This being detected by avast?

What to be detected. Scumware has it as follows: 2019-02-24 07:05:45 htxp://creativeengravingplus.com/wp-content/themes/ce/inc
lude/pik.zip 938DD9CB3B3CD59E88C9BBDEA0B0B645 199.102.228.90 US JS:Trojan.Agent.DQBF
URLhaus has it: https://urlhaus.abuse.ch/url/147741/ (abused domain malware)…
Nothing here: https://www.virustotal.com/#/url/e9dce59de43bb334d16ea8e423899531c1f820e314a67250abdcdaa280ab90d1/detection
Once flagged yesterday: https://www.virustotal.com/#/url/e870ac709185d43a131666df281c8f1dc65df12da6f42f113679a047ded9ea57/detection
avast shown such infections as seen here: https://wordpress.org/support/topic/jsagent-dzx-trj-wordpress-infected/

FAQ: https://codex.wordpress.org/FAQ_My_site_was_hacked

polonus (volunteer website security analyst and website error-hunter)

[b]Nothing here:[/b] https://www.virustotal.com/#/url/e9dce59de43bb334d16ea8e423899531c1f820e314a67250abdcdaa280ab90d1/detection
Yes there is ... look again ;)

goes to a zip that containe a downloader
https://www.virustotal.com/#/file/cefbc8d502e1ae7f0ffe1562c4bc4b2dff903495eea9431a73d10573d6ae9705/detection

Yep, avast detects as Script:SNH-gen [Trj],

pol

You are right, Pondus, I see, but the threat level for this Leaseweb IP address is sketched as low:
https://db-ip.com/199.102.228.90

pol