Did Epson techs mess up our MacBook with Malware?

I had a problem when trying to print documents from my iPads on our Epson printer - it wouldn’t offer but 3 paper choices, none 8.5”X11”. I used the Chat on an Epson site and a tech called me. He took control of my MacBook Pro for a bit then showed me in a long list of code what he claimed was a malicious driver disrupting our network’s ability to print, circling something named “csrss.exe” Trojan. He said he and anyone could see my network address, read it to me, and claimed it was unprotected. He said he’d connect me with two techs, one would check the printer for free while the other would “clean” the MacBook for $250.


Now I’ve been repeatedly told that Apple devices are pretty invulnerable and basic caution online and timely updates are about all one needs. But this fellow caught me in a bad mood, frustrated after months dealing with the printing issue and other problems of the day, and believing one should be able to trust reps of established companies like Epson, I reluctantly agreed. The printer was still acting inconsistently when that so-called “fix” was done, but afterward I think I inadvertently ran across the cause buried in its paper source settings, and hopefully resolved it myself. But when the initial tech came back on the phone, I scanned a check I wrote to some company he gave me the name of, and he copied it off my scanned documents files. At this point I’m really feeling antsy about trusting this deal, but it was Epson after all - a well known old company of integrity and quality products.


When time allowed later I read in this forum and other places about the “csrss.exe” thing and now suspect I’ve been tricked. He tried selling me a security service with outlandish prices and multiple timeline choices, but at that I balked. He is calling back tomorrow, supposedly to see if I chose a service. Scare tactics to draw in susceptible owners to unnecessary security services is not something I expected from Epson; except for the one paper media glitch, that 3 year old ET-8500 printer is the best I’ve ever owned.


So I’m not going to go for their “security” install or program, and if confirmed here that the csrss.exe is not an infection (theoretically now “cleaned” along with my network) but rather a common Windows program reference of some sort, I will cancel my check.


But what should I do now? Having had control of my MacBook for awhile, might he have successfully added an actual threat?

MacBook Pro (2017 – 2020)

Posted on Sep 10, 2026 5:19 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 11, 2026 9:37 PM

Catastrophic breach. Reset macOS, and restore your pre-breach Time Machine backup.


Don’t bother with add-on anti-malware or other add-ons, which are approximately ineffective at detecting back doors and all of the rubbish. Whether it finds some, it might not or will not find all of it, or find various add-ons or settings-related changes.


(I spent several days trying to verify whether a breached Mac was backdoored, and wasn’t ever entirely certain it was clear. This because the owners had production data, and no backups. I don’t recommend it. Either. The manual cleanup, or the no-backups. And yes, I found some “shenanigans” left, as well as some tools.)


That csrss.exe is part of the scam, and the scammers can load it and then call it out. Delete it. The lingering issue is not about that file either, it is about what else got changed, added, or reconfigured. Chasing all the possibilities is an immense project, and restoring your most recent Time Machine backup followed by password changes and payment cards changed, too. And anti-malware isn’t going to find an added account with a known password, etc.


Claims of invulnerability are best used as a way to identify people you might want to ignore, too.


Epson EcoTank Photo ET-8500 supports AirPrint, TWAIN, and ICA, which means it does not need add-on vendor drivers for common operations. There is a firmware update from last year, ON28P8. Once macOS is reaet and your Time Machine restored, ensure that’s loaded.


Google search results are too often tech support scams, if that is what you used. That Epson has a confusing array of websites doesn’t help.

12 replies
Question marked as Top-ranking reply

Sep 11, 2026 9:37 PM in response to Hafcanadian

Catastrophic breach. Reset macOS, and restore your pre-breach Time Machine backup.


Don’t bother with add-on anti-malware or other add-ons, which are approximately ineffective at detecting back doors and all of the rubbish. Whether it finds some, it might not or will not find all of it, or find various add-ons or settings-related changes.


