Pushycaptcha.live: what it is and how to remove it
Pushycaptcha.live is a fake website created by fraudsters to generate revenue from pay-per-click advertising. They use social engineering methods to trick people into subscribing to push notifications.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If you ran the command from pushycaptcha[.]live, a free scan can check startup items, tasks and programs that loaders usually add.
Do it yourself · free Remove Pushycaptcha.live yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Pushycaptcha.live: summary
| Distribution | Shady websites, deceptive ads, redirects, freeware installations |
|---|---|
| NAME | Pushycaptcha.live |
| TYPE | Push notification spam; adware |
| SYMPTOMS | Pop-up ads start appearing in the corner of the screen after the "Allow" button is pressed |
| DANGERS | Links embedded in the push notifications can lead to dangerous websites where users can be tricked into providing their personal information and suffer from monetary losses |
| Detection names | No Microsoft detection name is known |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Damage | Not recorded in the old report |
|---|---|
| Name | Pushycaptcha.live |
| Type | Fake CAPTCHA page |
| Symptoms | A fake CAPTCHA asking to press Win+R |
| Evidence | 5 write-ups by security sites; details still limited |
| Imitates | A human-verification check |
| Domains | pushycaptcha[.]live |
| First seen | 16 November 2022 |
| Facts checked | 7 October 2026 |
Is the Pushycaptcha.live check real?
- Address:
pushycaptcha[.]live
From our report of Nov 2022 · not reviewed since
More from our earlier report on Pushycaptcha.live
- Users can block push notifications via browser settings
What the Pushycaptcha.live scammers want
From our report of Nov 2022 · not reviewed since
Pushycaptcha.live generates revenue for crooks through pay-per-click advertising
Pushycaptcha.live is a fake website created by fraudsters to generate revenue from pay-per-click advertising.
They use social engineering methods to trick people into subscribing to push notifications. Users are asked to press the "Allow" button to confirm that they are not robots and proceed to the site.
In reality, there is no other content to explore on this site besides the deceptive message. Additionally, crooks may use rogue advertising networks that place ads leading to dangerous websites. People may end up on scam sites that try to trick them into providing personal information, downloading PUPs (potentially unwanted programs), and even malware.

From our report of Nov 2022 · not reviewed since
Safe browsing tips
Pages, like Pushycaptcha.live are usually found on other shady sites.
To avoid them, you should only visit websites that you know and trust. Do not use illegal streaming websites as they are unregulated. They are filled with deceptive ads and sneaky redirects. Some of them may even display fake "Download" and "Play" buttons.
Use legitimate streaming platforms like Netflix or Hulu. They only require a small monthly subscription fee and people are able to consume as much content as they want. This way you will prevent yourself from encountering scams and will keep your data as well as your system safe.

From our report of Nov 2022 · not reviewed since
Block notifications from Pushycaptcha.live
Because push notifications are subscription-based, they can be turned on and off only manually.
We have a detailed guide for the most popular browsers below:
Google Chrome (desktop):
Google Chrome (Android):
MS Edge (Chromium):
- Open Google Chrome browser and go to Menu > Settings.
- Locate the Privacy and security section and pick Site Settings > Notifications.
- Look at the Allow section and look for a suspicious URL.
- Click the three vertical dots next to it and pick Block. This should remove unwanted notifications from Google Chrome.
- Open Google Chrome and tap on Settings (three vertical dots).
- Select Notifications.
- Locate the unwanted URL and toggle the button to the left (Off setting).
- Open Mozilla Firefox and go to Menu > Options.
- Click on Privacy & Security section.
- Under Permissions, you should be able to see Notifications. Click Settings button next to it.
- In the Settings – Notification Permissions window, click on the drop-down menu by the URL in question.
- Select Block and then click on Save Changes. This should remove unwanted notifications from Mozilla Firefox.
- Click on Safari > Preferences...
- Go to Websites tab and, under General, select Notifications.
- Select the web address in question, click the drop-down menu and select Deny.
- Open Microsoft Edge, and click the Settings and more button (three horizontal dots) at the top-right of the window.
- Select Settings and then go to Advanced.
- Under Website permissions, pick Manage permissions and select the URL in question.
- Toggle the switch to the left to turn notifications off on Microsoft Edge.
- Open Microsoft Edge, and go to Settings.
- Select Site permissions.
- Go to Notifications on the right.
- Under Allow, you will find the unwanted entry.
- Click on More actions and select Block.
From our report of Nov 2022 · not reviewed since
Clear your browsers
It is highly suggested that you clear your web browsers after an encounter with a push notification page.
Websites may utilize a variety of tracking methods, like cookies. They can store data such as IP addresses, geolocation, website visits, links clicked on, and online purchases.
While cookies have some positives - like allowing websites to generate personalized content for users - often times they are embedded in order to sell user information to advertising networks and other third parties. You should use a maintenance tool, like . With the click of a button, this software can not only stop cookies from tracking but also delete any existing data that was already collected.
From our report of Nov 2022 · not reviewed since
Scan your system for adware
Unwanted browser activity can also be caused by PUPs.
Pages like Pushycaptcha.live occasionally appear without any user interaction. Adware is a computer program that creates commercial content on the machine automatically. Many of them are masqueraded as " handy" utilities, making them more difficult to detect for average users.
Proper security tools are essential for any PC - think of them as a door to your home. Anti-malware solutions can scan your machine and detect suspicious processes running in the background, which could alert you to dangerous files trying to enter your system.
However, if you still want to do this yourself, you can follow our step-by-step instructions for Windows and Mac machines:
To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:
- Enter Control Panel into Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- From the list, find the entry of the suspicious program.
- Right-click on the application and select Uninstall.
- If User Account Control shows up, click Yes.
