Captchaless.top: what it is and how to remove it

Captchaless.top is a fake website created by crooks to generate revenue from pay-per-click advertising. It uses social engineering methods to trick people into clicking the "Allow" button.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Not sure whether the captchaless[.]top command did anything? An automatic scan looks through the places it would hide.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Captchaless.top yourself 4 steps, about 12 minutes, no software needed.

Start the steps
Screenshot of Captchaless.top: captchaless top
Captchaless.top as our 2022 report showed it.

Captchaless.top: summary

DistributionShady websites, deceptive ads, redirects, freeware installations
NAMECaptchaless.top
TYPEPush notification spam; adware
SYMPTOMSPop-up ads start appearing in the corner of the screen after the "Allow" button is pressed
DANGERSLinks embedded in the push notifications can lead to dangerous websites where users can be tricked into providing their personal information and suffer from monetary losses
Detection namesNo Microsoft detection name is known
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
DamageNot recorded in the old report
NameCaptchaless.top
TypeFake CAPTCHA page
SymptomsA fake CAPTCHA asking to press Win+R
Evidence5 write-ups by security sites; details still limited
ImitatesA human-verification check
Domainscaptchaless[.]top
First seen22 August 2022
Facts checked7 October 2026

Is the Captchaless.top check real?

  • Address: captchaless[.]top

From our report of Aug 2022 · not reviewed since

More from our earlier report on Captchaless.top

  • Users can block push notifications via browser settings

What the Captchaless.top scammers want

From our report of Aug 2022 · not reviewed since

Captchaless.top causes pop-up spam when users press on the "Allow" button

Captchaless.top is a fake website created by crooks to generate revenue from pay-per-click advertising.

It uses social engineering methods to trick people into clicking the "Allow" button. Users are made to think that they need to click it to confirm that they are not robots.

In reality, by pressing "Allow" users are added to the push notification subscriber list. People start getting spammed with annoying pop-up ads that can appear even when the browser is closed. The ads can be sent from rogue advertising networks and lead to dangerous pages.

People can end up on scam pages that try to trick them into providing personal information, downloading PUPs (potentially unwanted programs), and even malware. Users report seeing ads promoting adult pages, fake antivirus deals, software offers, surveys, giveaways, etc.

Screenshot of Captchaless.top: captchaless top
Captchaless.top in our 2022 report.

From our report of Aug 2022 · not reviewed since

Freeware installations

Freeware distribution platforms are popular among people who do not want to spend a ton of money on computer programs.

However, often, they include additional programs in the installers to monetize user activity. The bundled software can be malicious, so users should be very careful.

Always choose the "Custom" or "Advanced" installation methods, read the Privacy Policy and Terms of Use. The most important step is to check the file list and untick the boxes next to any unrelated applications. This should help you avoid PUPs.

Why Captchaless.top opens in your browser

From our report of Aug 2022 · not reviewed since

Usually, people encounter pages like Captchaless.top while browsing through other shady sites.

They can rarely be found in the search results. We suggest avoiding websites that are unregulated. For example, illegal streaming sites are full of deceptive ads and sneaky redirects. They may also display fake "Download" and "Play" buttons.

That is why it is best to only visit pages that you know and trust. Do not click on random links and ads even if they seem to be promoting legitimate products, and services. Crooks can use social engineering to make the ads look as believable as possible.

Captchaless.top: captchaless top ads 1
Captchaless.top in our 2022 report.

What to do if you ran the Captchaless.top command

Whether you ran the command decides everything else, so the first step checks that.

  1. Step 1: Check whether the pasted command ran

    Press Windows + R and click the arrow at the right of the box: it lists the last commands typed there.

    A long line starting with powershell, mshta, cmd or curl means the page's command ran, and it usually downloads a password stealer. If it is there, disconnect from the internet now and do every step below, including the passwords.

    If the list holds nothing like it, you only saw the page, and closing it was enough. The Run box keeps this history in Windows 11 and Windows 10 alike.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  2. Step 2: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  3. Step 3: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  4. Step 4: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to Captchaless.top or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

Choose a proper web browser and improve your safety with a VPN tool

Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online.

One of the basic means to add a layer of security - choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features.

However, if you want true anonymity, we suggest you employ a powerful VPN - it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.

