Greatcaptchahere.top: what it is and how to remove it
Greatcaptchahere.top is a fraudulent website that uses social engineering techniques to trick people into subscribing to push notifications. Crooks try to persuade people that they must click the "Allow" button in order to gain access to the website.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Not sure whether the greatcaptchahere[.]top command did anything? An automatic scan looks through the places it would hide.
Do it yourself · free Remove Greatcaptchahere.top yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Greatcaptchahere.top: summary
| Distribution | Shady websites; deceptive ads; freeware installations |
|---|---|
| NAME | Greatcaptchahere.top |
| TYPE | Push notification spam; adware |
| SYMPTOMS | Pop-up ads, and banners start appearing on the screen even when the browser is closed |
| DANGERS | Deceptive advertisements can lead to dangerous websites where users are at risk of giving away their personal information and suffering from monetary losses or downloading malicious software |
| Detection names | No Microsoft detection name is known |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Damage | Not recorded in the old report |
|---|---|
| Name | Greatcaptchahere.top |
| Type | Fake CAPTCHA page |
| Symptoms | A fake CAPTCHA asking to press Win+R |
| Evidence | 5 write-ups by security sites; details still limited |
| Imitates | A human-verification check |
| Domains | greatcaptchahere[.]top |
| First seen | 14 March 2023 |
| Facts checked | 7 October 2026 |
Is the Greatcaptchahere.top check real?
- Address:
greatcaptchahere[.]top
From our report of Mar 2023 · not reviewed since
More from our earlier report on Greatcaptchahere.top
- Remove website permissions via browser settings or deploy professional security software to detect adware
- Use for remediation and fix any damage left
What the Greatcaptchahere.top scammers want
From our report of Mar 2023 · not reviewed since
Greatcaptchahere.top tries to trick users into accepting pop-up spam
Greatcaptchahere.top is a fraudulent website that uses social engineering techniques to trick people into subscribing to push notifications.
Crooks try to persuade people that they must click the "Allow" button in order to gain access to the website. Instead, they begin to receive annoying pop-up advertisements.
Unless a page is marked as malicious, your browser should never block access to it. Be wary of fake captcha verification pages or any sites that ask you to click "Allow" on a browser prompt that grants permission to send show push notifications.
Furthermore, fraudsters may use rogue advertising networks to place ads that lead to dangerous websites. People may unknowingly end up on scam pages that attempt to obtain personal information or push them to download PUPs (potentially unwanted programs) and malware.

From our report of Mar 2023 · not reviewed since
Stop the pop-ups
Greatcaptchahere.top starts showing ads promoting bogus browser extensions, security tools, etc. Push notifications work on a subscription-based model, so you will have to block them yourself.
You can do this easily by following our step-by-step instructions:
Google Chrome (desktop):
Google Chrome (Android):
MS Edge (Chromium):
- Open Google Chrome browser and go to Menu > Settings.
- Locate the Privacy and security section and pick Site Settings > Notifications.
- Look at the Allow section and look for a suspicious URL.
- Click the three vertical dots next to it and pick Block. This should remove unwanted notifications from Google Chrome.
- Open Google Chrome and tap on Settings (three vertical dots).
- Select Notifications.
- Locate the unwanted URL and toggle the button to the left (Off setting).
- Open Mozilla Firefox and go to Menu > Options.
- Click on Privacy & Security section.
- Under Permissions, you should be able to see Notifications. Click Settings button next to it.
- In the Settings – Notification Permissions window, click on the drop-down menu by the URL in question.
- Select Block and then click on Save Changes. This should remove unwanted notifications from Mozilla Firefox.
- Click on Safari > Preferences...
- Go to Websites tab and, under General, select Notifications.
- Select the web address in question, click the drop-down menu and select Deny.
- Open Microsoft Edge, and click the Settings and more button (three horizontal dots) at the top-right of the window.
- Select Settings and then go to Advanced.
- Under Website permissions, pick Manage permissions and select the URL in question.
- Toggle the switch to the left to turn notifications off on Microsoft Edge.
