Guten Tag,
neulich hatte mir ein freund eine ziemlich blöde datei geschickt. Beim öffnen installierte sich scheinbar "cookies control" addon bei google chrome. Dieses öffnet ab und zu irgendwelche werbetabs und ändert die standardsuche zu yahoo. Außerdem kann ich die Suchmaschine google fast garnichtmehr benutzen da es scheinbar die eingabe blockt.
Eigentlich hatte ich mit Junkwareremovaltool und
Malwarebytes anti malware die extension und zugehörige datein gelöscht. auch schon chrome neuinstalliert. jedoch taucht es immer wieder auf. ich kann bei erweiterungen auch nicht den "mülleimer" anklicken da hier steht "durch unternehmensrichtlinie installiert"
das einzige das mir bleibt ist inkognito modus nutzen - da hier das addon erst garnicht geladen wird.
hier mal logfiles die ich bisher habe:
Code:
Alles auswählen Aufklappen ATTFilter
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 16.07.2017
Suchlaufzeit: 19:19
Protokolldatei: mwbam log.txt
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2017.07.16.04
Rootkit-Datenbank: v2017.05.27.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: soonsnookie
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 275654
Abgelaufene Zeit: 3 Min., 18 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 3
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\_metadata, , [dc187de93c6d999dd1923bc6cf33b848],
Dateien: 15
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\background.js, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\icon-128.png, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\icon-48.png, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\icon-96.png, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\icon-allow.png, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\icon-block.png, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\icon-inactive.png, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\icon.png, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\infobar.html, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\manifest.json, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\options.css, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\options.html, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\options.js, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\_metadata\computed_hashes.json, , [dc187de93c6d999dd1923bc6cf33b848],
PUP.Optional.CookiesControl.ChrPRST, C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp\1.0.3_1\_metadata\verified_contents.json, , [dc187de93c6d999dd1923bc6cf33b848],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end)
Code:
Alles auswählen Aufklappen ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Pro x64
Ran by soonsnookie (Administrator) on 16.07.2017 at 18:57:22,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 0
Registry: 3
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEA429F3-D2D4-4BD7-A03E-5357DA017733} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEA429F3-D2D4-4BD7-A03E-5357DA017733} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{84F23192-A475-4038-B5C0-8584777F2DF4} (Registry Value)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.07.2017 at 18:59:33,22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Code:
Alles auswählen Aufklappen ATTFilter
Code:
Alles auswählen Aufklappen ATTFilter
HitmanPro 3.7.20.286
www.hitmanpro.com
Computer name . . . . : DESKTOP-37RBO84
Windows . . . . . . . : 10.0.0.15063.X64/8
User name . . . . . . : DESKTOP-37RBO84\soonsnookie
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (31 days left)
Scan date . . . . . . : 2017-07-16 19:50:00
Scan mode . . . . . . : Normal
Scan duration . . . . : 1m 47s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 1
Traces . . . . . . . : 81
Objects scanned . . . : 1.745.699
Files scanned . . . . : 46.617
Remnants scanned . . : 393.513 files / 1.305.569 keys
Malware _____________________________________________________________________
C:\Users\soonsnookie\AppData\Local\Temp\is-ENSST.tmp\LEM2tB8sSCkfBzBIDM.dll -> Deleted
Size . . . . . . . : 743.936 bytes
Age . . . . . . . : 2.0 days (2017-07-14 20:47:28)
Entropy . . . . . : 6.5
SHA-256 . . . . . : C3BD0D28A89F84A10BB6BC7DEC6A5FE1750A24F043339E9A7705A6757D43466E
Product . . . . . : TODO: <Product name>
Version . . . . . : 1.0.0.1
Copyright . . . . : Copyright (C) 2017
LanguageID . . . . : 1033
> Bitdefender . . . : Gen:Variant.Mikey.67661
Fuzzy . . . . . . : 103.0
Forensic Cluster
-2.1s C:\ProgramData\AVAST Software\Avast\SWCUData\Cache\InstallLocation\Office14.PROPLUS
-2.0s C:\Windows\Prefetch\CHXSMARTSCREEN.EXE-02862867.pf
-0.0s C:\Users\soonsnookie\AppData\Local\Temp\is-ENSST.tmp\
-0.0s C:\Users\soonsnookie\AppData\Local\Temp\is-ENSST.tmp\_isetup\
-0.0s C:\Users\soonsnookie\AppData\Local\Temp\is-ENSST.tmp\_isetup\_setup64.tmp
0.0s C:\Users\soonsnookie\AppData\Local\Temp\is-ENSST.tmp\LEM2tB8sSCkfBzBIDM.dll
0.8s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\B8VKB3XB\XXNL8CF1.htm
1.2s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\FO5MO1CH\logo-smart[1].png
1.3s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\NX8RDU5E\preloader[1].gif
6.7s C:\Windows\SysWOW64\GroupPolicy\gpt.ini
6.7s C:\Windows\System32\GroupPolicy\Machine\
6.7s C:\Windows\System32\GroupPolicy\User\
6.7s C:\Windows\System32\GroupPolicy\Machine\Registry.pol
6.7s C:\Windows\System32\GroupPolicy\GPT.INI
6.7s C:\ProgramData\ntuser.pol
8.3s C:\Windows\Prefetch\MINI_KMS.ZIP.TMP-C814559E.pf
8.6s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\B8VKB3XB\1[1].htm
8.8s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\B8VKB3XB\bulma[1].css
8.9s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\3L7WN3ZZ\sky_mini[1].jpg
9.0s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\FO5MO1CH\rss[1].svg