(I spent several days trying to verify whether a breached Mac was backdoored, and wasn’t ever entirely certain it was clear. This because the owners had production data, and no backups. I don’t recommend it. Either. The manual cleanup, or the no-backups. And yes, I found some “shenanigans” left, as well as some tools.)


That csrss.exe is part of the scam, and the scammers can load it and then call it out. Delete it. The lingering issue is not about that file either, it is about what else got changed, added, or reconfigured. Chasing all the possibilities is an immense project, and restoring your most recent Time Machine backup followed by password changes and payment cards changed, too. And anti-malware isn’t going to find an added account with a known password, etc.


Claims of invulnerability are best used as a way to identify people you might want to ignore, too.


Epson EcoTank Photo ET-8500 supports AirPrint, TWAIN, and ICA, which means it does not need add-on vendor drivers for common operations. There is a firmware update from last year, ON28P8. Once macOS is reaet and your Time Machine restored, ensure that’s loaded.


Google search results are too often tech support scams, if that is what you used. That Epson has a confusing array of websites doesn’t help.

Sep 12, 2026 12:49 AM in response to Hafcanadian

This is unfortunately a very well-documented tech support scam pattern, and there's one detail here that confirms it beyond doubt: csrss.exe is a Windows system process (Client/Server Runtime Subsystem) — it is part of Windows, full stop. It does not exist on macOS in any form. There is no file, process, or equivalent by that name anywhere on a Mac. A "tech" circling something called csrss.exe on your MacBook and calling it a Trojan wasn't reading anything real from your machine — he was running a generic scare script (or reciting a scam playbook memorized from Windows support scams) without even checking what OS he was looking at. That alone tells you everything about who you were actually talking to.


The rest of the pattern matches too: remote control to "show" you something alarming, reading your network/IP info back to you as if it proves compromise (it doesn't — that information isn't secret or dangerous on its own), then splitting the pitch into a "free" diagnostic and a paid "cleanup," followed by a harder sell to a "security service" once you hesitated. That's the scam funnel, not a legitimate Epson support escalation.


The part I'd actually treat as urgent, more than the malware claim, is that this person had remote access to your screen and, by your own account, scanned and copied off an image of a signed check while pretending to review "documents." That's not a vague risk — a check image gives someone your bank name, account number, routing number, and signature, which is enough for check fraud or an attempted unauthorized draw. I'd do this today, not after they call back tomorrow:


1. Call your bank directly (using the number on the back of your card or their official site, not anything from this interaction) and tell them a check image was compromised. Ask about a stop-payment on that specific check and whether they recommend closing/reissuing the account given the exposure.

2. Assume that "tech" is not legitimate and do not accept the callback tomorrow, do not pay for any "cleanup" or "security service," and don't give them access again.

3. On the Mac itself, check System Settings > General > Login Items & Extensions (and Privacy & Security) for anything installed during that session you don't recognize, especially remote-access software beyond whatever official screen-share tool Epson's chat used, and remove it.

4. Change your Epson account password and any password you may have typed while they had visual/remote access to the screen.

5. You do not need a paid "security install" — macOS doesn't work like the scenario he described, and there's nothing here suggesting your Mac itself is actually infected. The financial exposure from the check is the real thing to run down.


Good instinct holding off on the sale — the printer issue and the "infection" were never actually connected, and it's worth reporting this Epson chat interaction to Epson directly as well, since it sounds like either a rogue contractor or a scam operation impersonating their support channel.

Sep 10, 2026 5:46 AM in response to Hafcanadian

You were target of a classic, highly sophisticated technical support scam. You did not speak to real Epson employees; instead, you accidentally landed on a spoofed or fraudulent website that impersonated their support chat. 


Do this

  • Cancel the Check: Call your bank immediately to issue a Stop Payment on the check you wrote. Because the scammer has a digital copy of the check, they have your routing and account numbers. Explain to your bank's fraud department that a scammer intercepted your banking details. They may advise closing that account and moving your funds to a secure, new account.
  • Block the Callers: When the scammer calls you back tomorrow, do not answer. Block the number. If you accidentally pick up, hang up immediately without saying a word. They will try to intimidate or manipulate you; do not engage.

