I'm at work and my wife calls me due to her Win7 PC acting up. It sounds like a FakeAV type of infection.
I Remote-Desktop to her PC from work and log on under my own account and my login is not infected. Task manager shows a suspicious program Hotfix.exe Setup running about 20% of the CPU.
I killed the program and was able to log on as her without the infection showing up. There was a browser page pointing to "something".cz.cc (don't remember the Url exactly). I closed it. I located the hotfix.exe under her \users\wife\appdata\roaming and deleted it.
I will run a malwarebytes scan later but I think she is OK now. She runs MS Security Essentials but it did not prevent the attack nor did a quickscan find anything.