How to Remove LuDaShi Adware and Stop MiniPopups Alerts

Brendan Smith
Brendan Smith - Cybersecurity Analyst
14 Min Read
LuDaShi pop-up windows caught in a repeating loop with an uninstall lever.
Repeated LuDaShi pop-ups can point to an unwanted installation or a remaining startup component.

LuDaShi is a real Windows hardware utility, but an unexpected installation, repeated advertising pop-ups, or a PUAAdvertising:Win32/MiniPopups alert should be treated as an unwanted-software problem. Uninstall LuDaShi through Windows, remove other programs installed with it, reboot, and check startup entries, tasks, services, and browser changes. If the alert returns, use its exact affected-item path to find the component that is recreating it instead of deleting Defender history first.

Do not assume every file carrying the LuDaShi name is a Trojan. The source, digital signature, install path, companion apps, and post-reboot behavior decide whether you have the recognized utility, a bundled potentially unwanted app, or an unrelated lookalike.

Is LuDaShi a Virus or Adware?

LuDaShi describes its Windows product as a hardware-testing, authenticity-checking, temperature-monitoring, and performance utility. That establishes a legitimate product identity, but it does not authenticate the copy on your PC or make an unexpected bundle desirable. A familiar name can appear in an official signed installer, a third-party bundle, or a different executable using the same label.

Microsoft separates potentially unwanted applications (PUAs) from malware. A PUA can still show unwanted advertising, offer additional software, change the browsing experience, or make removal difficult. That distinction matters: a PUA alert is a reason to review and remove an unwanted installation, not proof that every LuDaShi build steals data or behaves like a Trojan.

Situation Risk and what to do
You deliberately installed LuDaShi from its official site, its publisher signature is valid, and there are no unexpected ads or companion apps The core utility may be intentional. Keep it only if you need it, and uninstall it normally rather than restoring a separately detected file by name alone.
LuDaShi appeared after another installer, download manager, driver tool, crack, or repack Treat it as an unwanted bundle. Remove LuDaShi and review every app installed on the same date.
Windows Security reports PUAAdvertising:Win32/MiniPopups Keep the item blocked or quarantined. Record the affected path, remove the owning app, reboot, and scan again.
The alert or pop-up returns after uninstall A task, service, startup helper, browser component, cached installer, or second bundled app may still be active.
The executable is unsigned, has a different publisher, or runs from Temp, Downloads, or an unrelated random folder Do not allow or restore it. Treat it as a suspicious lookalike and perform a full-system scan.

What Does PUAAdvertising:Win32/MiniPopups Mean?

PUAAdvertising:Win32/MiniPopups is a Microsoft Defender-style label for advertising software. The useful evidence is not only the name: Windows Security also shows the affected file and its path. A path containing a LuDaShi setup folder can connect the detection to that installation, while a file elsewhere may belong to another bundle or a lookalike.

A public Microsoft Q&A case documents the same MiniPopups label under a LuDaShi setup path and a warning that appeared again after reboot. The case also illustrates an important diagnostic split: sometimes the original file is still being recreated, while in other cases the file is gone and only old protection history remains. Confirm which state you have before clearing anything.

  • Active file: the affected path still exists or reappears after reboot. Find the owning app, task, service, or installer.
  • Repeated creation: the file disappears after quarantine but returns at the same path. A launcher or bundled component is restoring it.
  • History-only entry: the path no longer exists, a current full scan is clean, and no pop-up or process returns. The visible record may be stale protection history.

How to Remove LuDaShi and Stop It Coming Back

  1. Record the alert before changing anything. Open Windows Security → Virus & threat protection → Protection history. Note the exact detection, affected-item path, action status, and time. Take a screenshot for your own reference.
  2. Close LuDaShi and any advertising windows. Do not approve an update, recommended download, browser extension, or additional cleaner. If the app appeared unexpectedly, disconnect from sensitive accounts until cleanup is complete.
  3. Uninstall LuDaShi through Windows. Open Settings → Apps → Installed apps, locate LuDaShi, and choose Uninstall. Use Control Panel → Programs and Features on older Windows versions. Do not start by deleting its folder; the normal uninstaller should remove registered components first.
  4. Review other apps installed on the same day. Sort Installed apps by date. Remove unfamiliar download managers, driver utilities, video helpers, coupon tools, optimizers, or Chinese-language companion software that arrived with the same package. Do not remove an app only because its interface language is unfamiliar—verify its name, publisher, and install date.
  5. Restart Windows once. A reboot lets uninstallers finish and reveals whether a helper relaunches the program or recreates the detected file.
  6. Check startup entries, tasks, and services. In Task Manager → Startup apps, disable entries tied to the recorded LuDaShi path. In Task Scheduler, inspect the Actions tab before disabling a task. In services.msc, verify the executable path and publisher before stopping a service. Do not delete generic Windows update or maintenance entries by guesswork.
  7. Check browsers. Remove unknown extensions, restore the intended search engine and startup page, and revoke notification permissions from unfamiliar sites. If the browser says it is managed on a personal PC, inspect policies before resetting it.
  8. Remove confirmed leftovers. Delete the remaining LuDaShi app folder and cached installer only after the process, task, and service that use it are gone. Check the exact locations recorded by Windows Security. Do not delete broad Registry branches, Windows system folders, or every file whose name contains update.
  9. Update security intelligence and run a full scan. Apply the action offered for the PUA, update Microsoft Defender, and scan all drives. A second security scan is especially useful if LuDaShi arrived through a bundle, the executable ran from a user-writable folder, or multiple unwanted apps appeared.
  10. Reboot and verify again. Confirm that LuDaShi no longer appears in Installed apps or Task Manager, the same affected file is not recreated, the pop-ups are gone, and a current full scan is clean.