Disconnect from the Internet: Turn off your Wi-Fi immediately while you perform the cleanup steps below to prevent them from logging back in remotely.

Remove Remote Access Software: Go to your Applications folder and delete any remote tools they made you download (common ones include TeamViewer, AnyDesk, LogMeIn, GoToAssist, or Zoom). Drag them to the Trash and empty it. 

Change Your Passwords: Once your Mac is confirmed clean, change the passwords to your most critical accounts especially your Apple ID, primary email addresses, and online banking profiles.


Sep 11, 2026 9:03 PM in response to Hafcanadian

Hafcanadian wrote:
I used the Chat on an Epson site and a tech called me.

That's not how Epson support works. There is no Chat. You visit the page for your product and there you can find contact phone numbers where you contact them.


Also this on Epson's site:


Technical Support Fraud Alert

 

The FBI recently issued a Public Service Announcement regarding technical support fraud. Tech Support Fraud involves a criminal claiming to provide customer, security, or technical support in an effort to defraud unwitting individuals. This scam is particularly effective because victims think they are contacting a legitimate technical support team. To learn more about this scam, please see the FBI’s Public Service Announcement.

 

If you believe you are a victim of an online scam regardless of the dollar amount, you can file a complaint with your local law enforcement, the FBI IC3 unit, or the Federal Trade Commission.


Epson’s Customer Service and Support is Always Free


He took control of my MacBook Pro for a bit ... He said he’d connect me with two techs, one would check the printer for free while the other would “clean” the MacBook for $250.

Note above from Epson's real web site: Epson's Customer Service and Support is Always Free.


Also, Epson does not sell any "cleaning" or "security" products.

But what should I do now? Having had control of my MacBook for awhile, might he have successfully added an actual threat?

See WheelieNick's list of recommendations. If you had credit card numbers or other financial account info on the computer, whoever was impersonating Epson (it wasn't Epson) may have copied it off while they were logged in to your Mac. So you may need to "freeze" all those accounts and next steps would be to replace them all with new accounts and new account numbers. Which will entail new credit cards as well.


To that I would add download Malwarebytes and/or Etrecheck and run them. Both use different methods to look for malware and both help you remove it.

Sep 12, 2026 8:54 AM in response to Hafcanadian

Hafcanadian wrote:
I had the MacBook “cleaned”.

macOS doesn’t usually need cleaning. Things that can cause the perception that a Mac needs to be cleaned:

  • there’s a software problem, such as too much stuff in too small a Mac, or a too-small and too-full storage, or too-slow storage, etc.
  • there’s a hardware problem
  • add-in “cleaner” apps, add-on “security” apps, add-on VPN apps, cracked apps and keygen apps, adware and “free stuff” apps doing all of what they do: collecting everything, getting tangled, and variously themselves getting compromised
They wanted to put Trendmicro on it, but I declined. He put a free 30 day trial version on it anyway.

i’d expect places that do that probably get paid to load various (too often unnecessary and problematic) apps.


Restoring your backup from prior to the breach will remove the add-on app.

The WiFi has been turned off for over 2 days, so when I got the laptop home I recontacted the bank to finish what they needed me to do afterward. Then I contacted the internet provider and got the router reset with a new password, and will have to spend the weekend reattaching multiple devices to it.

Banks wouldn’t be my go-to for security advice. Not past assisting with their own bank-specific account security practices, and that’s usually mostly enabling two-factor authentication, and proper password care.

But I’m wondering about if the 3 iPads, iPhone, and Pixel phone could have been affected, and need checking.

Restore the compromised Mac, reset your passwords, particularly your Apple Account, and enable two-factor authentication on your Apple Account if not already.


Add-on apps won’t help here, and too often won’t help generally, and add-on “security” can hinder, and add-on “security” apps can themselves be targeted for exploits.


While Mac is not immune to malware, that seems rather less an issue here given it is you yourself that is getting hacked here. Not your gear. You. Us. We ourselves are the target.


