The embedded garbage in WEB sites is the easiest thing to defeat. Disable Java, disable any type of automatic downloads, disable .NET, kill ActiveX, stomp out any scripting whatsoever.
Once you have determined the site is safe (i.e. it is not running on a Windows OS platform) and clean, then you can drop it in your trusted sites, but sill leave Java and ActiveX dead even for trusted sites.
The reason I specifiy Windows OS servers is they are most susceptible to having viruses/spyware embedded on them without the local admin even knowing it.
I have left out a lot of details here as I figure no one would ever want to operate a computer like I operate mine. You would have to do without Youtube, MyFace, Facebook, and a plethora of other sites I find useless.