Lost your files? Use data recovery software

While some files located on any computer are replaceable or useless, others can be extremely valuable.

Family photos, work documents, school projects - these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur:

  • power cuts
  • Blue Screen of Death errors
  • hardware failures
  • crypto-malware attack
  • even accidental deletion

To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, can be your only hope to retrieve your invaluable files.

From our report of Aug 2022 · not reviewed since

How to block push notifications?

Because push notifications are subscription-based, they can be turned on and off only manually.

We have a detailed guide for the most popular browsers below:

Google Chrome (desktop):

Google Chrome (Android):

MS Edge (Chromium):

  • Open Google Chrome browser and go to Menu > Settings.
  • Locate the Privacy and security section and pick Site Settings > Notifications.
  • Look at the Allow section and look for a suspicious URL.
  • Click the three vertical dots next to it and pick Block. This should remove unwanted notifications from Google Chrome.
  • Open Google Chrome and tap on Settings (three vertical dots).
  • Select Notifications.
  • Locate the unwanted URL and toggle the button to the left (Off setting).
  • Open Mozilla Firefox and go to Menu > Options.
  • Click on Privacy & Security section.
  • Under Permissions, you should be able to see Notifications. Click Settings button next to it.
  • In the Settings – Notification Permissions window, click on the drop-down menu by the URL in question.
  • Select Block and then click on Save Changes. This should remove unwanted notifications from Mozilla Firefox.
  • Click on Safari > Preferences...
  • Go to Websites tab and, under General, select Notifications.
  • Select the web address in question, click the drop-down menu and select Deny.
  • Open Microsoft Edge, and click the Settings and more button (three horizontal dots) at the top-right of the window.
  • Select Settings and then go to Advanced.
  • Under Website permissions, pick Manage permissions and select the URL in question.
  • Toggle the switch to the left to turn notifications off on Microsoft Edge.
  • Open Microsoft Edge, and go to Settings.
  • Select Site permissions.
  • Go to Notifications on the right.
  • Under Allow, you will find the unwanted entry.
  • Click on More actions and select Block.

From our report of Aug 2022 · not reviewed since

Clear your browsers

After an encounter with such a website, it is strongly recommended to clear your browsers.

Websites can use cookies to collect data like your IP address, geolocation, websites you visit, links you click on, and things you purchase online. They can be used to generate revenue by selling them to advertising networks, and other third parties.

This powerful software can stop the tracking and delete the existing information. It can also fix serious system errors with a click of a button, which is especially helpful after a virus infection.

From our report of Aug 2022 · not reviewed since

Check your PC for adware

Unwanted browser behavior can also be caused by adware.

Sometimes pages like Captchaless.top show up without any user input at all. Adware can cause an increased amount of commercial content, like pop-ups, banners, and redirects. Many of them are disguised as "handy" tools so they would be more difficult to identify for average users.

That is why having professional security tools like and is essential. Anti-malware solutions can scan the machine and detect suspicious processes running in the background. Besides, it can prevent such infections by warning users about dangerous files trying to enter the system.

However, if you still want to do this yourself, you can follow our step-by-step instructions for Windows and Mac machines:

To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:

  • Enter Control Panel into Windows search box and hit Enter or click on the search result.
  • Under Programs, select Uninstall a program.
  • From the list, find the entry of the suspicious program.
  • Right-click on the application and select Uninstall.
  • If User Account Control shows up, click Yes.
  • Wait till uninstallation process is complete and click OK.
  • Click on Windows Start > Control Panel located on the right pane (if you are Windows XP user, click on Add/Remove Programs).
  • In Control Panel, select Programs > Uninstall a program.
  • Pick the unwanted application by clicking on it once.
  • At the top, click Uninstall/Change.
  • In the confirmation prompt, pick Yes.
  • Click OK once the removal process is finished.
  • From the menu bar, select Go > Applications.
  • In the Applications folder, look for all related entries.
  • Click on the app and drag it to Trash (or right-click and pick Move to Trash)
  • Select Go > Go to Folder.
  • Enter /Library/Application Support and click Go or press Enter.
  • In the Application Support folder, look for any dubious entries and then delete them.
  • Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.

