Troj/PAdmin-A is a backdoor Trojan that installs itself as the file
C:\<Windows>\Repair\lsass.exe
Troj/PAdmin-A creates the following registry entry so that the Trojan is run when Windows starts up:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows_LowLevel_Security_Core
The Trojan also drops and executes the file igfxtray.exe which is detected by Sophos Anti-Virus as Troj/Netstop-A.