From the detection name given (TR/Crypt.XPACK.Gen2) it seems they are using Avira AV engine

EDIT: And confirmed here >> https://forums.malwarebytes.com/topic/161171-reimage-repair-false-positive-report/