HTML:Script-inf: what it is and how to remove it

HTML:Script-inf is a malicious script detection from 2021 embedded in websites that performs drive-by-downloads if your system has software vulnerabilities. It can steal credentials through keylogging.

Facts checked October 5, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan of AppData, ProgramData and Temp can find what created C:\Users\.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove HTML:Script-inf yourself 5 steps, about 15 minutes, no software needed.

Start the steps
HTML:Script-inf: html script inf virus malicious script drive by install
HTML:Script-inf as our 2021 report showed it.

HTML:Script-inf: summary

NameHTML:Script-inf
TypeMalware (malicious script)
Infection conditionsDrive-by-download onto compromised machines
Possible symptoms of infectionError messages, computer slowdowns, redirects to suspicious sites, etc.
Affected browsersGoogle Chrome, Internet Explorer, Mozilla Firefox, Safari, etc.
Detection namesNo Microsoft detection name is known
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 7 more facts
DistributionNot recorded in the old report
DamageNot recorded in the old report
SymptomsAn unknown file or folder in AppData, ProgramData or Temp
Evidence4 write-ups by security sites; details still limited
File namesC:\Users\
First seen5 May 2021
Facts checked5 October 2026

What HTML:Script-inf does on an infected PC

What readers reported about HTML:Script-inf

What is this How_to_decrypt_files.html thing?. I switched on the PC today I got enraged that i can't access my files? I only found this and .txtx file on the dekstop. Is this some kind of new virus? It says I have to pay $250 to recover the data. I'd appreciate your advice.

A reader, 2016

Do you really think PC Fix Speed is malware?. Hi, would you be so kind please and remove your article about PC Fix speed ( where you claim that it is a malware. You know that it is not truth, and you are doing negative name of our product. thank you

A reader, 2013

From the comments under our earlier guide; names and contact details removed.

From our report of May 2021 · not reviewed since

HTML:Script-inf is a script that is hosted on the malicious sites to propagate malware

HTML:Script-inf is a generic detection used by multiple AV engines to describe a malicious script that is embedded into websites.

Virus authors might hack these sites or specially craft them for malicious purposes. Thus, under certain conditions, if users visit such a compromised domain, they might unintentionally and without any warning install malware on their device.

Virus can be related to a variety of activities, including data theft, keylogging, data-locking, etc. - its capabilities depend on what type of malware hackers host. Generally, such detection by anti-virus software does not mean that the visitor is infected; however, those who do not employ security measures might get infected with a nasty cyberthreat.

In some cases, the detection name might also represent a false positive - so that is something that should be investigated before files are quarantined or deleted from the computer. Additionally, some users claimed that their antivirus software does not stop showing popups on a regular basis without them visiting any websites.

This behavior is typically web browser exclusive (for example, it only occurs when Google Chrome is used), which indicates that browser settings have been compromised and need to be reset.

HTML:Script-inf is basically a part of a drive-by-download or drive-by-install technique used by cybercriminals to install malware on users machines. For this scheme to work, certain conditions must be met, including:

Once those two conditions are met, a virus is downloaded and populated on the user's computer. The only way to remove malware is by using sophisticated anti-virus scanners. Note that some infections, like adware or browser hijackers, can be terminated without security software. However, drive-by-download technique is used to install much more severe threats on devices.

Some users complained that their antivirus is constantly blocking a variety of websites and showing the popup upon entry. This means that the infection is already present on the device, and malware managed to save malicious files on the host machine. In such a case removal should be performed as soon as possible.

Generally, those who employ reputable security software can avoid any threats related to HTML:Script-inf virus. Therefore, you need to make sure that your machine is protected from malicious scripts, as they can be embedded into legitimate sites by cybercriminals (one of such compromised sites was cruisecritic.com).

If your device has been compromised, you need to detect and eliminate malware. After that, experts recommend using software that can fix virus damage, such as .

  • The host machine should hold a piece of software that has an embedded vulnerability;
  • The user should visit the compromised website for the script to download malicious payload.
HTML:Script-inf: html script inf virus malicious script drive by install
HTML:Script-inf in our 2021 report.
HTML:Script-inf: html script inf malware script malicious website
HTML:Script-inf in our 2021 report.

