Google's Safe Browsing API (malware and phishing protection) requires a cookie. But Firefox puts that cookie in a separate bucket than the one used for regular requests. If you have cookies enabled, you'll actually end up with two separate google.com "PREF" cookies - one for regular HTTP requests, and one just for for updating the Safe Browsing lists. Disabling Safe Browsing will prevent that cookie from every being sent, and should allow you to delete it (EDIT: modulo the cookie manager bug below).
UPDATE: It looks like http://bugzil.la/1026538 is why the cookie keeps reappearing.
Yes, that's basically how it works. Firefox periodically downloads a database of blocked URLs. Before loading a web page, it checks this database. If the check is negative then Firefox displays the page normally. If the check is positive, Firefox will also send a hashed URL to the Safe Browsing server to double-check whether to block the page or not.
This page has more documentation, including a link to the API specification:
https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...
Oh, and Google should _really_ provide their Safebrowsing API without a cookie, too. Youtube-nocookie.com works fine too....
these types of cookies may seem benign and helpful to users (and maybe they are), but i also wouldn't doubt that Google uses this information for persistent tracking.
it's already been disclosed that NSA uses Google PREF cookies to track users: http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10...
hence my other dispirited comment about the cookie UI... edit: reworded/clarified