If you see LuDaShi and bundled apps or other suspicious applications that you don't remember installing, you should remove them as well.

WindowsMacAndroid
Windows 10/11
  1. Right-click the Start button and select Installed Apps (or Apps & Features).
  2. Scroll through the list to find LuDaShi and bundled apps or any other unfamiliar program.
  3. Click the three dots (...) next to it and select Uninstall.
Mac OS
  1. Open Finder and go to the Applications folder.
  2. Locate LuDaShi and bundled apps or any app you don't recognize.
  3. Drag it to the Trash.
  4. Empty the trash to remove it permanently.
Android 11+
  1. Go to Settings > Apps > See all apps.
  2. Find LuDaShi and bundled apps or any suspicious app in the list.
  3. Tap on it and select Uninstall.

If the visible program is gone but MiniPopups activity returns, another launcher, scheduled task, service, browser change, or bundled module may remain. Run a full Gridinsoft Anti-Malware scan after the manual checklist, remove confirmed detections, reboot, and scan again if the symptom returns.

LuDaShi or MiniPopups keeps returning?

Browser reset can remove visible symptoms, but adware may keep a desktop app, extension source, notification permission, or startup task that brings pop-ups and redirects back.

Scan for adware leftovers

Remove LuDaShi-Related Browser Changes

Not every LuDaShi case changes a browser. Perform these steps only when the homepage, search engine, new tab, extensions, or notification behavior changed around the same time.

  1. Open the browser’s extension manager and remove add-ons you did not choose.
  2. Check the default search engine, startup pages, homepage, and new-tab behavior.
  3. Open notification permissions and remove unfamiliar allowed sites.
  4. Check chrome://policy or edge://policy on a personal computer. Unknown forced-extension or search-provider policies need investigation.
  5. Pause browser sync temporarily if the same unwanted setting returns on multiple devices.
Google ChromeSafariMozilla FirefoxMicrosoft EdgeBraveOpera
Google Chrome
Extension Manager
  1. Launch Chrome.
  2. Click the three dots (...) in the top right corner.
  3. Select Extensions > Manage Extensions.
  4. Click Remove next to the extension you want to delete.

Quick Access: Type chrome://extensions/ in the address bar.

Safari
Settings > Extensions
  1. Open Safari.
  2. In the menu bar, click Safari and select Settings (or Preferences).
  3. Click on the Extensions tab.
  4. Select the extension and click Uninstall.
Mozilla Firefox
Add-ons and Themes
  1. Click the menu button, select Add-ons and themes.
  2. Go to the Extensions tab.
  3. Click the three dots (...) next to the extension and select Remove.

Quick Access: Type about:addons in the address bar.

Microsoft Edge
Browser Extensions
  1. Launch Microsoft Edge.
  2. Click the three dots (...) in the top right corner.
  3. Select Extensions.
  4. Find the extension and click Remove.

Quick Access: Type edge://extensions/ in the address bar.

Brave
Shields and Extensions
  1. Launch Brave browser.
  2. Click the menu icon > Extensions.
  3. Find the extension and click Remove.

Quick Access: Type brave://extensions/ in the address bar.

Opera
Extension Management
  1. Launch Opera.
  2. Click the Opera logo in the top left corner.
  3. Select Extensions > Extensions.
  4. Click the X or Remove button next to the extension.

Quick Access: Type opera://extensions/ in the address bar.

Open Extensions/Add-ons again and remove any entry linked to LuDaShi bundle or clearly out of place.

If LuDaShi pop-ups keeps showing unwanted pop-ups, you likely granted it permission to send notifications. To stop them, you need to revoke that permission in your browser settings.

