Fake CAPTCHA and ClickFix pages: why you must never paste commands into Windows

•Fake alerts•Ugnius Kiguolis

A ClickFix page is a fake CAPTCHA, error or "fix" that tells you to press Win + R or Win + X, paste something and press Enter; what you paste is a command that downloads malware, usually a password stealer or a remote access tool. No real CAPTCHA, website or update ever works that way, and if you already ran the command, disconnect from the internet and treat your saved passwords as stolen.

What a ClickFix or fake CAPTCHA page is

ClickFix is the name security researchers gave to a social engineering trick that spread widely from 2024 onwards. A web page shows something familiar, such as an "I'm not a robot" box, a Cloudflare-style "Verify you are human" check, a browser error, a broken document or a meeting app that "cannot access your microphone", and then gives you a short set of keyboard steps to fix it.

The steps always end the same way: open a Windows box that runs commands, paste, press Enter. The page never asks you to download anything, which is the point. There is no file for the browser to warn about and no download prompt to click through. You run the attacker's command yourself, with your own permissions.

Microsoft Threat Intelligence described in 2025 how ClickFix campaigns reach thousands of devices every day and deliver information stealers, remote access tools and loaders. The Center for Internet Security described it as a technique that became prevalent in 2025 and now targets several operating systems. The lure changes often; the keyboard steps do not.

Guides to individual fake alert pages are grouped under Fake alerts on this site.

How the trick works, step by step

  1. You land on the page through a hacked website (often a small business or blog site whose code was injected), a malicious ad, a search result, a phishing e-mail with an HTML attachment or link, or a fake job interview or meeting invitation.
  2. The page shows a check box or an error. When you click it, a script on the page silently copies a command to your clipboard. You do not see it happen.
  3. New instructions appear: press Win + R, then Ctrl + V, then Enter. Some versions ask you to press Win + X and choose Terminal, or to paste into the File Explorer address bar.
  4. The Run box or Terminal executes the pasted text. The visible part may look harmless ("I am not a robot - reCAPTCHA Verification ID: 4721"), because everything before it is pushed out of view or hidden after a comment sign.
  5. The command uses a built-in Windows program such as powershell, mshta, cmd, curl, rundll32 or msiexec to download the next stage and run it, often directly in memory.
  6. The page may then say "Verification complete" so that nothing seems wrong.

Because built-in Windows tools do the downloading, ClickFix is sometimes called "fileless" or living-off-the-land malware. The final payload is usually an ordinary program, but it arrives without the warnings a browser download would show.

Why Win + R and Win + X

Win + R opens the Run box, which runs whatever you type with your account's permissions. Win + X opens the Start button's quick menu, where Terminal (or Windows PowerShell on Windows 10) gives a full command line. Both are normal Windows tools; the danger is only in what is pasted into them.

Variants named FileFix and TerminalFix use the same idea with the File Explorer address bar or a Terminal window. If a page tells you to paste anything anywhere in Windows, it is the same scam.

How to recognise a fake CAPTCHA

A real CAPTCHA is solved inside the web page: you tick a box, pick pictures or wait a few seconds. It never asks you to use the keyboard outside the browser. That one fact is enough to spot every ClickFix page.

  • Instructions that mention Win, Windows key, Run, Terminal, PowerShell or Command Prompt on a website.
  • Keyboard steps written as a numbered list with key pictures, such as "1. Press Win + R 2. Press Ctrl + V 3. Press Enter".
  • A "Copy" or "Fix it" button followed by pasting instructions.
  • A verification check that appears on a site that never had one before, especially a small site, a recipe blog or a page found through a search ad.
  • An error from a video call, a document viewer or a browser that claims to be fixed by running a command.
  • Pressure: the page will not let you continue, or says your account or document will be lost.

Mac versions of the same scam ask you to paste into Terminal; this guide covers Windows only, but the rule is the same everywhere.

