EFRService.exe

End Point Security

Check Point Software Technologies Ltd.

It runs as a separate (within the context of its own process) windows Service named “Check Point Endpoint EFR”.
Publisher:

Product:
End Point Security

Description:
Check Point Endpoint Forensic Recorder service

Version:
860010601

MD5:
ed6fd4f74961d9fa4d43d125f04018a4

SHA-1:
d1e2a060d22c6bb4ea144e3a92672455b7e956c6

SHA-256:
d604a9a89e01ef628de5342d841d95ff0b5c25224dcbddc01c9da274740d39a7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/17/2026 2:18:36 PM UTC  (today)

File size:
949.5 KB (972,304 bytes)

Product version:
R80

Copyright:
2009 Copyright Check Point Software Technologies Ltd.

Original file name:
EFRService.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\checkpoint\endpoint security\efr\efrservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/11/2014 8:00:00 PM

Valid to:
7/10/2017 7:59:59 PM

Subject:
CN=Check Point Software Technologies Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Check Point Software Technologies Ltd., L=Ramat-Gan, S=Ramat-Gan, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47E81C30F2CA2304E8F8BC304E44AB6F

File PE Metadata
Compilation timestamp:
7/1/2015 10:43:16 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
24576:56rNqvmBW3VvcATzQKNa2anh0NoNz7lKMB:K4zQ/mNoF7lKE

Entry address:
0x6CF0C

Entry point:
E8, A7, 18, 01, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, 56, FC, 8B, 75, 0C, 8B, 4E, 08, 33, CE, E8, F2, 96, FF, FF, 6A, 00, 56, FF, 76, 14, FF, 76, 0C, 6A, 00, FF, 75, 10, FF, 76, 10, FF, 75, 08, E8, BC, 61, 00, 00, 83, C4, 20, 5E, 5D, C3, 55, 8B, EC, 51, 53, FC, 8B, 45, 0C, 8B, 48, 08, 33, 4D, 0C, E8, BF, 96, FF, FF, 8B, 45, 08, 8B, 40, 04, 83, E0, 66, 74, 11, 8B, 45, 0C, C7, 40, 24, 01, 00, 00, 00, 33, C0, 40, EB, 6C, EB, 6A, 6A, 01, 8B, 45, 0C, FF, 70, 18, 8B, 45, 0C, FF, 70, 14, 8B, 45, 0C, FF, 70, 0C, 6A...
 
[+]

Entropy:
6.5279

Code size:
660 KB (675,840 bytes)

Service
Display name:
Check Point Endpoint EFR

Service name:
CPEFR

Description:
Check Point Endpoint Security Forensics service

Type:
Win32OwnProcess

Depends on:
epnetflt cpepmon


Scan EFRService.exe - Powered by Reason Core Security