Google ChromeSafariMozilla FirefoxMicrosoft EdgeBraveOpera
Google Chrome
  1. Copy and paste this into the address bar: chrome://settings/content/notifications
  2. Scroll down to the Allowed to send notifications list.
  3. Find LuDaShi pop-ups.
  4. Click the three dots (...) next to it and select Remove (or Block).
Safari
  1. Open Safari and go to Settings (or Preferences).
  2. Click the Websites tab and select Notifications on the left.
  3. Find LuDaShi pop-ups in the list on the right.
  4. Select it and click Remove (or change "Allow" to "Deny").
Mozilla Firefox
  1. Copy and paste this into the address bar: about:preferences#privacy
  2. Scroll down to Permissions and click Settings... next to Notifications.
  3. Type LuDaShi pop-ups in the search bar or find it in the list.
  4. Select the site and click Remove Website.
Microsoft Edge
  1. Copy and paste this into the address bar: edge://settings/content/notifications
  2. Look under the Allow section.
  3. Find LuDaShi pop-ups.
  4. Click the three dots (...) next to it and select Remove (or Block).
Brave
  1. Copy and paste this into the address bar: brave://settings/content/notifications
  2. Scroll to the Allowed to send notifications list.
  3. Find LuDaShi pop-ups.
  4. Click the three dots (...) and select Remove (or Block).
Opera
  1. Copy and paste this into the address bar: opera://settings/content/notifications
  2. Check the Allowed to send notifications list.
  3. Find LuDaShi pop-ups.
  4. Click the three dots next to it and select Remove.

Use the broader PUA and browser hijacker removal guide when redirects or managed policies remain after the desktop app is removed.

Could the LuDaShi Alert Be a False Positive or Stale History?

Possibly, but verify the file before restoring it. A clean decision needs more than an official-looking filename. Check that the installer came from the intended site, the digital signature names the expected publisher and validates correctly, the file hash is stable, the path belongs to the installed app, and no additional unwanted programs or symptoms appeared. The EXE safety checklist explains how to verify those properties.

If the affected file no longer exists, LuDaShi is uninstalled, a current full scan is clean, and nothing returns after reboot, the remaining entry may be historical. Update Defender and rescan before touching its history. Clearing history first can hide the path and time evidence needed to find an active launcher.

If you believe a current signed file is incorrectly classified, collect its SHA-256 hash, source URL, signature details, and detection name, then use the false-positive reporting process. Do not disable PUA protection or add a broad folder exclusion to keep one utility.

How to Confirm LuDaShi Is Completely Removed

  • LuDaShi and its unwanted companion apps are absent from Installed apps.
  • No LuDaShi process, startup entry, task, or service returns after reboot.
  • The affected MiniPopups file is absent and is not recreated.
  • Browser search, startup pages, extensions, policies, and notifications stay unchanged.
  • A current full scan completes without the same PUA or related bundle detections.
  • No new advertising window, optimizer prompt, or unexpected download appears.

If several unrelated apps, remote-access tools, account prompts, or security alerts appeared with LuDaShi, continue with a Windows security audit after malware. Removing one visible utility does not prove that an unrelated installer bundle is gone.

How to Avoid Another Unwanted Utility Bundle

  • Download utilities from the publisher’s official site, not search ads, mirrors, repacks, or download portals.
  • Choose custom installation and decline optional optimizers, browser helpers, extensions, and notification prompts.
  • Check the publisher signature before running a system utility with administrator rights.
  • Keep Microsoft Defender PUA blocking enabled and do not add exclusions to bypass a bundle warning.
  • Prefer Windows Update and the PC maker’s support page for drivers instead of broad driver or performance bundles.

FAQ

Is LuDaShi malware?

LuDaShi has a real hardware-utility identity, so the name alone does not make every copy malware. An unexpected installation, advertising behavior, PUA alert, invalid signature, wrong path, or bundled apps justify removal and a full scan.

Should I remove PUAAdvertising:Win32/MiniPopups?

Yes. Keep the detected item blocked or quarantined, record its path, remove the owning app or bundle, reboot, and scan again. Do not restore it only because the path contains a familiar product name.

Why does MiniPopups keep coming back after reboot?

A task, service, startup helper, cached installer, browser component, or second bundled app may be recreating the file. Compare the affected path before and after reboot to locate the owner.

Can I delete the LuDaShi folder manually?

Uninstall through Windows first. Delete a confirmed leftover folder only after its processes, tasks, and services are stopped. Manual folder deletion alone can leave registered startup components behind.

Should I clear Microsoft Defender history?

Not as the first fix. Confirm that the affected file is gone, nothing recreates it, and a current full scan is clean. Clearing history too early removes useful path and time evidence while an active launcher may remain.

References

  1. LuDaShi. “PC Version of LuDaShi.” LuDaShi official website, product page last showing a November 29, 2019 update; accessed August 10, 2026. https://www.ludashi.com/en/
  2. Microsoft Support. “Protect your PC from unwanted software.” Microsoft, current living document; accessed August 10, 2026. https://support.microsoft.com/en-us/windows/security/threat-malware-protection/protect-your-pc-from-unwanted-software
  3. Microsoft Q&A. “PUAAdvertising:Win32/MiniPopups (ludashi/setup/.dll).” Microsoft Community, July 28, 2024; accessed August 10, 2026. https://learn.microsoft.com/en-us/answers/questions/3997044/puaadvertising-win32-minipopups-(ludashi-setup-dll)
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?