What the command installs and what it can do

The command itself is only a downloader. What it fetches depends on the campaign, and Microsoft, Proofpoint and CIS have all documented the same families of payloads:

  • Information stealers, which copy saved browser passwords, cookies (which can let attackers into accounts without a password), autofill data, crypto wallets and files within minutes. See information stealers.
  • Remote access trojans and abused remote support tools, which let the attacker control the PC, watch the screen and come back later. See remote access trojans.
  • Loaders, which install further malware on demand, sometimes leading to ransomware on business networks. See trojans and loaders.
  • Occasionally miners or rootkit components that hide the rest.

The theft usually happens in the first minutes, before you have finished reading the page. That is why the response below starts with your accounts, not only with the PC.

A ClickFix page cannot do anything until you run the command. Seeing it, clicking the check box and even copying the text to the clipboard installs nothing. If you closed the page without pasting, there is nothing to clean.

If you pasted and ran the command

Act in this order. The PC can be cleaned later; stolen sessions are used straight away.

  1. Disconnect from the internet now: unplug the network cable or turn off Wi-Fi with Win + A. This stops further downloads and data upload.
  2. From another device (a phone or a clean computer), change the password of your main e-mail account, then banking, PayPal, Microsoft, Google, Apple, Amazon, social media and any crypto exchange. Use Sign out of all devices or end active sessions on each, because stolen cookies keep working until the session ends. The full order: securing your accounts after malware.
  3. Move crypto from any wallet that was on the PC to a new wallet created on a clean device. A copied seed phrase cannot be changed.
  4. Call your bank if card details were saved in the browser, and ask for a new card.
  5. Scan the PC with a full scan and then an offline scan, which runs before Windows starts: Run a Microsoft Defender Offline scan.
  6. Look for what the command left behind: new entries in Task Manager > Startup apps, new tasks in Task Scheduler that start powershell, mshta, wscript or a file in %AppData%, and programs in Settings > Apps > Installed apps that you did not install, especially remote support tools. Turning a startup entry off is shown here: Stop apps from opening at startup On uGetFix.
  7. Turn on two-step verification with an authenticator app or a passkey on every important account: Turn on two-step verification / secure a hacked account.

If scans keep finding new items, a remote access tool was installed or security settings were switched off, resetting Windows is the safer choice. How to decide: clean up or reset Windows after malware.

Do not run it again to see what it does

The command may still be in the Run box history: press Win + R and the last entry appears in the box. Do not press Enter. If you want to report the page, take a photo of the text or copy it into Notepad without running it. Windows keeps the Run history in the RunMRU registry key, which is also where investigators look for ClickFix commands.

If it happened on a work or school computer

Tell your IT or security team straight away and say exactly what you did: which site, what the page said, and that you pasted and ran a command. ClickFix is a common first step in attacks on companies, and the team can check other devices and accounts that you cannot.

Do not try to clean the PC yourself first, and do not delete the browser history: it helps the investigation. Change your work password only when the IT team asks you to, from a device they approve.

Organisations can block the trick technically. Microsoft's guidance includes turning off the Run box through Group Policy for users who do not need it, restricting PowerShell for standard users, enabling PowerShell script block logging and attack surface reduction rules, and keeping SmartScreen and cloud-delivered protection on.

How to protect yourself and your family

  • Learn one rule: a website never needs you to open Run, Terminal, PowerShell or Command Prompt. Share the rule with anyone who uses your PC.
  • Use a standard user account for everyday browsing. Commands still run, but they cannot change system-wide settings without an administrator password.
  • Keep Microsoft Defender on, with Cloud-delivered protection and Tamper Protection enabled in Windows Security > Virus & threat protection > Manage settings. Defender blocks many known ClickFix commands and payloads.
  • Leave SmartScreen and Safe Browsing on in Edge and Chrome so known malicious pages are blocked.
  • Do not save important passwords in the browser on a PC that other people use, and prefer passkeys and two-step verification so that a stolen password alone is not enough.
  • Be suspicious of verification checks on unfamiliar sites, especially ones you reached through an ad or a pirated streaming site. Close the tab instead.
  • Keep a backup of your files: the 3-2-1 backup rule.