The scammers convinced you (probably by Google ad placement), and the repair provider convinced you (quite possibly to get a payment from the app vendor) to do things against your own interests, and here we are with what is probably a still-compromised Mac now with add-on security apps loaded, and a Mac that probably still has the (beachballing?) issue you were seeking to have “cleaned”. And seemingly with no password reset yet?


Related: iPhone, iPad or Apple Account Security Co… - Apple Community


TL;DR: it’s increasingly easy to scam us and to fool us and to get us to compromise our own security, as compared with directly compromising our gear. Our Mac or our iPhone isn’t the direct target. We are. We then give access. There’s no add-on app that can fix our own vulnerabilities to these advertising-based schemes, either.

Sep 12, 2026 9:25 AM in response to Hafcanadian

Hafcanadian wrote:
I had the MacBook “cleaned”. They wanted to put Trendmicro on it, but I declined. He put a free 30 day trial version on it anyway.

That's not good and leads me to question the judgement of whomever "cleaned" the MacBook Pro. Trendmicro is a security and antivirus suite that eventually may interfere with the macOS protection you have. You will want to remove this.

The WiFi has been turned off for over 2 days, so when I got the laptop home I recontacted the bank to finish what they needed me to do afterward. Then I contacted the internet provider and got the router reset with a new password, and will have to spend the weekend reattaching multiple devices to it.

I would think that could be done in less than an hour, isn't it just logging in to the WiFi with the new password.

But I’m wondering about if the 3 iPads, iPhone, and Pixel phone could have been affected, and need checking.

They could have been affected if they are sharing the same Apple ID/account as your Mac. Also, it depends on whether you are using cloud storage (iCloud, Dropbox, etc.) because while the scammers were logged in to your Mac they could have been looking at things, changing things, or installing things or whatnot without you even seeing (it could have been on a screen you could not even see).


I think it is important to change the password of your Apple ID/account if you have not done so already. As well as login passwords for all accounts on all devices. Changing these passwords is not hard to do, but you need to be organized about it, make a list (on a piece of paper) and change everything on that list.


I guess I now agree with MrHoffman. Not knowing what was done or changed to your Mac while they were logged in (terminal commands could have been entered that you might have no record of), I would suggest a complete wipe and reset of your Mac, it's what I would do myself. The steps to follow are here:


What to do before you sell, give away, trade in, or recycle your Mac - Apple Support


This restores your Mac to the condition of a new computer with nothing on it. It will be completely erased so you need to have a backup of all your files so you can copy them back to the "new" Mac.


One way is to use Setup Assistant on first boot up and bring back files from a Time Machine backup. If you do this, it is imperative that it be a Time Machine backup done before your breach.


If this is not available, you can manually restore files piecemeal using Finder copies from a backup or other copy of what you had. If those copies were made before the breach, you should be safe. If made after the breach, I think I would bring back contents only of Documents, Desktop, Downloads but inspect them for anything that looks unfamiliar to you; if the backup dates from after your breach, I would not bring back anything from your user Library folder because that could have been compromised and direct browsers or other software to do things you don't want. If you are using GMAIL or IMAP email, that can be re-downloaded. If using POP email or you have "on my Mac" stored email, those can be manually restored from the Mail folder inside your user Library. Cloud stored files will re-download automatically.


If you don't have a backup at all, then copy to an external drive the contents of your Documents, Downloads, Desktop, and Mail folders (Mail folder is inside your Library folder). Inspect these folders for unfamiliar items and delete them. Then use them to restore to the completely erased Mac.


It would be preferable to restore files from a backup done before the breach.

Sep 12, 2026 4:41 AM in response to Hafcanadian

Hafcanadian wrote:
I had the MacBook “cleaned”. They wanted to put Trendmicro on it, but I declined. He put a free 30 day trial version on it anyway.


The real Trend Micro (there is apparently a Mac version)? Or some Trojan Horse program that puts up a screen making it look like an "anti-virus" program so you won't realize that what was installed was some remote access program or spyware ("keystroke logger") program to create an ongoing compromise to your system security?


