Sistray.exe is also a trojan. See:
This is a trojan which displays Italian messages, modifies the registry and shuts down the system after each reboot.
When executed it does the following:
Drops the files Sistray.exe and Sistrai.exe into folder C:\Windows\Command\
The file Sistrai.exe is a utility which shuts down the system and we detect it as 'Reboot-Q trojan'
Drops the file Explorer.exe into folder C:\Windows\System\
Replaces Autoexec.bat - The original is renamed to Autoexec.bac
Renames the MSconfig.exe in C:\Windows\System\ to system12.sys
The following registry keys are modified so that the system is shut down after every reboot.
It disables the Windows REGEDIT utility so that the user cannot edit the registry by setting the the following key value to 1:
It also removes the Run option from the Start menu as well as 'Favourites, 'Documents' and 'logoff' by setting the their key values to 1 from the following registry location.