Headcaptcha.live: what it is and how to remove it
Headcaptcha.live is a suspicious website that wasn't created for legitimate purposes and is largely operated by scammers. The main goal of crooks is to make people subscribe to push notifications, which would immediately give them permission to send any kind of information via the browser API, which largely consists of various insecure advertisements, including fake virus alerts, fake giveaways, get-rich-quick scams, and other phishing material.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
After a fake CAPTCHA on headcaptcha[.]live, a scan of the PC is a quick first check before you change passwords.
Do it yourself · free Remove Headcaptcha.live yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Headcaptcha.live: summary
| Distribution | Users typically arrive at the site after being redirected from another high-risk place. The activity is only possible when the "Allow" button is clicked within the notification prompt |
|---|---|
| Damage | Various security problems due to exposure to scams, monetary losses, system infections, etc. |
| Name | Headcaptcha.live |
| Type | Push notifications, ads, scam |
| Detection names | No Microsoft detection name is known |
| Symptoms | A fake CAPTCHA asking to press Win+R |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 5 more facts
| Evidence | 4 write-ups by security sites; details still limited |
|---|---|
| Imitates | A human-verification check |
| Domains | headcaptcha[.]live |
| First seen | 12 October 2022 |
| Facts checked | 7 October 2026 |
Is the Headcaptcha.live check real?
- Address:
headcaptcha[.]live
From our report of Oct 2022 · not reviewed since
More from our earlier report on Headcaptcha.live
- You need to access your browser's settings section to block intrusive pop-ups.
- Also, perform a scan with anti-virus to check for infections
- You should remove caches and other web data after the elimination of adware to prevent data tracking with the repair and maintenance tool.
- You can also repair damaged system components with it
What the Headcaptcha.live scammers want
From our report of Oct 2022 · not reviewed since
Headcaptcha.live shows you intrusive ads after convincing you to allow notifications
Headcaptcha.live is a suspicious website that wasn't created for legitimate purposes and is largely operated by scammers.
The main goal of crooks is to make people subscribe to push notifications, which would immediately give them permission to send any kind of information via the browser API, which largely consists of various insecure advertisements, including fake virus alerts, fake giveaways, get-rich-quick scams, and other phishing material.
While the activity is not caused by any computer infection directly, Headcaptcha.live redirects and similar websites, or an increased number of ads you encounter while browsing the internet daily, might be a sign of adware infection.


From our report of Oct 2022 · not reviewed since
How the scam operates
Users typically are presented with a scam message unexpectedly, which only adds to the success of the Headcaptcha.live scam.
Many legitimate websites generally use push notifications - that's what they have been created for. Users who like those particular sites can subscribe to push notifications and then receive relevant information periodically.
However, scammers soon realized that they could use the feature for something entirely different - to push scams and promote various commercial content. Since crooks are often associated with rogue ad networks, the quality of ads is often very poor and can include malicious links.
These are just a set of example messages that could be encountered after accessing the Headcaptcha.live site:
Messages are deliberately misleading and are made to look like they are designed for some type of verification, similar to a captcha. In other cases, people are simply promised some type of underlying content as long as users click the "Allow" button. Those who oblige would be allowing the site to deliver notifications to their screens.
- Press "Allow" to verify, that you are not a robot
- Click "Allow" to win the prize and get it in our shop!
- Please tap Allow to continue
- If you are 18+, click Allow
- Click "Allow" to start downloading.
What to do if you ran the Headcaptcha.live command
Whether you ran the command decides everything else, so the first step checks that.
Step 1: Check whether the pasted command ran
Press Windows + R and click the arrow at the right of the box: it lists the last commands typed there.
A long line starting with
powershell,mshta, cmd or curl means the page's command ran, and it usually downloads a password stealer. If it is there, disconnect from the internet now and do every step below, including the passwords.If the list holds nothing like it, you only saw the page, and closing it was enough. The Run box keeps this history in Windows 11 and Windows 10 alike.
Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 2: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 3: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 4: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to Headcaptcha.live or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
From our report of Oct 2022 · not reviewed since
How people end up on malicious websites and how to avoid them
It is crucial to discuss the methods by which false and harmful material spreads, as this is where many people start the unfortunate chain of events.
When safety precautions are followed, online fraud, albeit common, is relatively difficult to access because genuine websites, browsers, search engines, and other parts of the web infrastructure deploy a variety of security safeguards to stop phishing content from running rampant.
Users are less likely to come across malware, phishing, unwanted software, or anything else deemed hazardous thanks to Google, for instance, which uses efficient scanning tools that automatically identify and eliminate dangerous websites from search results. Sadly, this automated system is not safe-proof, and crooks occasionally manage to get past it. Even trustworthy websites may get compromised, exposing users to harmful links.
However, the most suspicious activity usually occurs on websites that aren't safe to visit in the first place, for example, peer-to-peer networks, gambling sites, and adult websites. These sites are rarely protected with adequate security measures, leaving users open to attacks from malicious ads, links, or files accessible to download.
Whenever users visit such dangerous places online, they run the risk of being redirected to Headcaptcha.live or similar sites or infecting their system with malware, so it's best to avoid them altogether if possible.

From our report of Oct 2022 · not reviewed since
Checking your system for adware and removing push notifications
Before you get rid of pesky notifications, try running some basic system checks.
Although push notification messages cannot harm you if you don't respond to them, system infections can be quite harmful and result in continuous personal data theft, money loss, or even identity theft.
Checking your system is vital because users with adware or other malicious software infections present on their systems are more prone to encounter phishing messages and excessive advertisements. In addition, some malware may be completely invisible to regular users and continue to operate in the background undetected.
The simplest way to accomplish this is to run a complete system scan using dynamic anti-malware software like or . All harmful files and programs are found, quarantined, and eliminated from the system by security software. We also advise using to clean your web browsers, which can assist you in preventing adware's data trackers from operating.
When it comes to Headcaptcha.live ads removal, all you have to do is access browser settings and block the website's URL. Choose the browser you use and follow the steps below:
Google Chrome (Android)
MS Edge (Chromium)
- Open the Google Chrome browser and go to Menu > Settings.
- Locate the Privacy and security section and pick Site Settings > Notifications.
- Look at the Allow section and look for a suspicious URL.
- Click the three vertical dots next to it and pick Block. This should remove unwanted notifications from Google Chrome.
- Open Google Chrome and tap on Settings (three vertical dots).
- Select Notifications.
- Locate the unwanted URL and toggle the button to the left (Off position).
- Open Mozilla Firefox and go to Menu > Options.
- Click on Privacy & Security section.
- Under Permissions, you should be able to see Notifications. Click the Settings button next to it.
- In the Settings – Notification Permissions window, click on the drop-down menu by the URL in question.
- Select Block and then click on Save Changes. This should remove unwanted notifications from Mozilla Firefox.
- Click on Safari > Preferences...
- Go to the Websites tab and, under General, select Notifications.
- Select the web address in question, click the drop-down menu and select Deny.
- Open Microsoft Edge, and go to Settings.
- Select Site permissions.
- Go to Notifications on the right.
- Under Allow, you will find the unwanted entry.
- Click on More actions and select Block.
- Open Internet Explorer, and click on the Gear icon at the top-right of the window.
- Select Internet options and go to the Privacy tab.
- In the Pop-up Blocker section, click on Settings.
- Locate the web address in question under Allowed sites and pick Remove.
Questions about Headcaptcha.live
I only saw the headcaptcha[.]live CAPTCHA and closed it. Is that safe?
Yes. The page on headcaptcha[.]live copies a command to your clipboard, but a clipboard does nothing on its own. Unless you opened the Run box, PowerShell or Terminal and pasted it, nothing ran.
To be tidy, copy some harmless text so the command is no longer on the clipboard, and if clipboard history is on, delete the entry with Win+V. Then think about how you reached the page:
- a hacked site
- an ad
- a link in a message
If notifications from strange sites keep opening pages like it, remove them in the browser settings.