From our report of May 2021 · not reviewed since

Precautionary measures to avoid malware on the internet

Malware usually does not emit any infection symptoms, as hackers want to make sure that the malicious payload can stay on the device as long as possible and execute what it's been programmed to do. For example, a compromised device might record every keystroke performed by the victim, recording such data as emails, banking details, passwords, etc. Without a doubt, such activity is extremely dangerous for the user.

Due to malware's stealthy behavior, the threat might be present on the machine for weeks or even months before it is detected. Thus, it is best to avoid cyber infections altogether, and make sure the precautionary measures are used:

  • Employ reliable security software that can block malicious scripts on websites and protect you from most already-known viruses;
  • Update your system and software with security patches as soon as they become available;
  • Do not download and install applications that might compromise your browser and lead to malicious sites;
  • When installing freeware or shareware, make sure you pick Advanced/Custom installation settings to avoid adware and other PUPs;
  • Use ad-block for all sites (but don't forget to make exclusions for domains you want to support);
  • If you are downloading high-risk files (executables, obfuscated files, etc.), make sure you scan them with tools like Virus Total before opening.

From our report of May 2021 · not reviewed since

Terminate malware with the help of reputable security software

To remove a virus, you will have to use professional security software.

There are plenty on the market available, but be aware that detection rate might vary from tool to tool, depending on what type of malware was injected into your device. Thus, a scan of several AV engines might be needed until the threat is detected and eliminated.

In some cases, the virus might interfere with security software and prevent it from working correctly. In such a case, you should enter Safe Mode with Networking and perform a full scan from there.

If the detection is recurring, you might have to take additional steps to perform a full HTML:Script-inf removal. Here's what you should try:

  • Update your operating system, security application, and the web browser affected;
  • Reset your browser;
  • Delete contents in C:\Users\ \AppData\Local\Google;
  • Reset Google Chrome Sync;
HTML:Script-inf: html script inf malware detection name avg
HTML:Script-inf in our 2021 report.

From our report of May 2021 · not reviewed since

More from our earlier report on HTML:Script-inf

  • To fully recover from the infection, use

How to check the PC for HTML:Script-inf

  • Path: C:\Users\

How to remove HTML:Script-inf

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to HTML:Script-inf or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever HTML:Script-inf installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Uninstall from Windows

There might be some potentially unwanted programs on Windows that could implement browser changes without your permission. Uninstall everything you find suspicious:

Uninstall from Windows 10/8:

  1. Type Control Panel into the Windows search box and open the result.
  2. Under Programs, select Uninstall a program.Uninstall from Windows 10/8

Uninstall from Windows 7/XP:

  1. Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
  2. In Control Panel, select Programs > Uninstall a program.Uninstall from Windows 7/XP

Remove the unwanted program:

  1. In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
  2. If User Account Control appears, click Yes to confirm, then complete the removal.Uninstall the unwanted program from Windows
Remove from Google Chrome

The issue is prevalent on Google Chrome browsers, so you should take your time in order to clean it properly:

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2
Remove from Microsoft Edge

To reset MS Edge or clean it otherwise, proceed with the following:

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge
Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge
Remove from Mozilla Firefox (FF)

You should uninstall Firefox extensions you don't remember installing:

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2
Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari
Delete from macOS

Remove the unwanted application:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).Uninstall from Mac

Delete leftover files and folders:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
  3. Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.Delete leftover files from Mac
  4. Finally, empty the Trash to permanently remove the leftovers.

After removal: passwords, accounts and prevention

Your passwords after HTML:Script-inf

Removing HTML:Script-inf does not undo what it may already have sent out while the PC showed an unknown item at C:\Users\.

Treat saved browser passwords and logged-in sessions on this PC as known to the attacker.

From another device, change the e-mail password first and end all its sessions. Then do the same for the bank, PayPal, Microsoft, Google and Apple accounts. Stolen session cookies keep working after a password change until you sign out everywhere.

Move crypto to a new wallet created on a clean device. A step-by-step order for every kind of account is in our guide to account security after an infection.

Access your website securely from any location

When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.

If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.

Recover files after data-affecting malware attacks

While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.

More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.

Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.

Questions about HTML:Script-inf

What is HTML:Script-inf?

HTML:Script-inf is a generic detection used by multiple antivirus engines to describe a malicious script that is embedded into websites. According to the 2021 guide, it is a script hosted on malicious sites to propagate malware. Virus authors might hack legitimate sites or specially craft malicious sites for this purpose.

