I get them to, but it is not mollom's fault. They are actually registering and typing the captcha just like a legitimate user. In our case they even have to use a legitimate email as they cannot do anything more than an anonymous user until the verify their email. I don't see any pattern I could apply to the user names that would distinguish them from our valid users who have some pretty weird usernames. You could find or right a module that enforced using "real names", i.e. John Doe. But I even got some like that that turn out to be spammers.