Why does headcaptcha[.]live ask me to run a command to prove I am human?
Because the command is the attack. Real human checks, from Google, Cloudflare or anyone else, only ask you to click or solve a puzzle inside the page; none ever needs the Windows Run box. Criminals use this trick, called ClickFix, because browsers block malicious downloads but cannot stop you from running something yourself.
The page on headcaptcha[.]live mimics a familiar verification box to make the request feel routine. If any page asks you to press Win+R, open PowerShell or paste anything into Windows, close it. That one rule defeats every ClickFix page.
Is Headcaptcha.live really from a human-verification check?
No. It is a web page made to look like a message from a human-verification check. Websites cannot scan your computer, see your files or know whether your antivirus is active. Real security warnings appear in Windows Security or in your antivirus program, not as browser pages with phone numbers, countdowns or prize wheels.
Close the page; nothing was installed just by seeing it. If you want to check, open Windows Security from the Start menu and run a quick scan. It shows the real status of your protection.
Is headcaptcha[.]live safe?
No. The site headcaptcha[.]live hosts Headcaptcha.live, a page that imitates a human-verification check to scare or lure visitors. Do not open it again to check; the content can change between visits and may include downloads. If you see it once, close the tab.
If it opens by itself, a notification permission, an extension or a redirecting site is sending you there; the steps in this guide remove each of these. You can report the address to your browser so that others get a warning page before it loads.
Does a human-verification check ever ask me to press Win + R?
Never. Real checks from a human-verification check run entirely inside the page:
- you tick a box
- click pictures
- simply wait a few seconds
They do not use the clipboard, do not open Windows tools and do not ask for keyboard shortcuts. Any page that shows Win + R, Ctrl + V and Enter as steps of a check is Headcaptcha.live or a page like it. Close it, and if you already followed the steps, disconnect from the internet and use the plan in this guide.
Is it safe to force-close the browser?
Yes. Ending the browser in Task Manager or restarting the PC does not damage Windows or your files, despite what pages like Headcaptcha.live say. The warning "do not close this window" is part of the scam.
At worst you lose unsaved text in other tabs. After restarting, do not let the browser restore the previous session, because that would reopen the scam page.
If it reopens anyway, open the browser's settings for startup pages and remove the address. Then remove its notification permission if it has one.
How do I avoid pages like Headcaptcha.live?
Keep the browser updated, do not click Allow on notification prompts from sites you do not know, and leave sites that open many pop-ups. Turn on Microsoft Defender SmartScreen in Edge under Settings > Privacy, search, and services, or Safe Browsing in Chrome under Settings > Privacy and security > Security.
Never call numbers, download files or paste commands because a web page told you to. An ad blocker from your browser's official extension store also cuts most redirect ads. Keep Potentially unwanted app blocking on in Windows Security as well.
Why does Headcaptcha.live keep coming back?
Most often because a site has permission to send notifications, and those notifications lead to new scam pages. Remove notification permissions for unknown sites. Other causes are an adware extension, a browser that restores the previous session, or a site you visit often that shows such ads.
If the page appears outside the browser, a program on the PC is responsible; check Installed apps. If you cannot find the source, resetting the browser removes all of these causes at once.
Is my phone affected by Headcaptcha.live?
Not through the PC. A scam page in a Windows browser cannot reach a phone, even if both use the same account. The sign reported, A fake CAPTCHA on headcaptcha[.]live that asks you to paste a command, happened in a browser on the PC.
Phones can meet similar pages on their own, usually through ads or notifications, and the fix there is the same idea: remove notification permissions and unknown apps. If you used the phone to call a number shown on the page, follow the steps for callers in this guide.
Will Fortect remove Headcaptcha.live?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Headcaptcha.live, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Wikipedia: API (read October 7, 2026)
- FTC: How to spot, avoid and report tech support scams (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)
- Microsoft Learn: How Microsoft names malware (read October 7, 2026)