Website still being blocked by AVG after malware cleanup – primeincare(.)com

Hello,

I need some help regarding our website primeincare(.)com, which has been experiencing security issues for approximately the past 1–1.5 months.

The website was compromised for the first time around June 28, 2026. The issue was investigated and malicious content was removed. An unknown account/user that we did not recognize was also found and removed.

Unfortunately, after that we experienced further incidents.

During one of them, we found a malicious script injected into the website which appeared in the page source as:

ganalytics-tracker-js

and was loading JavaScript from an external suspicious domain (bornilo43.life/t.js). This code was subsequently removed.

More recently, AVG Web Shield blocked another external request while visiting our website:

trokuni412(.)icu/t.js?..

AVG classified it as URL:Botnet and prevented the connection.

Since then, we have checked the website again. At the moment we cannot reproduce this request. We have inspected the page source, browser DevTools, loaded scripts and Network requests, including during the ordering/checkout process, and currently cannot find requests to trokuni412.icu, bornilo43.life, or another obviously suspicious external JavaScript domain.

However, we still receive reports that some visitors cannot access primeincare(.)com, while for other visitors the website opens normally.

We also performed a fresh VirusTotal URL analysis. The website currently returns 5 detections out of 92 vendors. The current detections include:

• alphaMountain.ai – Phishing

• Fortinet – Phishing

• Seclookup – Malicious

• SOCRadar – Malware

• Webroot – Malicious

The majority of vendors report the website as clean.

Therefore, we are trying to understand whether AVG is currently detecting an active threat on primeincare(.)com, or whether the domain is still being blocked because of its reputation/history following the previous compromises.

Could you please clarify:

Is primeincare(.)com currently blacklisted or classified as malicious by AVG/Avast?

If so, is this because AVG currently detects malicious content on the website, or because of its previous reputation/history?

Does AVG still detect any specific malicious URL, script or file being loaded from primeincare(.)com? If yes, could you please provide the exact URL/file so that we can investigate it?

After a compromised website has been cleaned, how long does it normally take for AVG/Avast to reassess the domain and stop blocking it?

Is there a manual review/reclassification process that we should request in order to have the website rescanned and removed from the malicious/compromised website list?

We are particularly concerned because the website is an active e-commerce website, and intermittent security blocking is preventing some customers from accessing it.

We can provide screenshots of the AVG URL:Botnet detection, VirusTotal results and any other information required.

Thank you in advance for checking the current status of primeincare(.)com.

Hello @Maria_Yankova,

Thank you for raising this!

The reported URLs were manually checked, and based on the findings, the detection was removed. The websites are now marked as clean in the AVG virus database. This change may take up to 1 hour to take full effect. Please accept my apology for the inconvenience.

If the detection persists after 1 hour, please update the AVG virus database and try again.

Thank you.