Any program that the scammers installed needs to be removed from that Mac with extreme prejudice. Although core parts of macOS are hardened against malware attack, a password stealer could well be planted in some part of the system that you, as an Administrator installing an application, would have permission to modify. You don't want to secure your bank account only to unwittingly hand the new keys to the scammers.


Or, in the immortal words of Ellen Ripley (Aliens), "I say we take off and nuke the site from orbit. It's the only way to be sure."

Sep 10, 2026 3:59 PM in response to Hafcanadian

Hafcanadian wrote:
I had a problem when trying to print documents from my iPads on our Epson printer - it wouldn’t offer but 3 paper choices, none 8.5”X11”. I used the Chat on an Epson site and a tech called me. He took control of my MacBook Pro for a bit then showed me in a long list of code what he claimed was a malicious driver disrupting our network’s ability to print, circling something named “csrss.exe” Trojan. He said he and anyone could see my network address, read it to me, and claimed it was unprotected. He said he’d connect me with two techs, one would check the printer for free while the other would “clean” the MacBook for $250.



good lord...


Recognize and avoid phishing messages, phony support calls

Recognize and avoid social engineering schemes including phishing messages, phony support calls, and other scams - Apple Support


Sep 12, 2026 12:47 AM in response to Hafcanadian

I had the MacBook “cleaned”. They wanted to put Trendmicro on it, but I declined. He put a free 30 day trial version on it anyway. The WiFi has been turned off for over 2 days, so when I got the laptop home I recontacted the bank to finish what they needed me to do afterward. Then I contacted the internet provider and got the router reset with a new password, and will have to spend the weekend reattaching multiple devices to it.


But I’m wondering about if the 3 iPads, iPhone, and Pixel phone could have been affected, and need checking.

Sep 25, 2026 4:58 PM in response to WheelieNick

3 main points to hit, and any input is appreciated:

-email changing;

-MacBook reset done, -malwarebytes?

-home network afoul.


Forgive my ignorance. We've had the same email addresses since 1995. I think there are latent ones left over from an old Verizon or Frontier association, but I haven't seen them or visited the sites for probably a decade. So I'm not familiar with how to run your suggested email/password changes, if doing so would mess with decades of user ID's and contacts' communications, so I'm reluctant to approach that perhaps daunting endeavor. The flip side is that for the last 2 months, prior to this breach, I've been inundated with junk email, dozens daily compared to 6 or 8 previously. Changing email addresses theoretically would ameliorate having to constantly peruse tons of junk for any misplaced legitimate mail.


I took the laptop to the Apple Store Monday and they sent files to the Cloud, wiped the machine, then reloaded it with the latest OS 26.7, etc. I'd not been able to get our emails on the laptop's Mail app for 2 years, and had loaded Outlook on it to get them; the iPads, iPhone, iWatch - no problem with Mail. Apple Store techs fixed that while they were at it - something to do with Microsoft "Exchange"; I lost track during her explanation 😳.


They also recommend Malwarebytes as protection against whatever bad things that may be out there that can still be harmful even to Apple users. They loaded just an introductory page for that on the Safari, but I'm just asking here if you also think that is a reasonable step to take, or is it unnecessary given Apple's relative invulnerability. Would it protect against a repeat of my recent stupidity? Protecting the machine is one thing, but protecting against my personal human carelessness, in times of stress like that day was, is another. If it can pick up on fraudulent sites/scams, and keep us from another fiasco like this, it could be worth it.


I'm having issues at home with our fiber WiFi as even though last week the provider walked me through changing the password, some channels retain the old one. It's complicated by our two extenders, so with Guest channels and 2G and 5G, there can be up to 12 channels involved - some using the new pwd and others the old. I've slowly been trying to sort out what's what, and have all our in-house devices reprogrammed (PITA!) to one 5G basic router channel on the new pwd.