HTML:Script-inf is basically part of a drive-by-download or drive-by-install technique used by cybercriminals to install malware on users' machines. Once certain conditions are met, including vulnerable software on the host machine and visiting a compromised website, the script downloads and deploys a malicious payload to the user's computer.

Is HTML:Script-inf a virus?

HTML:Script-inf is technically a malicious script detection rather than a traditional virus. According to the 2021 guide, generally such detection by antivirus software does not mean the visitor is infected. However, those who do not employ security measures might get infected with a nasty cyberthreat.

In some cases, the detection name might represent a false positive that should be investigated before files are quarantined or deleted. The 2021 guide noted that antivirus software constantly blocks websites and shows popups upon entry in some infections, which means malware managed to save malicious files on the host machine rather than just encountering the script once.

How do I get infected with HTML:Script-inf?

According to the 2021 guide, for a drive-by-download infection to work, two conditions must be met. First, the host machine must hold software with an embedded vulnerability.

Second, the user must visit a compromised website where the script downloads malicious payload. Virus authors hack legitimate sites or create specially crafted malicious sites for this purpose. One example cited by the 2021 guide was the compromised site cruisecritic.com.

When users visit such compromised domains, they unintentionally and without any warning download malware. The 2021 guide noted that the infection requires both a vulnerable host and visit to a compromised site to execute the attack.

What does HTML:Script-inf do on my computer?

According to the 2021 guide, HTML:Script-inf can be related to a variety of malicious activities depending on what type of malware is hosted by the script. Capabilities include data theft, keylogging, and data-locking. The malware might record every keystroke performed by the victim, capturing data such as emails, banking details, and passwords.

Browser-related infections may cause error messages, computer slowdowns, redirects to suspicious sites, and persistent popups in web browsers. The 2021 guide noted that if antivirus constantly shows popups without user intervention, malware has saved malicious files on the machine and browser settings have been compromised and need reset.

Is HTML:Script-inf dangerous?

Yes, HTML:Script-inf is dangerous. According to the 2021 guide, malware's stealthy behavior means the threat might be present on the machine for weeks or even months before detection. Without a doubt, keystroke recording and data theft activities are extremely dangerous for the user.

The 2021 guide emphasized that malware usually does not emit any infection symptoms, as hackers want to ensure the malicious payload stays on the device as long as possible to execute what it's programmed to do.

Drive-by-download techniques are used to install much more severe threats on devices than simple adware or browser hijackers. Therefore, you need to make sure your machine is protected from malicious scripts, as they can be embedded into legitimate sites by cybercriminals.

Can HTML:Script-inf steal my personal information?

Yes, absolutely. According to the 2021 guide, malware delivered through HTML:Script-inf can record every keystroke performed by victims, capturing data such as emails, banking details, passwords, and other sensitive information. Data theft is one of the primary capabilities listed for this malware.

The 2021 guide specifically warned that a compromised device might record such data without any warning or user knowledge. Due to malware's stealthy behavior, such malicious activity might occur on your machine for weeks or months before discovery. The threat might also enable keylogging, allowing cybercriminals to capture all your typing including passwords and financial information.

How do I remove HTML:Script-inf from my computer?

According to the 2021 guide, the only way to remove this malware is by using sophisticated antivirus or anti-malware scanners. However, in some cases, the virus might interfere with security software and prevent it from working correctly.

In such cases, enter Safe Mode with Networking and perform a full scan from there. A scan of several antivirus engines might be needed until the threat is detected and eliminated. After removal, experts recommend using software that can fix virus damage.

If the detection recurs, you should try updating your operating system, security application, and affected web browser, and delete contents in C:\Users\[username]\AppData\Local\Google. The 2021 guide emphasized the importance of using reputable security software for complete removal.

How can I prevent HTML:Script-inf infection?

According to the 2021 guide, employ reliable security software that blocks malicious scripts on websites and protects against known viruses. Update your system and software with security patches as soon as they become available, as vulnerabilities are required for the attack.

Do not download and install applications that might compromise your browser. When installing freeware or shareware, choose Advanced or Custom installation settings to avoid adware and PUPs. Use ad-block for all sites to prevent script injection.

If downloading high-risk files (executables, obfuscated files), scan them with tools like Virus Total before opening. Those who employ reputable security software can avoid most threats related to HTML:Script-inf virus.

Will Fortect remove HTML:Script-inf?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For HTML:Script-inf, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Questions and experiences: HTML:Script-inf

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year