This forum thread needs a solution.
Kudos0

Malicious site blocked (cleardexchange) when browsing safe sites

I wonder if someone might be able to suggest a solution to this problem for me.

This started a few weeks ago.  Occasionally (about 2-3 times per week), whilst looking through the legitimate UK news websites "www.dailymail.co.uk" and "www.thesun.co.uk", without clicking on anything, the browser closes the page and I am presented with a Norton page which says:

"Malicious site blocked - you attempted to access https://cleardexchange.com/......" - I have enclosed a screen shot below.

This is as a result of having the Norton Safe Web extension to the Chrome browser.

I contacted Norton support and their solution was to remove the Norton extension from the browser.  However, what the support team could not tell me was - am I now at risk?  Without the protection of Norton, would I have inadvertently been sent to this "cleardexchange" web site and suffered damage or data loss?

Are the Daily Mail and The Sun websites directing users to this dodgy website and should they be told about it?  Or is the Norton extension suspecting trouble with a perfectly safe site / advert?

Any clues would be very gratefully received.

File Attachment: 

Replies

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Malicious Site Blocked is a Norton IPS Alert/Block.
Maybe, you've changed Site Settings/Permissions? 
Maybe, you allowed Push Notifications?
Maybe, you installed a suspect Chrome extension or _______?
Maybe, you run Chrome sync? 

How to Remove Cleardexchange.com Redirect (Virus Removal Guide)

Cleardexchange.com is part of an advertising service that website publishers can use to generate revenue on their sites. Unfortunately, there are malicious programs that are redirecting users to these Cleardexchange.com ads without the permission of the publisher in order to generate revenue.

When Cleardexchange.com redirects a browser to an advertisement, the ads are typically for unwanted chrome extensions, surveys, adult sites, online web games, fake software updates, and unwanted programs.

You are seeing the Cleardexchange.com pop-up ads because your computer is infected with a malicious program, or a site that you have visited has redirected you to this page.

Less than reputable sites can display malicious ads that redirect your browser to the Cleardexchange.com pop-up ads to generate advertising revenue. If this happens, you can close the page and install an adblocker to block the malicious ads. However, if you continuously see pop-ups like the Cleardexchange.com pop-up ads, then your computer might be infected with a malicious program, and you need to scan your device for adware and remove it.

This malware removal guide may appear overwhelming due to the number of steps and numerous programs that are being used. We have only written it this way to provide clear, detailed, and easy-to-understand instructions that anyone can use to remove malware for free.
Please perform all the steps in the correct order. If you have any questions or doubts at any point, stop and ask for our assistance.

https://malwaretips.com/blogs/remove-cleardexchange-com/


How to install and run a scan with Malwarebytes (Guide)
https://malwaretips.com/blogs/scan-malwarebytes-anti-malware-2-0/

Malwarebytes Malware Removal Help
https://forums.malwarebytes.com/forum/108-malware-removal-help/


https://safeweb.norton.com/report/show?url=https://cleardexchange.com = Untested

https://safeweb.norton.com/report/show?url=https://www.thesun.co.uk/ = Safe -> News

https://safeweb.norton.com/report/show?url=https://www.dailymail.co.uk/ushome/index.html = Safe -> News


Why did Norton not stop cleardexchange.com from hijaking my browser? What do I do??https://community.norton.com/en/forums/why-did-norton-not-stop-cleardexchangecom-hijaking-my-browser-what-do-i-do

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Malvertising
Malvertising, or malicious advertising, is the use of online advertising to distribute malware with little to no user interaction required.
https://www.malwarebytes.com/malvertising/

Malwarebytes Browser Guard
Filters out annoying ads and scams while blocking trackers that spy on you.
https://www.malwarebytes.com/browserguard/

Browser push notifications: a feature asking to be abused
https://blog.malwarebytes.com/security-world/technology/2019/01/browser-push-notifications-feature-asking-abused/

Adware and PUPs families add push notifications as an attack vector
https://blog.malwarebytes.com/adware/2019/06/adware-and-pups-families-add-push-notifications-as-an-attack-vector/

Remove Malicious Browser Ads from Windows, Mac, and Android
https://malwaretips.com/blogs/remove-adware-popup-ads/


Malwarebytes AdwCleaner
https://www.malwarebytes.com/adwcleaner/

Malwarebytes AdwCleaner guide
https://support.malwarebytes.com/hc/en-us/articles/360038520174-Malwarebytes-AdwCleaner-guide

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

markfranklin:

I contacted Norton support and their solution was to remove the Norton extension from the browser.  However, what the support team could not tell me was - am I now at risk?  Without the protection of Norton, would I have inadvertently been sent to this "cleardexchange" web site and suffered damage or data loss?

Are the Daily Mail and The Sun websites directing users to this dodgy website and should they be told about it?  Or is the Norton extension suspecting trouble with a perfectly safe site / advert?

Any clues would be very gratefully received.

Presumably, if you remove/disable Norton Safe Web extension. 
Presuming you run Norton 360/Security.  Your Norton 360/Security would throw an IPS Alert popup.   

I tried reproducing your Norton IPS Alert/Block by clicking around "thesun" and "dailymail".
At this time, I've only produced Norton Safe Web block.
Maybe, I can reproduce your Norton IPS Alert/Block if you provide the full blocked address.  IDK

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Thanks for the very helpful notes on this.

I downloaded and ran both Malwarebytes and Hit Man Pro in sequence and both came back with "no threats found".

I shall monitor to see if the issue persists.

Thanks again

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Thanks for the very helpful notes on this.

I downloaded and ran both Malwarebytes and Hit Man Pro in sequence and both came back with "no threats found".

I shall monitor to see if the issue persists.

Thanks again

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Remove unwanted ads, pop-ups & malware
If you're seeing some of these problems with Chrome, you might have unwanted software or malware installed on your computer:

https://support.google.com/chrome/answer/2765944


Chrome Secure Preferences detection always returns - Chrome Sync
https://forums.malwarebytes.com/topic/258886-chrome-secure-preferences-detection-always-returns/

Resetting Google Chrome to clear unexpected issues
https://forums.malwarebytes.com/topic/258938-resetting-google-chrome-to-clear-unexpected-issues/

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

cleardexchange.com does not appear to have a working website at this time

https://cleardexchange.com/

The 403 Forbidden Error happens when the web page (or another resource) that you’re trying to open in your web browser is a resource that you’re not allowed to access. It’s called a 403 error because that’s the HTTP status code that the webserver uses to describe that kind of error.

You usually get this error for one of two reasons. The first is that the owners of the webserver have properly set up access permissions and that you’re really not allowed access to the resource. The second reason is that the owners of the webserver have improperly set up permissions and you’re getting denied access when you really shouldn’t be.

Google

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

markfranklin:

I shall monitor to see if the issue persists.

@markfranklin

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Thanks again for all the comments and suggestions.  Over the past few weeks, I have not seen any further instances, so fingers crossed the issue has gone away.

Great news!

Kudos0

Re: Malicious site blocked (cleardexchange) when browsing safe sites

Thanks

This thread is closed from further comment. Please visit the forum to start a new thread.