URL:CardStealer popup on magento 2 websites

Hello Attila, 

We are sorry for the inconvenience caused. We will check and help you to resolve it. Please submit the URL to our developers for analysis.
Click this link (https://www.avg.com/en-ww/false-positive-file-form) to submit the form.
Our developers will check and get back to you as soon as possible.

Until then you can add this website to the Exceptions.
AVG >> Menu >> Settings >> General >> Exceptions

Hi, I am a web developer and we work with Magento 2 CE websites.
I have 2 websites reported by AVG beeing infected with URL:CardStealer .
I searched for hours both in database and code and found nothing. 
Also git and composer reports no modifications of the files.
Please review https://www.sculesiechipamente.ro/ and https://staging.anveloshop.ro/ and help us to identity the malware. 
Could it be that AVG detects a false positive ?
Thank you.

Hello Attila.

Did you solve your problems ? We have the same here on (url removed)
If yes, what did you do ?

Best,
Maxime

Hello Attila.

Did you solve your problems ? We have the same here on (url removed)
If yes, what did you do ?

Best,
Maxime

Hi Maxime,

We're glad to look into this & help you.
Please write back to us in your own post to proceed further.
Thank you in advance!

Hello Attila, 

We are sorry for the inconvenience caused. We will check and help you to resolve it. Please submit the URL to our developers for analysis.
Click this link (https://www.avg.com/en-ww/false-positive-file-form) to submit the form.
Our developers will check and get back to you as soon as possible.

Until then you can add this website to the Exceptions.
AVG >> Menu >> Settings >> General >> Exceptions