Did Epson techs mess up our MacBook with Malware?
I had a problem when trying to print documents from my iPads on our Epson printer - it wouldn’t offer but 3 paper choices, none 8.5”X11”. I used the Chat on an Epson site and a tech called me. He took control of my MacBook Pro for a bit then showed me in a long list of code what he claimed was a malicious driver disrupting our network’s ability to print, circling something named “csrss.exe” Trojan. He said he and anyone could see my network address, read it to me, and claimed it was unprotected. He said he’d connect me with two techs, one would check the printer for free while the other would “clean” the MacBook for $250.
Now I’ve been repeatedly told that Apple devices are pretty invulnerable and basic caution online and timely updates are about all one needs. But this fellow caught me in a bad mood, frustrated after months dealing with the printing issue and other problems of the day, and believing one should be able to trust reps of established companies like Epson, I reluctantly agreed. The printer was still acting inconsistently when that so-called “fix” was done, but afterward I think I inadvertently ran across the cause buried in its paper source settings, and hopefully resolved it myself. But when the initial tech came back on the phone, I scanned a check I wrote to some company he gave me the name of, and he copied it off my scanned documents files. At this point I’m really feeling antsy about trusting this deal, but it was Epson after all - a well known old company of integrity and quality products.
When time allowed later I read in this forum and other places about the “csrss.exe” thing and now suspect I’ve been tricked. He tried selling me a security service with outlandish prices and multiple timeline choices, but at that I balked. He is calling back tomorrow, supposedly to see if I chose a service. Scare tactics to draw in susceptible owners to unnecessary security services is not something I expected from Epson; except for the one paper media glitch, that 3 year old ET-8500 printer is the best I’ve ever owned.
So I’m not going to go for their “security” install or program, and if confirmed here that the csrss.exe is not an infection (theoretically now “cleaned” along with my network) but rather a common Windows program reference of some sort, I will cancel my check.
But what should I do now? Having had control of my MacBook for awhile, might he have successfully added an actual threat?
MacBook Pro (2017 – 2020)