When roaming my registry today, I found a suspicious key under HKLM\Software that was obviously encrypted, and the values inside were likewise:
[HKEY_LOCAL_MACHINE\SOFTWARE\T96Pk0Px4ALJoXfi0l_v7CWW]
"vFFOg4JQG0r7wfUevNmW"="liC!t06Jas-jsKtpyH_zu!He2BWW"
"QoOAmAsdC!nFJ4o_pHP_oIyDenSBX4Yg-HfvaLwveEk0X49_xrNW"="QM-A3fRGekiQJfTPo_M_34cGCgSQh4kR-H1d34KdekiQI4U1TkNW"
"CJsPtCWW"="RkYa"
"lY3dqQGEpCWW"=""
"YQtOwAGbOFZW"=""
"YQtOwAGbOFXW"=""
"zjumvCWW"=""
"0jivbQZW"=""
"lY3FyXJjpCWW"=""
"5kz0"=""
"0UolLhZW"=""
"JklO"=""
"1PrvjaOW"="iZrIB_ZvTcH-dhBW"
"26_mic_K"="0BWW"
"rVfpxKGFeQGfh3j_f_XW"="0-WW"
"IrzxTG8uju_V-AnSRwzD"="0BWW"
"w0SPY6jKTM-W"="0BWW"
Well, I think I remember having read something about encrypting registry keys (e.g. to protect shareware), but I've never seen any legitimate shareware (or other software) really do that. I have no idea where this key comes from (and I like to know such stuff).
I decided to just delete this key (after backing it up), and afterwards tested all (!) my programs for error messages on startup (found none), but I'm still wondering:
What might have produced this key?
Is it really safe to delete it?
Is this a sign of malware? (Never had any, and just recently scanned the machine thoroughly.)
Is there an OS-supplied encryption system for registry entries? (that next to nobody seems to use?)
Since I know there are some pretty bright people in this forum, and especially some shareware authors, maybe someone could give me some pointers.