Common myths about fake CAPTCHA pages

  • "I only clicked the check box, so I am infected." Clicking copies text to the clipboard; nothing runs until you paste it into Run or Terminal and press Enter.
  • "The command looked harmless." The visible part is designed to look harmless. The real command sits before it, out of view.
  • "My antivirus did not warn me, so it was fine." Commands run through built-in Windows tools and change constantly. Defender catches many, not all. Assume the worst until a scan and your account checks are done.
  • "It was a real site I use, so the check was real." Hacked legitimate sites are the main source of ClickFix pages. The site's owner usually does not know.
  • "Restarting the PC removes it." Payloads usually add a startup entry or scheduled task, and stolen passwords are already gone. A restart fixes neither.

Frequently asked questions

I pressed Win + R and pasted a command from a website. What should I do now?

Disconnect from the internet straight away. Then, from a phone or another computer, change the password of your main e-mail account, your bank and other important accounts, and sign out of all sessions on each, because the command most likely installed a password stealer that also copies login cookies. Move any crypto to a new wallet created on a clean device. After that, run a full scan and a Microsoft Defender offline scan on the PC, and check Startup apps, Task Scheduler and Installed apps for anything new. Turn on two-step verification. If scans keep finding things or a remote access tool appears, reset Windows.

Is a CAPTCHA that asks me to press Windows + R real?

No. Every CAPTCHA that tells you to press the Windows key, open Run, open Terminal or paste something is fake. Real CAPTCHA services, including Google reCAPTCHA and Cloudflare's checks, work entirely inside the web page: you tick a box, choose pictures or wait a moment. They have no way to need a command on your computer. Close the tab. If the page appeared on a site you trust, the site has probably been hacked; you can tell its owner, and report the address to Microsoft or Google so that browsers start blocking it.

I only clicked the "I'm not a robot" box. Am I infected?

No, not from the click alone. Clicking the box on a ClickFix page copies a command to your clipboard, which is why the next step asks you to paste. Until you paste it into Run, Terminal or the File Explorer address bar and press Enter, nothing has run. Close the page. To be safe, copy some ordinary text so the command is no longer in the clipboard, and do not paste anywhere. If you are not sure whether you pressed Enter, press Win + R and look: if the command is shown as the last entry, assume it ran and follow the steps for a command that was run.

What does a ClickFix command install?

Most often an information stealer, which copies saved passwords, browser cookies, autofill data, crypto wallets and some files, and sends them to the attacker within minutes. Other campaigns install remote access trojans or misused remote support tools that let the attacker control the PC, or loaders that fetch more malware later. Microsoft, Proofpoint and CIS have documented families such as Lumma Stealer, AsyncRAT, XWorm, NetSupport and DarkGate in ClickFix attacks. The exact payload changes often, so treat any run command as a stealer infection: protect your accounts first, then clean the PC.

Will Microsoft Defender protect me from ClickFix?

It helps a lot but cannot be the only defence. Defender, with cloud-delivered protection on, blocks many known ClickFix commands, scripts and payloads, and SmartScreen in Edge blocks known malicious pages. Attackers change commands and hosting daily, so new variants can slip through for a while. Run a full scan and an offline scan if you ran a command, and check your accounts regardless of the result, because a stealer may have finished its work before it was detected. The only complete protection is the habit of never pasting commands from a website.

Why does the fake CAPTCHA keep appearing on a site I visit?

Because the site itself has been hacked. Attackers inject a script into legitimate websites, often ones running an outdated content management system or plugin, and the script shows the fake check to some visitors. Your PC is not the cause if you see it only on that site. Stop visiting the site for now and tell the owner if you can. If fake checks or similar pop-ups appear on many different sites, look for an adware extension or notification permissions in your browser instead: Remove a browser extension and Stop website notifications and pop-ups.

About the author

Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year