9.0s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\NX8RDU5E\thumb_upm[1].png
9.1s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\B8VKB3XB\thumb_downm[1].png
9.1s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\3L7WN3ZZ\download[1].svg
9.2s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\FO5MO1CH\magnet[1].svg
9.3s C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCache\IE\NX8RDU5E\verified[1].png
9.9s C:\Windows\Prefetch\MINI_KMS.ZIP.TMP-9197FCCF.pf
13.6s C:\Users\soonsnookie\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EA7B4DD121D30CF83CCB5E008C0D231C
13.6s C:\Users\soonsnookie\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EA7B4DD121D30CF83CCB5E008C0D231C
13.6s C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d40c30c2ea5332692fcb26f8082cbb3b_562d8ac1-f54a-4e70-a19d-19668d36e5c0
23.8s C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Operational.evtx
23.8s C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Admin.evtx
Cookies _____________________________________________________________________
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:571703138.log.optimizely.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.turn.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad1.adfarm1.adition.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad3.adfarm1.adition.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adaptv.advertising.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:addthis.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adfarm1.adition.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adform.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adformdsp.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adhigh.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adnxs.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.avocet.io
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.smartstream.tv
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.stickyadstv.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adscale.de
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsrvr.org
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsymptotic.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:agkn.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidr.io
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidswitch.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:bluekai.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:connexity.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:demdex.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:dotomi.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:dpm.demdex.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:everesttech.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:gwallet.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ibeu2.mookie1.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ibillboard.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ih.adscale.de
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:krxd.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:m6r.eu
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:match.rundsp.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:mathtag.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:metrigo.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:ml314.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:mookie1.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:mxptint.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:nexac.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:openx.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:optimizely.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:partners.tremorhub.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:pixel.rubiconproject.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:pubmatic.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:rfihub.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:rlcdn.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:rubiconproject.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:scorecardresearch.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:server.adformdsp.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:simpli.fi
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:statcounter.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:taboola.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:tapad.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:tidaltv.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:trc.taboola.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:tremorhub.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:tubemogul.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:turn.com
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:w55c.net
C:\Users\soonsnookie\AppData\Local\Google\Chrome\User Data\Default\Cookies:yieldlab.net
C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCookies\L2FSKHBS.cookie
C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCookies\Low\GOG9R02Y.cookie
C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCookies\Low\K2COT5FM.cookie
C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCookies\Low\P7JFR67R.cookie
C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCookies\Low\RUDPRON1.cookie
C:\Users\soonsnookie\AppData\Local\Microsoft\Windows\INetCookies\Low\VY5KWWO4.cookie
C:\Users\soonsnookie\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\Cookies\7JX1EG5B.cookie
C:\Users\soonsnookie\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\Cookies\EE9YASLU.cookie
C:\Users\soonsnookie\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\Cookies\JKWKH6DB.cookie
C:\Users\soonsnookie\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\Cookies\RNWTJNY8.cookie
alles gelöscht, kommt aber alles wieder