- Open Microsoft Edge, and go to Settings.
- Select Site permissions.
- Go to Notifications on the right.
- Under Allow, you will find the unwanted entry.
- Click on More actions and select Block.
From our report of Mar 2023 · not reviewed since
Clear your browsers
Cookies are small text files that can track your browsing activity and store information such as your IP address, geolocation, websites visited, links clicked on, and items purchased.
This information is normally used to personalize the user experience, but crooks use it to make money. They are valuable to ad networks and other third parties.
They can even be hijacked and used for malicious purposes, which is why security experts advise that they be cleared on a regular basis. A maintenance tool like can make this process much easier. Furthermore, this powerful software can repair a variety of system errors, corrupted files, and registry issues, which is especially useful following a virus infection.
From our report of Mar 2023 · not reviewed since
Check your system for adware infection
If blocking site permissions in your browser settings did not work, you may have a potentially unwanted program on your system that is generating ads in the background without your permission. Adware is a type of program that infiltrates the system through freeware distribution platforms.
Security software can also help you avoid future infections by alerting you to suspicious programs. If you want to give it a shot, here are the instructions for Windows and macOS:
Windows 10/8 machines:
To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:
- Enter Control Panel into Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- From the list, find the entry of the suspicious program.
- Right-click on the application and select Uninstall.
- If User Account Control shows up, click Yes.
- Wait till uninstallation process is complete and click OK.
- Click on Windows Start > Control Panel located on the right pane (if you are Windows XP user, click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.
- Pick the unwanted application by clicking on it once.
- At the top, click Uninstall/Change.
- In the confirmation prompt, pick Yes.
- Click OK once the removal process is finished.
- From the menu bar, select Go > Applications.
- In the Applications folder, look for all related entries.
- Click on the app and drag it to Trash (or right-click and pick Move to Trash)
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any dubious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.
Why Greatcaptchahere.top opens in your browser
From our report of Mar 2023 · not reviewed since
Greatcaptchahere.top and other push notification spam sites are rarely found in search results.
Most of the time, they hide in other shady, unregulated locations. Pages that engage in illegal activities are riddled with deceptive ads and sneaky redirects that can lead to fraudulent websites.
Use legitimate streaming services, such as Netflix or Hulu, instead of illegal streaming sites, which frequently display bogus "Download" and "Play" buttons that redirect users to deceptive pages.
Do not click on random links and advertisements. Even if the advertisement appears to promote legitimate and well-known products, it is best to go directly to the source.
Another possibility is that the page appeared without any input from the user. This can happen if you have adware on your computer. It may result in an increase in commercial content such as pop-ups, banners, and redirects.

What to do if you ran the Greatcaptchahere.top command
Whether you ran the command decides everything else, so the first step checks that.
Step 1: Check whether the pasted command ran
Press Windows + R and click the arrow at the right of the box: it lists the last commands typed there.
A long line starting with
powershell,mshta, cmd or curl means the page's command ran, and it usually downloads a password stealer. If it is there, disconnect from the internet now and do every step below, including the passwords.If the list holds nothing like it, you only saw the page, and closing it was enough. The Run box keeps this history in Windows 11 and Windows 10 alike.
Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 2: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 3: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 4: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to Greatcaptchahere.top or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Access your website securely from any location
When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.
If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.
Recover files after data-affecting malware attacks
While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.
More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.
Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.
Questions about Greatcaptchahere.top
What did the greatcaptchahere[.]top verification command do?
In ClickFix campaigns the pasted line starts a hidden PowerShell, mshta or curl process that fetches a script from a remote server and runs it. That script installs the real payload, most often an information stealer, sometimes a remote access tool or a loader that brings more malware later.
The exact payload of greatcaptchahere[.]top can change from day to day, which is why the safe response does not depend on knowing it: scan offline, remove what was added and change passwords from another device. Look in the Run box history with Win+R to confirm the command was executed.
Was greatcaptchahere[.]top hacked, or is it a scam site?
