Ran it against a bunch more scanners and came up with a suspicious payload. F-Secure refers to it as "Tibs.gen134", Sophos as "Mal/Dorf-E", etc, but just because it is suspicious doesn't mean anything definitive. Other than, it probably isn't tor since it is 1/20th the size. http://www.virustotal.com/resultado.html?f63f10cc10953a005a9683b875eac2dd Steve