Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

30957 7.14%
70c91 7.14%
d762d 7.14%
83f5d 7.14%
4cb1b 7.14%
c5521 7.14%
506b0 35.71%
9ee81 14.29%
04119 7.14%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
CryptAcquireContextA, CryptGenRandom, RegCloseKey, RegOpenKeyExA, RegQueryValueExA, DeregisterEventSource, RegisterEventSourceA, ReportEventA
gdi32.dll
BitBlt, CreateCompatibleBitmap, CreateCompatibleDC, CreateDCA, DeleteDC, DeleteObject, GetBitmapBits, GetDeviceCaps, GetObjectA, SelectObject
kernel32.dll
CloseHandle, CreateFileA, CreateFileMappingA, CreateIoCompletionPort, CreatePipe, CreateProcessA, CreateSemaphoreA, DeleteCriticalSection, EnterCriticalSection, ExitProcess, FindClose, FindFirstFileA, FindNextFileA, FormatMessageA, FreeLibrary, GetCurrentThreadId, GetExitCodeProcess, GetFileSize, GetLastError, GetModuleFileNameA, GetModuleHandleA, GetProcAddress, GetQueuedCompletionStatus, GetSystemDirectoryA, GetSystemInfo, GetSystemTimeAsFileTime, GetVersion, GetVersionExA, InitializeCriticalSection, InitializeCriticalSectionAndSpinCount, InterlockedExchange, IsDBCSLeadByteEx, LeaveCriticalSection, LoadLibraryA, LocalFree, MapViewOfFile, MultiByteToWideChar, OpenProcess, PeekNamedPipe, PostQueuedCompletionStatus, ReadFile, ReleaseSemaphore, SetHandleInformation, SetUnhandledExceptionFilter, Sleep, TerminateProcess, TlsGetValue, UnmapViewOfFile, VirtualProtect, VirtualQuery, WaitForSingleObject, WideCharToMultiByte, GetCurrentProcessId, GetFileType, GetStdHandle, GetTickCount, GlobalMemoryStatus, QueryPerformanceCounter, SetLastError
libeay32.dll
DllMain
libssp-0.dll
__stack_chk_fail, __stack_chk_guard
msvcrt.dll
DllMain
shell32.dll
SHGetMalloc, SHGetPathFromIDListA, SHGetSpecialFolderLocation, SHGetSpecialFolderPathA
ssleay32.dll
SSL_CIPHER_get_name, SSL_CTX_check_private_key, SSL_CTX_ctrl, SSL_CTX_free, SSL_CTX_get_cert_store, SSL_CTX_new, SSL_CTX_set_verify, SSL_CTX_use_PrivateKey, SSL_CTX_use_certificate, SSL_accept, SSL_connect, SSL_ctrl, SSL_do_handshake, SSL_free, SSL_get_error, SSL_get_ex_data, SSL_get_ex_new_index, SSL_get_peer_cert_chain, SSL_get_peer_certificate, SSL_get_rbio, SSL_get_session, SSL_get_wbio, SSL_library_init, SSL_load_error_strings, SSL_new, SSL_pending, SSL_read, SSL_renegotiate, SSL_set_bio, SSL_set_cipher_list, SSL_set_ex_data, SSL_set_info_callback, SSL_set_verify, SSL_shutdown, SSL_state_string_long, SSL_write, SSLv23_method
user32.dll
GetDesktopWindow, GetProcessWindowStation, GetUserObjectInformationW, MessageBoxA
ws2_32.dll
WSACleanup, WSAGetLastError, WSAIoctl, WSASetLastError, WSAStartup, accept, bind, closesocket, connect, gethostbyname, gethostname, getservbyname, getsockname, getsockopt, htonl, htons, ioctlsocket, listen, ntohl, ntohs, recv, recvfrom, select, send, sendto, setsockopt, socket, shutdown

tor.exe

Remove tor.exe
MD5:   30957c1d9e5dda3f95719daa0c732ff1
SHA1:   8a637fafd2c2049e034e2f24033d0801ab3e5372
SHA256:   5f16908f5fcbe891390b3efedd141a6b574d3bc3b2c4d966e2beef6b6fc40567

Overview

tor.exe runs as a service under the name Tor Win32 Service (tor) within the local user context. This is typically installed with the program Polipo 1.0.4.1 published by Juliusz Chroboczek.

DetailsDetails

File name:tor.exe
Typical file path:C:\Program Files\vidalia bundle\tor\tor.exe
Size:2.76 MB (2,892,814 bytes)
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
Juliusz Chroboczek
12% remove
Polipo is a lightweight forwarding and caching web proxy server. Polipo is HTTP 1.1-compliant, supports IPv4, IPv6, traffic filtering and privacy-enhancement. To minimize latency, Polipo both pipelines multiple resource requests and multiplexes multiple transactions onto the same TCP/IP connection. Polipo can be configured to use on-disk cache and serve cached content when offline, perform various forms of content filtering and serve as...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'tor' (Tor Win32 Service)
  • tor

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00033987%
0.028634%
Kernel CPU:0.00022474%
0.013761%
User CPU:0.00011513%
0.014873%
Kernel CPU time:9,734 ms/min
100,923,805ms/min
Context switches:5/sec
284/sec
Memory
Private memory:19.69 MB
21.59 MB
Private (maximum):32.75 MB
Private (minimum):24.79 MB
Non-paged memory:19.69 MB
21.59 MB
Virtual memory:110.83 MB
140.96 MB
Virtual memory (peak):121.38 MB
169.69 MB
Working set:28.58 MB
18.61 MB
Working set (peak):32.84 MB
37.95 MB
Page faults:4,079,161/min
2,039/min
Resource allocations
Threads:3
12
Handles:122
600
GUI GDI count:9
103
GUI GDI peak:9
142
GUI USER count:1
49
GUI USER peak:2
71

BehaviorsProcess properties

Integrety level:Undefined
Platform:64-bit
Command line:"C:\Program Files\vidalia bundle\tor\tor.exe" -f C:\users\user\appdata\local\vidalia\torrc controlport 9051 __owningcontrollerprocess 2444 hashedcontrolpassword 16:827357ba49d24c6760c3e19b900e56cbe310aaddd32c989ac5414380e4
Owner:User
Windows Service
Service name:tor
Display name:Tor Win32 Service
Description:“Provides an anonymous Internet communication system”
Type:Win32OwnProcess
Parent process:vidalia.exe (Vidalia by Equifax)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 42.86%
Windows 7 Home Premium 28.57%
Windows 8.1 Pro 7.14%
Microsoft Windows XP 7.14%
Windows 7 Professional 7.14%
Windows Server 2012 Standard Evaluation 7.14%

Distribution by countryDistribution by country

Ireland installs about 14.29% of tor.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 28.57%
Lenovo 28.57%
Acer 14.29%
Hewlett-Packard 14.29%
American Megatrends 14.29%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE