I’m reporting a false positive for novax.hr, which is being blocked by Avast/AVG with detection “URL:Blacklist” (Web Guard).
I’ve submitted the official false-positive report form on the AVG website twice — first around July 16, 2026, and a follow-up around July 21, 2026 — but haven’t received any response or resolution on either submission.
Some background: novax.hr is the official website of NOVAX, a graphic design and digital printing company based in Lovran, Croatia. The website was rebuilt from scratch as a clean static HTML site (no CMS). The previous WordPress installation, which was targeted by heavy automated wp-login.php brute-force attacks, has been fully deleted and is no longer in use.
The site is currently rated clean by Google Safe Browsing and Sucuri SiteCheck, and has already been cleared as a false positive by Fortinet, Sophos, Webroot, McAfee, Emsisoft, Dr.Web, Forcepoint ThreatSeeker, and Symantec/Broadcom (WebPulse).
Could someone from the Avast team please take a look and remove novax.hr from the URL:Blacklist? Alert ID from the detection popup: f5ad448eebba/2026-07-21T14:41:55.282Z
First, I’m an Avast user and not an Avast Team member.
Possible False Positive
New location to report both a False Positive and or a False Negative (for File or URL) I don’t know if this is where you reported it - Choose Your Sample Submission Type | Avast
You won’t get a direct response but it should be analysed within 48 hours, if found to be false it will be removed.
There are sites that can also check a site link.
Thank you so much for looking into this and for offering to loop in the Avast team — really appreciate it!
Just to add some context: we’ve been actively reaching out to the other vendors that had novax.hr flagged too, and most have already cleared it (Fortinet, Sophos, Webroot, McAfee, Emsisoft, Dr.Web, Forcepoint ThreatSeeker, Symantec/Broadcom WebPulse, alphaMountain.ai, Chong Lua Dao). A couple are still pending.
Interestingly, one of them (Gridinsoft) told us they can’t manually clear the detection until the other vendors do — their system aggregates other engines’ verdicts and updates automatically once the rest are clean. So Avast being one of the last ones still flagging it is actually holding back that domino effect for at least that vendor too.
Thanks again for the help, and I’ll keep an eye on this thread!
The reported domain was checked, and based on the findings, the detection was removed. The website is now marked as clean in the Avast database. This change may take up to 1 hour to take full effect. Please accept my apology for the inconvenience caused.