Google links auto-download a .gif file and then immediately close the browser. Is there a fix?

A

AC Question

The other day I decided to visit A-Z lyrics to check out some lyrics to a Beatles song (which is a rare occurrence) and ended up accidentally clicking an add as I was scrolling the page. It then proceeded to direct me to the Google Play store several times in a row. Every time I'd hit the back button, it would redirect me to another random Google Play app. Super fishy, but I didn't see how this could harm anything without me actually downloading and installing a program from the store. So, I just closed out of my browser and went about my business.

Then, last night, I couldn't sleep and was browsing Facebook for a bit when I noticed something start installing on my task bar at the top and then a pop-up came up and said something along the lines of "system has been updated." The only option the pop-up gave me was "OK" which I did not click. I thought this to be highly suspicious as, in my experience, nothing typically will download/install without providing a prompt beforehand.

I did some searching and couldn't find any information on any system updates for my phone (Galaxy Note 2). I then downloaded Malwarebytes and ran it and it didn't come up with any red flags. So now I'm left wondering what the heck that was all about.

Come this morning, I open up my browser to Google Searched for a nearby zipline park and the link auto-downloaded a .gif and then immediately closed my browser out. I then tried this with a few other Google searches and they all did the same thing when I clicked the link. I immediately deleted the .gif files from my downloads without opening them as I didn't want to risk further infection (if I'm even infected at all?).

I tried searching this problem from my desktop computer and couldn't really find any solid solutions or even any leads. So, I ended up doing a factory reset this morning, but the problem reoccurred again after a clean install. I'm wondering if maybe something got a hold of my system files and gave itself root access. Is that even possible?

I have since encrypted my phone before doing a factory reset and clearing the system cache, and it seems to be a little better now, but every once in a while I will click a Google link and it downloads another .gif file. The issue is 100% repeatable with that Zip Line park link, for whatever reason.

Now I'm paranoid to log into any of my personal accounts on my phone in the event that whatever is happening is some external malicious source that is logging my account info. I have linked one of my Google accounts to the phone and so far I haven't received any notifications about suspicious account activity, but I am very hesitant to do any banking or log into any other accounts.

Is this a known issue? Does anyone know what I can do to remedy this problem short of scraping the phone?

Please keep in mind that I am not super savvy when it comes to Android, so I may not be able to provide you with any technical troubleshooting information.

Thanks in advance for your help!
 

knownaim

New member
Oct 10, 2016
1
0
0
Visit site
Forgot to add: I also tried doing a factory reset without my SD card inserted and the issue was still happening - so I don't believe that anything malicious has been installed on the card.