Questions about Captchaless.top

I pressed Win+R and pasted the code from captchaless[.]top. Am I hacked?

Assume yes and act now. The command a fake CAPTCHA on captchaless[.]top copies to your clipboard downloads and runs malware, usually an information stealer or a remote access trojan, and stealers can copy browser passwords and cookies within a minute. Disconnect the PC from the internet.

Run a Microsoft Defender Offline scan, then remove new startup items, scheduled tasks and programs. From another device, change your e-mail password first, then banking and everything else saved in the browser, sign out of all sessions and turn on two-step verification. If crypto wallets were on the PC, move the funds from a clean device.

Could Windows Security have stopped the captchaless[.]top command?

Sometimes. Microsoft Defender blocks many known ClickFix scripts and payloads, and Protection history in Windows Security will show it if it did. But campaigns change quickly, and a command you ran yourself starts with your permissions, so a new variant can get through before signatures catch up.

Check Protection history for entries from the time you visited captchaless[.]top. Whatever it shows, run an offline scan, look for new startup items and change your important passwords from another device, because stealers act fast and what they took cannot be called back by a later detection.

Is Captchaless.top really from a human-verification check?

No. It is a web page made to look like a message from a human-verification check. Websites cannot scan your computer, see your files or know whether your antivirus is active. Real security warnings appear in Windows Security or in your antivirus program, not as browser pages with phone numbers, countdowns or prize wheels.

Close the page; nothing was installed just by seeing it. If you want to check, open Windows Security from the Start menu and run a quick scan. It shows the real status of your protection.

Is captchaless[.]top safe?

No. The site captchaless[.]top hosts Captchaless.top, a page that imitates a human-verification check to scare or lure visitors. Do not open it again to check; the content can change between visits and may include downloads. If you see it once, close the tab.

If it opens by itself, a notification permission, an extension or a redirecting site is sending you there; the steps in this guide remove each of these. You can report the address to your browser so that others get a warning page before it loads.

Does a human-verification check ever ask me to press Win + R?

Never. Real checks from a human-verification check run entirely inside the page:

  • you tick a box
  • click pictures
  • simply wait a few seconds

They do not use the clipboard, do not open Windows tools and do not ask for keyboard shortcuts. Any page that shows Win + R, Ctrl + V and Enter as steps of a check is Captchaless.top or a page like it. Close it, and if you already followed the steps, disconnect from the internet and use the plan in this guide.

Does Captchaless.top affect other devices at home?

No. A page in a browser lives in that browser on that PC. The pattern reported, A fake CAPTCHA on captchaless[.]top that asks you to paste a command, does not spread across a home network or through the router.

Other devices are only affected if they visit the same kind of site or if you used them to call, pay or install something the page asked for.

If you share a browser profile through sync, check notification settings and extensions on each computer that uses that profile, because a permission granted on one PC can follow you to the others.

I followed the page's instructions. What should I change first?

Your e-mail password, from another device. E-mail can reset every other account, so it comes first. Then banking and payment accounts, then Microsoft, Google and social media accounts, then everything else that was saved in the browser.

In each account, sign out of all sessions and turn on two-step verification. Do this after disconnecting and scanning the PC, not before, and never from the PC itself until the offline scan is clean. Move crypto to a new wallet created on a clean device as well.

How do I avoid pages like Captchaless.top?

Keep the browser updated, do not click Allow on notification prompts from sites you do not know, and leave sites that open many pop-ups. Turn on Microsoft Defender SmartScreen in Edge under Settings > Privacy, search, and services, or Safe Browsing in Chrome under Settings > Privacy and security > Security.

Never call numbers, download files or paste commands because a web page told you to. An ad blocker from your browser's official extension store also cuts most redirect ads. Keep Potentially unwanted app blocking on in Windows Security as well.

Why does Captchaless.top keep coming back?

Most often because a site has permission to send notifications, and those notifications lead to new scam pages. Remove notification permissions for unknown sites. Other causes are an adware extension, a browser that restores the previous session, or a site you visit often that shows such ads.

If the page appears outside the browser, a program on the PC is responsible; check Installed apps. If you cannot find the source, resetting the browser removes all of these causes at once.

Will Fortect remove Captchaless.top?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Captchaless.top, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: Captchaless.top

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year