Frustrated, I have them sending a tech tomorrow to help straighten the network out, as sometimes the router/extender's sites will open on the iPad and sometimes it won't, so I've modified some extender settings when I could, but stubbornly the base router can't be connected to with any pwd, contrary to its site saying its fine. So when a device that's on automatic searches and finds that strong channel, it tries but fails to connect. Even though the router is supplied rent-free, I'm considering going to a TP-link Deco, 3-piece Mesh setup, so the satellite units reflect the same channels/passwords because its all one network.



Sep 25, 2026 6:57 PM in response to Hafcanadian

Hafcanadian wrote:
3 main points to hit, and any input is appreciated:
Forgive my ignorance. We've had the same email addresses since 1995.

How long an email account has existed isn’t all that relevant to a breach.

I think there are latent ones left over from an old Verizon or Frontier association, but I haven't seen them or visited the sites for probably a decade.

Delete accounts you’re not using, or delete the saved passwords for now-gone accounts.

So I'm not familiar with how to run your suggested email/password changes, if doing so would mess with decades of user ID's and contacts' communications, so I'm reluctant to approach that perhaps daunting endeavor.

You reset the associated passwords, and not change the email addresses.


Catastrophic security breaches stink, yes.


And the scammers are undoubtedly quite willing to leverage all of what they’ve collected.


This stuff is a business, and the business automates the collection, processing, and (mis)use of whatever data gets collected, including using existing mail messages a d contact info to phish contacts and family,

The flip side is that for the last 2 months, prior to this breach, I've been inundated with junk email, dozens daily compared to 6 or 8 previously.

Everybody gets spam. Between online collection and resale, and data collected from breaches such as the recent IDscan breach, email addresses always get out.

Changing email addresses theoretically would ameliorate having to constantly peruse tons of junk for any misplaced legitimate mail.

That’s ineffective, at best. Just as soon as you get a new email address, you’ll get spam. I’ve gotten spam on email addresses I’ve created and never used. Shortly after start using it, most any email address will get collected and targeted.


I’m using SpamSieve to filter spam, though there are other options.


If you want to reduce spam from your existing or nee email address, the Apple Hide My Email mechanism might help.

I took the laptop to the Apple Store Monday and they sent files to the Cloud, wiped the machine, then reloaded it with the latest OS 26.7, etc….
They also recommend Malwarebytes as protection … If it can pick up on fraudulent sites/scams, and keep us from another fiasco like this, it could be worth it.

I’m skeptical. I prefer to have fewer or no add-on security apps around (excluding configurations needing endpoint security, and yours doesn’t), as it is less stuff for malcontents to target and potentially exploit, and less that can add issues and corruptions and complexity, and(as has happened with various add-ons to collect and resell information.

I'm having issues at home with our fiber WiFi as even though last week the provider walked me through changing the password, some channels retain the old one. It's complicated by our two extenders, so with Guest channels and 2G and 5G, there can be up to 12 channels involved - some using the new pwd and others the old. I've slowly been trying to sort out what's what, and have all our in-house devices reprogrammed (PITA!) to one 5G basic router channel on the new pwd.

If the guest network is a problem, then get rid of it. Less complexity, less to manage, and with less chances of visitors causing problems or sharing seldom-changed Guest network credentials.


Pending a re-secured and reworked and stable network, the visitors can use their own cellular connections.


And as for Wi-Fi extenders and passwords, those get reset and re-added.


For Wi-Fi, it is 2.4 GHz and 5 GHz, not 2G and 5G. 5G is a cellular network term.

Frustrated, I have them sending a tech tomorrow to help straighten the network out, as sometimes the router/extender's sites will open on the iPad … Even though the router is supplied rent-free, I'm considering going to a TP-link Deco, 3-piece Mesh setup, so the satellite units reflect the same channels/passwords because its all one network.

That would be an advantage of a mesh or access point network, yes.


Here is another similar mesh question: What is the best mesh router for Apple Ho… - Apple Community


[Some text edited to fit into the character limit]

Did Epson techs mess up our MacBook with Malware?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.