Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

13.6.20.2100 8.50%
13.6.20.2100 0.65%
13.6.20.2100 0.65%
13.6.20.2100 0.65%
13.6.20.2100 1.96%
13.6.20.2100 0.65%
13.6.0.1550 3.27%
13.6.0.1550 1.96%
13.6.0.1550 1.96%
13.6.0.778 4.58%
13.6.0.778 6.54%
13.6.0.778 0.65%
13.6.0.652 16.99%
13.6.0.652 0.65%
13.6.0.652 0.65%
13.6.0.652 0.65%
13.6.0.652 0.65%
13.6.0.652 0.65%
13.6.0.400 11.11%
13.6.0.400 4.58%
13.4.0.300 0.65%
13.4.0.232 2.61%
12.3.0.15 24.84%
12.3.0.15 1.96%
12.3.0.15 0.65%
View more

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
DeleteService, OpenServiceW, OpenSCManagerW, CreateServiceW, CloseServiceHandle, AdjustTokenPrivileges, SetServiceStatus, LookupPrivilegeValueW, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, OpenProcessToken
kernel32.dll
VerifyVersionInfoW, VerSetConditionMask, GetVersionExW, GetModuleHandleW, LoadLibraryA, GetTickCount, InterlockedExchange, DecodePointer, IsProcessorFeaturePresent, GetSystemTimeAsFileTime, GetCurrentThreadId, IsDebuggerPresent, SetUnhandledExceptionFilter, DeleteFileW, ReadConsoleInputW, DeleteCriticalSection, QueryPerformanceFrequency, EnterCriticalSection, GetStdHandle, lstrlenW, CreateFileW, SetConsoleMode, LeaveCriticalSection, FreeConsole, Sleep, WideCharToMultiByte, InitializeCriticalSection, WriteFile, SetConsoleScreenBufferSize, QueryPerformanceCounter, GetNumberOfConsoleInputEvents, AllocConsole, SetFilePointer, LocalFree, GetCurrentProcessId, CloseHandle, CreateEventW, InterlockedExchangeAdd, GetProcAddress, GetLastError, GetModuleFileNameW, FormatMessageW, LoadLibraryW, FreeLibrary, OutputDebugStringW, SetEvent, WaitForSingleObject, GetCurrentProcess, DeviceIoControl, UnhandledExceptionFilter, TerminateProcess, EncodePointer, GetStartupInfoW, HeapSetInformation, InterlockedCompareExchange, InitializeCriticalSectionAndSpinCount
msvcp100.dll
DllMain
msvcr100.dll
DllMain
user32.dll
GetSystemMetrics

sched.exe

Avira Free Antivirus by Avira Operations GmbH & Co. KG (Signed)

Remove sched.exe
Version:   13.6.0.778
MD5:   7cf87de4109e854e8f4ae2910a711a73
SHA1:   83a5e3472098011792bf7bc3d7d84184f79d2987
SHA256:   07f0781bb2fc12eef0b5b5d450c57467ff1fabea51207c613eed3565f91e6afb

What is sched.exe?

Avira Scheduler. This edition of Avira Antivirus is free of charge and runs as a background process which checks every file opened or downloaded. Like many antivirus programs, it can run a full or custom scan to check the PC for malware in order to remove them. It updates its virus definitions automatically everyday by default using the Internet.

About sched.exe (from Avira Operations GmbH & Co. KG)

Our entry-level antivirus eliminates many forms of malware, including worms, rootkits and costly dialers. System Scanner prevents infection from viruses, worms and Trojans. AHeAD Technology halts unkn

Overview

sched.exe runs as a service under the name Avira Agendamento (AntiVirSchedulerService) within the local user context. The file is digitally signed by Avira Operations GmbH & Co. KG which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:sched.exe
Publisher:Avira Operations GmbH & Co. KG
Product name:Avira Free Antivirus
Description:Avira Scheduler
Typical file path:C:\Program Files\avira\antivir desktop\sched.exe
File version:13.6.0.778
Size:84.72 KB (86,752 bytes)
Build date:2/15/2013 11:04 AM
Certificate
Issued to:Avira Operations GmbH & Co. KG
Authority (CA):VeriSign
Expiration date:Sunday, July 20, 2014
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C++ 10.0
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • AntiVirSchedulerService

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00151645%
0.028634%
Kernel CPU:0.00071724%
0.013761%
User CPU:0.00079921%
0.014873%
Kernel CPU time:140,625 ms/min
100,923,805ms/min
Memory
Private memory:2.52 MB
21.59 MB
Private (maximum):1.6 MB
Private (minimum):80 KB
Non-paged memory:2.52 MB
21.59 MB
Virtual memory:36.95 MB
140.96 MB
Virtual memory (peak):40.97 MB
169.69 MB
Working set:216 KB
18.61 MB
Working set (peak):5.07 MB
37.95 MB
Resource allocations
Threads:5
12
Handles:118
600
GUI GDI count:4
103
GUI USER count:2
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\avira\antivir desktop\sched.exe"
Owner:User
Windows Service
Service name:AntiVirSchedulerService
Display name:Avira Agendamento
Description:“Serviço para programar tarefas e atualizações do Avira Free Antivirus.”
Type:Win32OwnProcess
Parent process:services.exe (by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 34.64%
Microsoft Windows XP 27.45%
Windows 7 Home Premium 16.99%
Windows 7 Professional 11.76%
Windows Vista Home Premium 2.61%
Windows 7 Home Basic 1.96%
Windows 8 Pro 1.31%
Windows 7 Enterprise 1.31%
Windows 7 Starter 1.31%
Windows Vista Business 0.65%

Distribution by countryDistribution by country

Malaysia installs about 14.00% of Avira Free Antivirus.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 27.42%
Hewlett-Packard 20.97%
Toshiba 11.29%
Intel 9.68%
Acer 7.26%
Lenovo 6.45%
Dell 6.45%
Compaq 3.23%
Samsung 1.61%
MSI 1.61%
GIGABYTE 1.61%
Sahara 1.61%
American Megatrends 0.81%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE