In his position, I would immediately cease operations after that police software was used on the system. Resume operations only after restoring from a clean backup taken prior to the raid.
In fact, I should probably build a "invalidate every credential I have on all my computers and accounts" checklist. That and a tested backup strategy.