As of June 2012 two separate variants of ransomware titled Police Central e-crime Unit ransomware 1. Win32/Weelsof and 2. Win32/Reveton have been infecting numerous computers disguised as police units such as the Specialist Crime Directorate or Metropolitan Police. The Police Central e-crime Unit ransomware locks computer systems, claims the operating system or internet browser is locked due to a violation of laws, which may include distributing and visiting illegal pornography, such as child pornography, and zoofila, among other false claims. The e-crime Unit virus then demands a fine of 100 Euro or $100 (or other) be paid by UKash, Paysafecard, or other currency services.
Police Central e-crime Unit ransomware symptoms
1. Win32/Weelsof
â– A fake alert from an online authority Metro Police  stating the infected computer has been violating the law which states “this computer was locked to stop your illegal activity.”
â– Fake violation claims include: Your IP address was used to visit websites containing pornography, child pornography, zoofila, and child abuse.
â– The infection claims “Your computer also contains video files with pornographic content, elements of violence, and child pornography. Spam-messages with terrorist motives were also sent from your computer.” (please be aware these are false claims)
â– A demand for a penalty fine is made by the infection in order for infected systems to become unlocked and accessible again. “To unlock the computer you must pay a fine of 100 E” by use of Ukash or Paysafecard services.

The first variant belongs to the Win32/Weelsof malware family. Basically, it’s a Trojan that allows hackers to perform a number of actions on the infected computer. And they certain can launch such fake Police warnings as shown in the image below.
While Win32/Weelsof clearly targets the United Kingdom, the infection has spread to many other countries as well and is expected to progress, change, and adapt to other countries in the future.
2. Win32/Reveton
â– A fake alert from an online authority Specialist Crime Directorate stating the infected computer has been violating the law which states “Your computer is blocked due to at least one of the reasons specified below.”
■You have been violating Copyright and Related Rights Law (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article 128 of the Criminal Code of Great Britain.
â– Article 128 of the Criminal Code provides for a fine of two to five hundred minimal wages or a deprivation of liberty for two to eight years.
â– You have been viewing or distributing prohibited Pornographic content (Child Porno/Zoofilia and etc). Thus violating article 202 of the Criminal Code of Great Britain.
â– Illegal access to computer data has been initiated from your PC, or you have been… (incomplete wording)
â– Article 208 of the Criminal Code provides for a fine up to E 100,000 and/or a deprivation of liberty for four to nine years.
■Illegal access has been initiated from your PC without our knowledge or consent, your PC may be infected by malware, thus you are violating the law on Neglectful Use of Personal Computer. (No such law)
The second variant of Police Central e-crime Unit (PCeU) ransomware belongs to the Win32/Reveton malware family. The fake waning is different than the Weelsof version and much more sophisticated, claiming to be from Specialist Crime Directorate rather than Metropolitan Police.
How to remove Police Central e-crime Unit (Removal Instructions)
1. We strongly recommend writing down the toll free number below in case you run into any issues or problems while following the instructions. Our techs will kindly assist you with any problems.
if you need help give us a call
2. Download and install the free or full version of Malwarebytes Anti-Malware.
3. Open Malwarebytes Anti-Malware.

4. Click the large Scan Now button or visit the “Scan” tab to scan your computer for Police Central e-crime Unit malware and malicious files.

5. Once the scan is complete, click the Quarantine All button to remove the files and restart your computer.
User accounts
Ransomware usually infects 1 user account on Windows systems at a time. Here are some tips to remove ransomware by using different user accounts.
- Log into an account not affected by malware (with administrative rights) and perform a scan with reputable software to detect and remove malware.
- You can also delete the infected account.
- Other options include creating a new user account to remove malware if only 1 Window’s user account is present on the computer system.
Internet/network issues
Safe Mode With Networking can be used to access the Internet for updates, drivers, removal software, or other files if internet and network connectivity is compromised.
- DigiCert Revokes 60 Code Signing Certificates After Support Malware Incident
- ClickUp Data Leak Shows $4B Came Before Customer Security for Over a Year
- Fast16 Malware Targeted Microsoft Windows Engineering Software Before Stuxnet
- eBay DDoS Claim Follows Marketplace Outage Reported by Users
- METO Systems Named in Insomnia Ransomware Claim
WordPress Bot Protection
Bot Blocker for WordPress
Monitor bot traffic, review live activity, and control AI crawlers, scrapers, scanners, spam bots, and fake trusted bots from one clean WordPress dashboard.
Sean Doyle
Sean is a tech author and security researcher with more than 20 years of experience in cybersecurity, privacy, malware analysis, analytics, and online marketing. He focuses on clear reporting, deep technical investigation, and practical guidance that helps readers stay safe in a fast-moving digital landscape. His work continues to appear in respected publications, including articles written for Private Internet Access. Through Botcrawl and his ongoing cybersecurity coverage, Sean provides trusted insights on data breaches, malware threats, and online safety for individuals and businesses worldwide.










