> Source: [sk142372](https://support.checkpoint.com/results/sk/sk142372)

# sk142372 - Endpoint Forensic Recorder Service (EFRService.exe) creates high CPU usage 

| Property | Value |
|----------|-------|
| Solution ID | sk142372 |
| Date Created | 2018-12-12 |
| Last Modified | 2023-08-10 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Consistently high CPU usage (20%-100%) of Endpoint Forensic Recorder Service (EFRService.exe) appears in the process manager.  

* The following error frequently appears in efrsal_reg.log:   
  "BaseSal::Run: Asynchronous operation error, 31 - A device attached to the system is not functioning"  

* The Countersignatures signer should be: `COMODO SHA-1 Time Stamping Signer`.

  In order to check this, open the **Process Manager** , right-click **EFRService.exe** , select **Properties** ,**Digital Signatures** tab, and double-click on the Check Point certificate.   

  **Example**:

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1544536197954/cert1812110810.PNG)

## Solution

This problem was fixed. The fix is included in:

* **[Endpoint Client version E80.87](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk135432)**

Check Point recommends to always [upgrade to the most recent version.](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=175)  

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