- Wait till uninstallation process is complete and click OK.
- Click on Windows Start > Control Panel located on the right pane (if you are Windows XP user, click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.
- Pick the unwanted application by clicking on it once.
- At the top, click Uninstall/Change.
- In the confirmation prompt, pick Yes.
- Click OK once the removal process is finished.
- From the menu bar, select Go > Applications.
- In the Applications folder, look for all related entries.
- Click on the app and drag it to Trash (or right-click and pick Move to Trash)
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any dubious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.
What to do if you ran the Pushycaptcha.live command
Whether you ran the command decides everything else, so the first step checks that.
Step 1: Check whether the pasted command ran
The fake check asked you to press Windows + R, paste and press Enter. Open the same box and look at its drop-down history: a
powershell,mshtaor curl line you did not type yourself is the command Pushycaptcha.live gave.Once run, it fetches malware within seconds, so take the PC offline and follow all the remaining steps. If the history is empty or harmless, nothing was started on the Windows 11 or Windows 10 PC.
Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 2: Scan the PC, then run the offline scan
A scan finds the parts of Pushycaptcha.live that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 3: Change passwords from another device and sign out other sessions
Pushycaptcha.live can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 4: Delete scheduled tasks that bring it back
Programs like Pushycaptcha.live add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
Questions about Pushycaptcha.live
What did the pushycaptcha[.]live verification command do?
In ClickFix campaigns the pasted line starts a hidden PowerShell, mshta or curl process that fetches a script from a remote server and runs it. That script installs the real payload, most often an information stealer, sometimes a remote access tool or a loader that brings more malware later.
The exact payload of pushycaptcha[.]live can change from day to day, which is why the safe response does not depend on knowing it: scan offline, remove what was added and change passwords from another device. Look in the Run box history with Win+R to confirm the command was executed.
Was pushycaptcha[.]live hacked, or is it a scam site?
Both happen. Many ClickFix pages are injected into legitimate websites whose software was not updated, so a site you know can suddenly show a fake check. Others sit on throwaway domains reached through ads or links in messages.
For you the answer is the same: do not follow the instructions on pushycaptcha[.]live, and if you already did, clean the PC and change passwords. If the site belongs to a business you trust, let them know through a contact form; they may not realise their pages have been tampered with.
Does a human-verification check know about Pushycaptcha.live?
Large brands such as a human-verification check are aware that scammers copy their names and logos, and most have pages where you can report such abuse. They do not run these pages and do not profit from the warnings themselves.
Sometimes an affiliate of an antivirus vendor sends traffic through fake alerts, which breaks the vendor's rules and gets the affiliate banned when reported. If you want to help, report the page address to the brand's security team and to your browser through its report option.
Why does my browser keep opening pushycaptcha[.]live?
Because something sends you there. The usual causes are a notification permission you gave to some site, an adware extension, or a site you visit often that shows redirect ads. The site itself cannot open on its own.
Remove unknown sites from the notification settings, check the extensions list, and do not restore the previous session when the browser starts. If the page appears even with the browser closed, look in Installed apps for programs you did not install. Running a scan with Windows Security afterwards confirms that nothing else is involved.
Why does Pushycaptcha.live use the a human-verification check design?
Because people see real a human-verification check checks every day and click through them without thinking. The attackers copy the familiar box, the colours and the wording, then add a few extra steps that look like part of the routine.
The trust in the real service is what makes the trick work. That is also why the page appears on ordinary websites: a hacked site with a familiar check feels safe. The extra keyboard steps are the only reliable sign, and they are always fake.
The page will not close. What can I do?
Press Esc to leave full-screen mode, then close the tab. If the browser is frozen, open Task Manager with Ctrl + Shift + Esc, select the browser and click End task. When you restart the browser, do not restore tabs.
If the page loads again on start, open a new window and close the old one, then remove the page from the browser's startup settings. Restarting the PC also works. Nothing was installed by the page, so closing it by force is safe and loses nothing.
Why do I keep seeing Pushycaptcha.live?
Because something keeps sending your browser to it. The usual causes are a site allowed to show notifications, an extension that injects pages, or ads on sites you visit often. The sign reported, A fake CAPTCHA on pushycaptcha[.]live that asks you to paste a command, appears whenever one of these triggers fires.
Remove unknown sites from the browser's notification list, delete extensions you did not install on purpose, and see whether the page returns. If it only appears on one particular site, that site's ads are the source and avoiding it or using the browser's built-in protection settings is the fix.
Do I need to reset my router because of Pushycaptcha.live?
No. Fake alert pages work inside the browser and do not change router settings. The sign reported is A fake CAPTCHA on pushycaptcha[.]live that asks you to paste a command, which comes from a web page, not from the network. Resetting the router will not stop it.
What stops it is removing the browser permission, extension or program that opens the page. If you see the same page on every device in the house without visiting the same sites, that is unusual and worth checking the router's DNS settings, but it is not what has been reported here.
I closed it, but it appeared again the next day. Why?
A page that returns on its own has a trigger. Look at how it appeared: from a pop-up in the corner of the screen means a notification permission; on start-up means a session restore or a changed start page; while browsing any site means an extension; on one particular site means that site's ads.
Each has a quick fix in the browser settings. If none of them explains it, reset the browser, which clears permissions, extensions and start pages together.
Will Fortect remove Pushycaptcha.live?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Pushycaptcha.live, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Exabeam: Top 8 Social Engineering Techniques and How to Prevent Them [2022] (read October 7, 2026)
- Howtogeek: PUPs Explained: What is a "Potentially Unwanted Program"? (read October 7, 2026)
- Torrentfreak: Google Targets Fake 'Download' and 'Play' Buttons (read October 7, 2026)
- FTC: How to spot, avoid and report tech support scams (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)