162 Comments
thanks a lot, u just saved my £100, i almost paid! i actually just used the “safe mode” and after running the scan, evrythng was cleaned. cheers!!!! continue the good work!
brilliant; followed onscreen instructions with my other computer and fixed in minutes.
Thank you, had to system restore to rid it! Excellent instructions!!
Thank you so so much!!!!!!!!!!! Life saver!!!!
thank u
Thank youuuu.. It is a scary experience…
I was nearly in tears when this came on the family laptop! Thankyou sooo much!!
I got one today I could’nt believe it cheeky sods thanks for the advice
thanks very much
Very very grateful! Legend
Hi,
I was unfortunate to get this virus and had my system blocked.
I tried to get to the Task manager but could’t do it so I tried to swich the user and logged on to my guest’s account.
From there it was easy to start Norton Security which found and cleaned 46 threats then I restored the computer settings to a previous date using the system restore.
Thank you so much fella. You are a life saver 🙂 x
legend
Thank you thank you for this information!
Sean Doyle you are my hero, thanks
Thanks, so so helpful!
[…] one client the victim of spectacular zoophilia accusing, picture taking ransomware, this post http://botcrawl.com/how-to-remove-the-police-central-e-crime-unit-ransomware-virus-metropolitan-poli…Â explained how to get rid rather neatly, safe mode with cmd prompt, manually start system restore, […]
U saved my life buddy I was worried couldnt sleep all night. cheers
[…] what I find on google. Check this out, looks like a good thorough guide / read about the virus. How To Remove The Police Central e-crime Unit Ransomware Virus (Metropolitan Police, Crime Directora… __________________ I'm part of *The Project* 😉 Dont Eat Animals, Its Not Good For Them And […]
Thanks so much
thank you thank you thank you
cant believe I actually got this ransome virus, So grateful to person who put this online, well done. saved me a fortune
Thank you so much. very clear instructions that anyone could follow easily. God bless
Horrible experience but with iPad on the side giving me your instructions got through it. Cannot thank you enough. These virus guys should be dealt with.
Many thanks for your help. Virus successfully removed .
Appreciated, thank you
thnks a lot buddy
Thank you 🙂 you just saved me from stupidly paying £100 for nothing! Thank you so much 🙂
thanks!!
Thank you, Sean. Very grateful to you !
Thank you so much
Thanks Sean, I was unable to access windows except using the command prompt technique. I was unable to restore my computer though as apparently system protection was not turned on?? I did manage to download malware bytes on a different computer and managed to install and run it through the safe mode cmd promt screen. This picked them up and cleared the problem. Many thanks!
That was great. but I had this virus last night (30/01/2013) on my wife’s laptop and neither avast (free version) nor superantispyware professional version could detect the virus! probably its a new version. but the good thing is that restoring the system is still resolve the problem.
Thank you mate, your a legend. Unfortunately I was so scared that I bought a UKASH voucher for £100 and entered it as said on the screen but still could not acess the computer. So I lost £100 but than I managed to get online using the different user account on the same computer and restored it to previous date and it is working fine. Hope there will be no more problems. once again thank you mate and keep up the good work.
Thank you mate. At the beginning I was scared but then thanks to your instruction I get rid of the virus!!
Thank you. Even I managed to follow the instructions and get rid of the annoying virus.
Sean, You seriously ROCK, thanks to your very detailed post, I was able to restore my pc in less than 45 minutes.
Many thanks @ RESPECT!!
Thanks Sean your a top a bloke!
Oh thank you, YOU ARE A GOD!
wow only just seen this just did a whole os reinstall ……..
thank you for being so kind as to share this with us
Thank you for your help. Was really scared when first saw it appear – then guessed it was a horrible virus so googled it and found this. Thanks a bunch man. I did a system restore and all seems ok now.
Thankyou very much, thank god there is someone trying to resolve these problems instead of creating them for no apparent reason. Much appreciated.
Thanks Sean, I successfully removed that virus – Peter
thank you so much worked great
Thanks very much for the help. It can be quite panicking when you’re told you’ve committed a crime, especially when you know you didn’t do so, so it’s great to know there are sites like this to help clear it up. Keep up the great work.
God bless Sean Doyle . Beautiful. Followed instructions and got rid of the virus in less than 5 minutes. Thanks Sean for sharing your knowledge and expertise.
Thank you so much for your help. You’re amazing.
Thank you. I have been able to get my system back after using the safe mode with command prompt. The virus had blocked anything else.
I have windows 7 and didn’t get the rstrui.exe window but a help menu from where I could access the restore to an anterior date.
Again thank you very much
Great help. Thank you. I have Vista Ultimate and virus was removed. I run (as per your instructions) C:\windows\system32\rstrui.exe and press Enter and then followed all steps to restore my computer system to an earlier time and date, before infection. Spiros from Athens Greece.