This mail had a .rar file attached and since that is not suspicious she opened it and clicked on the perfectly common .exe file.
So yeah. Well, it doesn't really do much, it opens a window that rask for access to a protected element (whatever that means) and the name of the aplication is a weird A with a - on the top, like a card on top of two cards.
This unusual fellow seems to go by the process name of "mesengerwindows.exe" (Only one s) and has files on C:\WINDOWS\System32\mesengerwin\mesengerwindows.exe
This file is the one that boots on startup and it shows up several times on the Start menu.
Looking for the name of the .exe doesn't give any results on the internets so I'm going to install a decent antivirus, boot on Safe mode, run it, run SUPERAntiSpyware, run CCleaner, run some kind of online scan, delete the files and see how it goes.
Any tips?