Both happen. Many ClickFix pages are injected into legitimate websites whose software was not updated, so a site you know can suddenly show a fake check. Others sit on throwaway domains reached through ads or links in messages.
For you the answer is the same: do not follow the instructions on greatcaptchahere[.]top, and if you already did, clean the PC and change passwords. If the site belongs to a business you trust, let them know through a contact form; they may not realise their pages have been tampered with.
Is Greatcaptchahere.top really from a human-verification check?
No. It is a web page made to look like a message from a human-verification check. Websites cannot scan your computer, see your files or know whether your antivirus is active. Real security warnings appear in Windows Security or in your antivirus program, not as browser pages with phone numbers, countdowns or prize wheels.
Close the page; nothing was installed just by seeing it. If you want to check, open Windows Security from the Start menu and run a quick scan. It shows the real status of your protection.
Is greatcaptchahere[.]top safe?
No. The site greatcaptchahere[.]top hosts Greatcaptchahere.top, a page that imitates a human-verification check to scare or lure visitors. Do not open it again to check; the content can change between visits and may include downloads. If you see it once, close the tab.
If it opens by itself, a notification permission, an extension or a redirecting site is sending you there; the steps in this guide remove each of these. You can report the address to your browser so that others get a warning page before it loads.
Does a human-verification check ever ask me to press Win + R?
Never. Real checks from a human-verification check run entirely inside the page:
- you tick a box
- click pictures
- simply wait a few seconds
They do not use the clipboard, do not open Windows tools and do not ask for keyboard shortcuts. Any page that shows Win + R, Ctrl + V and Enter as steps of a check is Greatcaptchahere.top or a page like it. Close it, and if you already followed the steps, disconnect from the internet and use the plan in this guide.
I followed the page's instructions. What should I change first?
Your e-mail password, from another device. E-mail can reset every other account, so it comes first. Then banking and payment accounts, then Microsoft, Google and social media accounts, then everything else that was saved in the browser.
In each account, sign out of all sessions and turn on two-step verification. Do this after disconnecting and scanning the PC, not before, and never from the PC itself until the offline scan is clean. Move crypto to a new wallet created on a clean device as well.
Is it safe to force-close the browser?
Yes. Ending the browser in Task Manager or restarting the PC does not damage Windows or your files, despite what pages like Greatcaptchahere.top say. The warning "do not close this window" is part of the scam.
At worst you lose unsaved text in other tabs. After restarting, do not let the browser restore the previous session, because that would reopen the scam page.
If it reopens anyway, open the browser's settings for startup pages and remove the address. Then remove its notification permission if it has one.
How do I avoid pages like Greatcaptchahere.top?
Keep the browser updated, do not click Allow on notification prompts from sites you do not know, and leave sites that open many pop-ups. Turn on Microsoft Defender SmartScreen in Edge under Settings > Privacy, search, and services, or Safe Browsing in Chrome under Settings > Privacy and security > Security.
Never call numbers, download files or paste commands because a web page told you to. An ad blocker from your browser's official extension store also cuts most redirect ads. Keep Potentially unwanted app blocking on in Windows Security as well.
Why do I keep seeing Greatcaptchahere.top?
Because something keeps sending your browser to it. The usual causes are a site allowed to show notifications, an extension that injects pages, or ads on sites you visit often. The sign reported, A fake CAPTCHA on greatcaptchahere[.]top that asks you to paste a command, appears whenever one of these triggers fires.
Remove unknown sites from the browser's notification list, delete extensions you did not install on purpose, and see whether the page returns. If it only appears on one particular site, that site's ads are the source and avoiding it or using the browser's built-in protection settings is the fix.
Will Fortect remove Greatcaptchahere.top?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Greatcaptchahere.top, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Webroot: What is Social Engineering? (read October 7, 2026)
- Wikipedia, the free encyclopedia: CAPTCHA (read October 7, 2026)
- Makeuseof: Why Should You Avoid Illegal Streaming Sites? (read October 7, 2026)
- FTC: How to spot, avoid and report tech support scams (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)