My brother in law got hit with Windows Police Pro on either 29 or 30 August. I wiped the WPP folder, but all EXE files were being intercepted and routed through "desote.exe". I deleted that file (probably a bad idea) and now I cannot reassociate EXE files. That means that I can't get into RegEdit, although there's a second problem there.
Apparently there's some hidden process running that intercepts regedit and regedt32; if I try alternate ways to run them (including renaming) they try to start and get killed. Also, I can't do system restore because the Properties attribute on My Computer cannot fine rundll32.exe (although it is right there in plain sight where it should be).
A process called svchasts.exe was running; I deleted it from task manager and it has not come back.
We may have a doorstop if I can't work out a way to reassociate EXE files to work, as I can't find the original XP CD on this box.