TR/Crypt.XPACK.Gen is a generic detection for a harmful Trojan that encrypts certain data on the infected computer. This type of Trojan specifically targets files on Windows operating system. The Trojan then demands for a ransom payment to decrypt data. Users will be oblige to pay for the decryption tool using various online payment schemes.

In usual occasion, TR/Crypt.XPACK.Gen enters the computer through the use of another threat. It can be a Trojan Downloader or malicious code pretending to be a useful program. Once executed, it will drop a file that can lead to the infection of TR/Crypt.XPACK.Gen. Files and registry entries are then created on the infected PC. Added registry values are vital in loading TR/Crypt.XPACK.Gen as soon as Windows system starts.

Presence of TR/Crypt.XPACK.Gen brings several disruptions on the computer. Aside from reducing the performance on the system, the Trojan also causes severe malfunction to some programs and operating system as well. Furthermore, TR/Crypt.XPACK.Gen may affect other Windows functions especially tools that are useful in the removal of threats. Anti-virus program may also stop performing when TR/Crypt.XPACK.Gen infects executable files related to it.

You must remove TR/Crypt.XPACK.Gen immediately before it can further harm the computer. Follow the procedures stated below to totally get rid of this threat including other relayed viruses.


Signs and Symptoms of TR/Crypt.XPACK.Gen Infection:

TR/Crypt.XPACK.Gen will disable your antivirus program
Once a Trojan infects a computer, it has a tendency to lower security settings and disable firewall and antivirus program. TR/Crypt.XPACK.Gen carry out this task to ensure that antivirus software will not respond on the attack.

Blocks Internet access to security web site
TR/Crypt.XPACK.Gen attacks the center of the security system. Aside from disabling antivirus software, this Trojan also blocks your access to security web site to prevent downloading of any removal tools.

Presence of TR/Crypt.XPACK.Gen reduces PC's performance
Trojans are known to reside in the memory, thus, it can consume resources that can cause computer to slow down. There are cases that infected computer crashes due to insufficient resources.

Other Functions of TR/Crypt.XPACK.Gen:

  • TR/Crypt.XPACK.Gen can communicate to a remote server to download more threats
  • It can infect executable files on the local and network drives
  • This hazardous Trojan can connects to a distant server to update its configuration
  • Some variants of TR/Crypt.XPACK.Gen can destroy system files making the computer unstable
  • This Trojan can allow a backdoor entry for an attacker to control the infected PC

How to Remove TR/Crypt.XPACK.Gen

Step 1 - Run a thorough scan using your antivirus program

1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. Open your antivirus application and update the virus definitions. This method ensures that your antivirus program can detect even newer variants of TR/Crypt.XPACK.Gen

3. Start Windows in Safe Mode with Networking.
- From a power-off state, turn on the computer and press F8 repeatedly.
- Your computer will display Windows Advanced Boot Options menu. Select Safe Mode with Networking.
- System will boot Windows loading only necessary drivers and system files.


4. Open your antivirus program and run a full system scan. After the scan, delete all infected items. If unable, better place them in quarantine. Once the scan is complete please proceed with the next step.

Step 2 - Double-check with Online Virus Scanner

Another way to remove TR/Crypt.XPACK.Gen without the need to install additional antivirus application is to perform a thorough scan with free online virus scanner that can be found on websites of legitimate anti-virus and security provider.

5. Go to Online Virus Scanner list and run a virus scan. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.

Online Scan

6. After completing the necessary download, your system is now ready for online virus scanning.
7. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
8. Remove or delete all detected items.
9. When scanning is finished you may now restart the computer in normal mode.

Step 3 - Automatic Removal of TR/Crypt.XPACK.Gen files and registry entries

In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.


  1. jeff

    kindly help me to remove this virus on my pc thanks

  2. arkey

    how can i remove this TR/Crypt.XPACK.Gen virus or spyware

  3. Bin

    Please help…. i also got this virus in my pc. how can i remove this???

  4. John

    The advice given above did not work for the variant I have. The Anti-Virus solutions that failed to find it include:

    1. Macafee
    2. Kaspersky
    3. Malbytes Anti-Malware (Found but false clean!)

    Avira antivir personal found and quarantined the infected files. I have no axe to grind with any of the above products. But after the original scan and clean I was lulled into a false sense of security. I don’t think this is the end of the story as the registry scan did not reveal how the virus is loaded. If I discover how the virus starts up I will post the info here. As a courtesy I will send copies of the infected files to the above companies.

  5. Billy

    update anyone? cant get rid of it….. mbam, avira, avast, none work???? HELP

  6. nick

    im at work and unfortunately the work computer uses windows 2000 and the virus popped up soon after i downloaded an extension form from the irs website…now i cant access the internet to fix the problem and i cant even use my usb slots to upload a file from a flash drive…what do i do?????????

  7. Justin Mitchell

    I’ve had no luck (so far) removing this virus from a Win XP machine. I’ve run nod32, kaspersky, bitdefender, superantispyware, malwarebytes, avg, and avira.

    MLB and Avira detected it, but failed to remove it. In fact, any time I ran Avira, the computer would shutdown. Running under safe mode gave me better results, but the virus persisted, even though avira said it removed it.

    Another website suggested trendmicro housecall, which I will try next.

  8. Sam

    i have Avira Free version i also have Deepfreeze so i always have a popup window telling me that this virus is on my comp. i keep on deleting but it doesn’t work. also i think maybe because of the deepfreeze. but im too scared to remove it because it might crash it while deepfreeze is disabeled. Help me pls O_O

  9. Dustin

    Anyone got any solution for this virus? every time i boot my pc and scan my drives this virus is still there even though the previous scan that i did showed that it has been contained. Mushqila, this virus is so persistent.

  10. Rob

    The reason most of you are having trouble removing it is because your running your virus scanners in Windows or a safe mode environment, your best bet would be to use a boot cd of sorts and run a virus scanner (avira) /malwarebytes. It will work 99.95% of the time.

  11. Eve - New for Technician Computer

    How to remove the virus :
    – TR/Crypt.XPACK.Gen

  12. Ravi

    Disconnected the Hard Disk.
    and mounted it on a clean enviroment
    Still the Same

  13. Mel

    I have tried Avira, Malwarebytes and Spybot, all of which have not removed the virus. It is in my temp folder and every time I delete it, it pops up under a different file name. Please help. It’s starting to drive me insane

  14. aleksi

    I have similar problems with trojan Crypt.XPACK.Gen
    I have tried Avira, Malwarebytes and Avast, all of which have not removed the virus. It is in my temp folder and every time I delete it, it pops up under a different file name. Please help.

  15. Abe

    Hi. I have the following:

    I’m not sure if it’s still in my system but i have the proof!! My laptop is so slow, everytime i open the laptop, Avira Gaurd is disabled, and sometimes my firewall turns of everytime i open the laptop.

    Please help me!!!! I’m not sure if it’s in my laptop but i’m very sure it’s infected!! thanks

  16. CJ

    Down load (free) AntiVir Personal software…run the defaul settings. It will remove this virus…I’ve done my ProBono for today. :) Let me know the outcome.

  17. s.b

    it also infect the file svchosts file. in the process list in Task Manager in some cases. remove tre proces and then run AV program. ceck again in task manager
    hope it works

Comments are closed.