.59 MB
Private (maximum):2.52 MB
Private (minimum):717.33 KB
Non-paged memory:3.22 MB
21.59 MB
Virtual memory:56.96 MB
140.96 MB
Virtual memory (peak):65.29 MB
169.69 MB
Working set:1.52 MB
18.61 MB
Working set (peak):6.36 MB
37.95 MB
Page faults:111,813/min
2,039/min
I/O
I/O read transfer:22.99 KB/sec
1.02 MB/min
I/O read operations:4/sec
343/min
I/O write transfer:358 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:43 Bytes/sec
448.09 KB/min
I/O other operations:5/sec
1,671/min
Resource allocations
Threads:9
12
Handles:154
600
GUI GDI count:4
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\avira\antivir desktop\sched.exe"
Owner:SYSTEM
Windows Service
Service name:AntiVirSchedulerService
Display name:Avira Planificateur
Description:“Service de commande des tâches de contrôle et mises à jour Avira Free Antivirus.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll
Total CPU:0.00278512%
0.272967%
Kernel CPU:0.00129681%
0.107585%
User CPU:0.00148831%
0.165382%
CPU cycles:42,102/sec
5,741,424/sec
Memory:252 KB
1.16 MB
msvcr100.dll (Microsoft Visual Studio 2010 by Microsoft)
Total CPU:0.00260896%
Kernel CPU:0.00100992%
User CPU:0.00159903%
Memory:764 KB
ADVAPI32.dll
Total CPU:0.00151485%
Kernel CPU:0.00067326%
User CPU:0.00084158%
Memory:620 KB
sched.exe (main module)
Total CPU:0.00129572%
Kernel CPU:0.00070518%
User CPU:0.00059054%
CPU cycles:22,689/sec
Memory:440 KB
sechost.dll
Total CPU:0.00023369%
Kernel CPU:0.00009759%
User CPU:0.00013609%
CPU cycles:5,295/sec
Memory:100 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 28.95%
Windows 7 Ultimate 23.68%
Microsoft Windows XP 13.16%
Windows 8 Single Language 10.53%
Windows 8 Pro 10.53%
Windows 7 Starter 5.26%
Windows 7 Professional 5.26%
Windows 8.1 2.63%

Distribution by countryDistribution by country

Philippines installs about 26.32% of Avira Product Family.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 23.73%
Toshiba 20.34%
Sony 13.56%
GIGABYTE 10.17%
Acer 10.17%
Compaq 6.78%
ASUS 6.78%
Dell 3.39%
Medion 3.39%
Samsung 1.69%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE