Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

14.0.4.620 34.21%
14.0.3.336 13.16%
14.0.2.180 7.89%
14.0.0.335 44.74%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
DeleteService, OpenServiceW, OpenSCManagerW, CreateServiceW, CloseServiceHandle, AdjustTokenPrivileges, SetServiceStatus, LookupPrivilegeValueW, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, OpenProcessToken
kernel32.dll
VerifyVersionInfoW, VerSetConditionMask, GetVersionExW, GetModuleHandleW, DeviceIoControl, LoadLibraryA, GetTickCount, DecodePointer, EncodePointer, IsProcessorFeaturePresent, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, DeleteFileW, ReadConsoleInputW, QueryPerformanceFrequency, GetStdHandle, lstrlenW, CreateFileW, SetConsoleMode, FreeConsole, Sleep, WideCharToMultiByte, InitializeCriticalSection, WriteFile, SetConsoleScreenBufferSize, QueryPerformanceCounter, GetNumberOfConsoleInputEvents, AllocConsole, SetFilePointer, LocalFree, GetCurrentProcessId, CloseHandle, GetCurrentThreadId, DeleteCriticalSection, CreateEventW, InterlockedExchangeAdd, EnterCriticalSection, GetProcAddress, GetLastError, GetModuleFileNameW, LeaveCriticalSection, FormatMessageW, FreeLibrary, InitializeCriticalSectionAndSpinCount, LoadLibraryW, OutputDebugStringW, SetEvent, WaitForSingleObject, GetCurrentProcess, InterlockedCompareExchange, TerminateProcess, GetStartupInfoW, HeapSetInformation, InterlockedExchange
msvcp100.dll
DllMain
msvcr100.dll
DllMain
user32.dll
GetSystemMetrics

sched.exe

Avira Product Family by Avira Operations GmbH & Co. KG (Signed)

Remove sched.exe
Version:   14.0.3.336
MD5:   4d282b9c5bb05df92c9f3977dfb9f916
SHA1:   74acae18df793ae74117726f97b1a6efbb4fdae0

Overview

sched.exe runs as a service under the name Avira Planificateur (AntiVirSchedulerService) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Avira Operations GmbH & Co. KG which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:sched.exe
Publisher:Avira Operations GmbH & Co. KG
Product name:Avira Product Family
Description:Antivirus Host Framework Service
Typical file path:C:\Program Files\avira\antivir desktop\sched.exe
Original name:avguard.exe
File version:14.0.3.336
Size:430.08 KB (440,400 bytes)
Build date:2/13/2014 3:26 PM
Certificate
Issued to:Avira Operations GmbH & Co. KG
Authority (CA):VeriSign
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'AntiVirSchedulerService' (Avira Planificateur)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00200688%
0.028634%
Kernel CPU:0.00095034%
0.013761%
User CPU:0.00105654%
0.014873%
Kernel CPU time:1,768,256 ms/min
100,923,805ms/min
CPU cycles:51,151/sec
17,470,203/sec
Memory
Private memory:3.12 MB
21.59 MB
Private (maximum):3.42 MB
Private (minimum):534.67 KB
Non-paged memory:3.12 MB
21.59 MB
Virtual memory:48.1 MB
140.96 MB
Virtual memory (peak):53.94 MB
169.69 MB
Working set:1.11 MB
18.61 MB
Working set (peak):5.98 MB
37.95 MB
Page faults:32,247/min
2,039/min
I/O
I/O read transfer:51.6 KB/sec
1.02 MB/min
I/O read operations:12/sec
343/min
I/O write transfer:165 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:46 Bytes/sec
448.09 KB/min
I/O other operations:4/sec
1,671/min
Resource allocations
Threads:7
12
Handles:138
600
GUI GDI count:4
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\avira\antivir desktop\sched.exe"
Owner:SYSTEM
Windows Service
Service name:AntiVirSchedulerService
Display name:Avira Planificateur
Description:“Service de commande des tâches de contrôle et mises à jour Avira Free Antivirus.”
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
advapi32.dll (Advanced Windows 32 Base API by Microsoft)
Total CPU:0.00169572%
0.272967%
Kernel CPU:0.00084786%
0.107585%
User CPU:0.00084786%
0.165382%
Memory:620 KB
1.16 MB
msvcr100.dll (Microsoft Visual Studio 2010 by Microsoft)
Total CPU:0.00123656%
Kernel CPU:0.00047280%
User CPU:0.00076376%
Memory:764 KB
sched.exe (main module)
Total CPU:0.00083592%
Kernel CPU:0.00047848%
User CPU:0.00035744%
Memory:440 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 28.95%
Windows 7 Ultimate 23.68%
Microsoft Windows XP 13.16%
Windows 8 Single Language 10.53%
Windows 8 Pro 10.53%
Windows 7 Starter 5.26%
Windows 7 Professional 5.26%
Windows 8.1 2.63%

Distribution by countryDistribution by country

Philippines installs about 26.32% of Avira Product Family.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Lenovo 23.73%
Toshiba 20.34%
Sony 13.56%
GIGABYTE 10.17%
Acer 10.17%
Compaq 6.78%
ASUS 6.78%
Dell 3.39%
Medion 3.39%
Samsung 1.69%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE